Home APIs

Managing Cyber Blind Spots: Shadow APIs

It’s never been more important to secure the entire API ecosystem, including finding and protecting unknown and shadow APIs.

application-programming-interface-API-security

Application programmable interfaces (APIs) are critical in enabling different software applications to communicate and interact across today’s online experience – for both businesses and consumers. From a programmatical perspective, APIs are a base component of everything we do online, from accessing content on web servers and using mobile applications to streaming services.

However, the world’s dependence on APIs coupled with their high growth brings an increased risk of security exposure due to the open nature of APIs and the challenges of managing API inventories. According to Gartner research, APIs have become a significant target. Shadow APIs, along with unknown and unmanaged APIs, face the most significant risk as they are a primate target of over a third of all malicious requests.

Understanding the Importance of APIs

APIs provide the means by which most modern applications communicate and retrieve data, so they are a crucial component of the application landscape. Their true purpose is holding access to data across web applications to ensure smooth, programmatic communication between databases and applications. This means they’re also a significant factor in the path to organizations’ digital transformation efforts. Despite their importance, many APIs remain unmanaged and undiscovered, and even known APIs are often poorly secured. APIs also tend to have less mature defenses, making them a prime target for attackers.

A recent survey found that over half of all organizations are impacted by three or more API attacks per month. Knowing that threats to APIs are at an all-time high, security teams must ensure proper protections are implemented to this part of the application ecosystem. An exploited API can lead to drastic consequences for an organization as attackers can gain access to sensitive information, such as corporate intellectual property and personally identifiable information (PII) like customer or employee data. Shadow and unmanaged APIs should be a top security priority as they are much more vulnerable to threats than known and documented APIs.

Protection of Shadow and Unknown APIs is Invaluable

Shadow APIs are extensions of known APIs that are undocumented usually resulting from an incomplete development process. Unknown APIs are often created by developers during application development, third-party integrations, or other users within an organization to run other functions, such as employee-initiated tools and subsequently left orphaned while still being active.  Because both exist within an organization without the proper approval or oversight from the security team, it’s impossible to protect them.

They also lack the right security tools and documentation, making them extremely vulnerable to attacks. An exploited or insecure API compromises all the systems they interact with, therefore increasing the chances of data breach. Another common risk is the use of APIs as an entry point for network breaches. Once they’ve entered the network via an exploited API, they’re able to move laterally to gain access to their target accounts or systems.

Implementing the Proper Protection

Keeping track of all APIs and identifying potential vulnerabilities is certainly challenging for security teams. The vulnerabilities often posed by shadow and unknown APIs can be a disaster waiting to happen, and mass amounts of data are at risk.

Today’s threat landscape is becoming more sophisticated as cybercriminals deploy new tactics. Attackers are getting more innovative with their methods, such as using AI to create more targeted attacks.

Getting a handle on their API footprint is the first step in a strong protection strategy for any organization. The proper protection can drastically help mitigate attacks and reduce damage if the elements of solid API management are followed:

  • Taking inventory of all APIs: Security teams must inventory all API endpoints exposed and ensure they are documented. This should include the full API environment, including production, staging, testing, and deployment. From there, security teams are better able to detect vulnerabilities and flaws in the APIs.
  • Monitoring, testing, and mitigation: Continuous monitoring of all internal and external APIs helps identify new endpoints as they become active and can find flaws in API implementations. Robust detection solutions should include monitoring for compliance, vulnerabilities, exposed sensitive data, and flaws in business logic. These solutions can then provide security teams with a means of remediating these risks.
  • Incorporating advanced bot mitigation: Advanced bot mitigation capabilities are an API security must-have, as bot-based attacks are the most common source of API threats. Advanced bot management solutions involve various techniques, including AI and ML, to help identify malicious bots and block threats in real-time.

Protecting your Business’ Bottom Line

The API ecosystem is constantly evolving. Security teams must also continuously evolve their defenses to prevent attacks that eventually snowball into business disruption, data theft, financial loss, and reputational damage. Given its importance in serving the online experience, it’s never been more important to secure the entire API ecosystem — and that includes finding and protecting unknown and shadow APIs.


Carlos Morales

Carlos Morales is the Senior Vice President of Solutions for Vercara, responsible for product management of Vercara’s portfolio of application security, DNS, and threat data services. In his role, he manages and empowers a senior group of product managers to define product strategy, product requirements, and roadmaps and oversees the release process to create service differentiation and accelerate growth. He also helps define the strategy for security acquisitions and the execution of strategic partnerships. Before taking the SVP of Solutions role, he was CTO of the Security Solutions business unit within Neustar. Prior to joining the company, Carlos held a number of senior leadership roles with Netscout and Arbor Networks where he led product strategy, sales, operations, and other core business functions.

×