One in five APAC organizations look to AI/ML-powered solutions to tackle API security challenges

One in five APAC organizations look to AI/ML-powered solutions to tackle API security challenges

According to F5’s inaugural 2024 Strategic Insights: API Security in APAC report, PAC organizations are increasingly turning to artificial intelligence (AI) and machine learning (ML) solutions to address a range of security challenges related to Application Programming Interfaces (APIs). The report delves into the evolving landscape of API security in the Asia-Pacific (APAC) region, where APIs are integral to digital experiences.

As APIs become a focal point for cyberattacks, one in five APAC organizations has implemented AI/ML technologies to detect and counter advanced threats, such as server-side request forgery (SSRF), which traditional security measures might miss. Additionally, 20% of organizations in the region are adopting API Gateways to enhance access control and address a wide array of vulnerabilities, including unrestricted access to sensitive business processes.

Applications have become the front door to cybercrime, and cybercriminals increasingly use APIs as the key. Across the APAC region, we have seen more attacks, with increasing speed, scale and sophistication as cybercriminals leverage AI-powered tools,” said Mohan Veloo, Chief Technology Officer for Asia Pacific, China and Japan, F5. “As such, protecting API connections and the data that runs through them has become the critical security challenge for APAC organizations, especially with many looking to deliver AI.”

“Businesses are prioritizing investments in security infrastructure, to ensure protection for their applications. According to our 2024 Strategic Insights: API Security in APAC report, the majority of Indian businesses are prioritizing API security testing, access control, and runtime protection for comprehensive API security.”

— Pratik Shah, Managing Director of India and SAARC, F5.

“APAC organizations are facing unique API security challenges that differ significantly from global OWASP rankings. The research highlights the pressing need for tailored security measures to address specific risks such as Broken Authentication, Server-Side Request Forgery, and Security Misconfiguration. Countries like Malaysia, New Zealand, South Korea, and India are prioritizing these issues, reflecting the diverse API adoption patterns across the region. It’s clear that a focus on robust testing, strong access control and continuous runtime protection is essential for a holistic API security approach in APAC,” said Manoj Menon, Founder and CEO at Twimbit.

While APAC organizations look to protect their APIs during runtime, many also increasingly recognize the importance of guarding APIs right from development. Having robust code security standards and practices (17.5%) has emerged as a fundamental strategy among the region’s organizations to guard APIs against a broad range of complex vulnerabilities, from Broken Object Level Authorization and Security Misconfiguration issues to SSRF.

“Today, API security is more important, but also more complex than ever. Findings from our report clearly show that more organizations are shifting left along the API lifecycle, while still attempting to shield right. F5 is bringing advanced API code testing and telemetry analysis to F5 Distributed Cloud Services, creating the industry’s most comprehensive and AI-ready API security solution. F5 Distributed Cloud Services can offer API discovery, testing, posture management, and runtime protection, all in a single platform, allowing organizations to gain true visibility and security from code to cloud,” Veloo added.

Some key India findings from the 2024 Strategic Insights: API Security in APAC report include:

·       Rising Security Concerns around Broken Authentication (API2) and Server-Side Request Forgery (SSRF):

o   Broken Authentication: Broken Authentication has been marked by 15% of respondents as a top concern, aligning with the APAC average of 15%. The prevalent use of Webhooks (37%) and REST APIs (43%) necessitates strong authentication mechanisms to prevent unauthorized access. Securing authentication processes is vital to protect user identities and sensitive data.

o   Server-Side Request Forgery (SSRF): It is also a significant concern in India, with 15% of respondents indicating it as a top issue, compared to 13.8% in APAC. The high use of GraphQL (40%) and SOAP (37%) protocols highlights the importance of validating user-supplied URLs to prevent SSRF attacks. Implementing robust validation mechanisms is essential to safeguard against malicious requests.

·       India Prioritizes API Security Testing, Access Control, and Runtime Protection for Comprehensive API Security: In India, API Security Testing is the highest priority, with 57% of respondents marking it as a top concern, exceeding the APAC average of 52%. API Access Control, including Authentication and Authorization, is another critical priority, highlighted by 47% of respondents, slightly above the APAC average of 46%. The significant use of Internal (67%) and Public (57%) APIs emphasizes the need for robust access control mechanisms, aligned with OWASP API2 and API5. Additionally, API Runtime Protection is crucial, with 43% of respondents marking it as a top concern compared to 36% in APAC, driven by the high use of Internal (67%) and REST (43%) APIs.

·       Significant Adoption of Code Security Solutions: Code security solutions are the most adopted API security solutions in India, with an 18.0% adoption rate. This highlights the importance of secure coding practices and static code analysis to prevent vulnerabilities from being introduced during the development phase. By integrating code security solutions with AIML technologies, businesses can proactively identify and address potential security issues, ensuring a secure API environment from the ground up.

·       Critical Role of API Gateways in API Security: API Gateways play a crucial role in India’s API security strategy, with a 16.5% adoption rate. The use of API Gateways helps manage and secure API traffic, providing essential controls for access and consumption, which is critical given India’s significant use of RPC (43%) and REST APIs (43%).

·       Adoption of AIML Solutions for Comprehensive Protection: AIML solutions are another key focus for India, with a 16.5% adoption rate. The rise in the adoption of AIML solutions demonstrates India’s proactive approach to leveraging advanced technologies for comprehensive threat detection and prevention, ensuring robust security measures across dynamic API environments.

To evaluate the current landscape of API security in APAC, Twimbit conducted research on behalf of F5 in H1 of 2024, surveying 297 professionals from various sectors, including security, DevOps, SecOps, and application development. Respondents were distributed across 11 APAC markets: Australia, China, India, Indonesia, Japan, Korea, Malaysia, New Zealand, Singapore, Taiwan, and Thailand. 

Comments

Leave a Reply