Skip to main content
No items found.
currentColor
  • Platform
    • Complete Runtime Protection
      The unified enforcement platform for AI attacks.
    • Runtime Defense Agents
      Your AI security engineering team. Running inline.
    • Surfaces
    • LLM Protection
      Deterministic agent controls.
    • Agent Protection
      Control how agents behave in production.
    • MCP Protection
      Runtime control for the MCP layer.
    • WAF
      WAF for the Agentic Era.
    • API
      AI Security for the Agentic era.
  • Why Impart
  • Use Cases
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
  • Performance
  • Trust
    • Heading
      One runtime engine. Every request. Before your backend sees it.
    • Documentation
      Let the payload pass. It won’t execute.
    • Research
      Let the request run. It won’t succeed.
    • Events
      Lorem Ipsu Dolor Sit Ament
    • AI/LLM Security
      Let the prompt start. Harmful requests won't finish.
  • Resources
    • Resource Center
      Blog, Product Updates, Guides, and more.
    • Events
      Where to find us next.
    • AI/LLM Security
      Let the prompt start. Harmful requests won't finish.
  • Company
    • About
      At AI speed, runtime is the only source of truth.
    • Newsroom
      Impart in the News.
    • Careers
      Come build runtime defense with us.
  • Book a Demo
currentColor
  • Platform
    • Complete Runtime Protection
      The unified enforcement platform for AI attacks.
    • Runtime Defense Agents
      Your AI security engineering team. Running inline.
    • Surfaces
    • LLM Protection
      Deterministic agent controls.
    • Agent Protection
      Control how agents behave in production.
    • MCP Protection
      Runtime control for the MCP layer.
    • WAF
      WAF for the Agentic Era.
    • API
      AI Security for the Agentic era.
  • Why Impart
  • Use Cases
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
    • Branding
  • Performance
  • Trust
    • Heading
      One runtime engine. Every request. Before your backend sees it.
    • Documentation
      Let the payload pass. It won’t execute.
    • Research
      Let the request run. It won’t succeed.
    • Events
      Lorem Ipsu Dolor Sit Ament
    • AI/LLM Security
      Let the prompt start. Harmful requests won't finish.
  • Resources
    • Resource Center
      Blog, Product Updates, Guides, and more.
    • Events
      Where to find us next.
    • AI/LLM Security
      Let the prompt start. Harmful requests won't finish.
  • Company
    • About
      At AI speed, runtime is the only source of truth.
    • Newsroom
      Impart in the News.
    • Careers
      Come build runtime defense with us.
  • Request a Demo
Back to Blog

The Future of Appsec is APIs

Impart Security
7.24.2024
•
41
min read

‍

Summary

In this conversation, Matt Johansen and Brian Joe discuss API security and its evolution from traditional application security.

First and foremost, they define what we mean by “API Security.” This involves a quick history lesson on the rise of microservices and decentralized applications. 

They also highlight the challenges and vulnerabilities associated with API security, such as broken authentication and authorization.

We even get into how AI has impacted security testing and the need for innovation in response and enforcement!

Overall, the discussion provides insights into the current state and future of API security. Join us to explore the evolution of web application firewalls (WAFs) and what they can and can not do in the ever-growing world of APIs.

‍Matt’s favorite takeaway: Traditional WAFs inspected a single request and decided if it was good or bad. Next-gen WAFs added the dimension of looking at attack traffic over time instead of that single request. Impart, and modern API Security solutions are going beyond that 2nd dimension and bringing in a lot more context to make security decisions on API traffic.

Key Takeaways

‍

  • API security is the protection of microservices and decentralized applications, ensuring the secure communication between different components.
  • API security is an evolution of traditional application security, focusing on the unique challenges and vulnerabilities of APIs.
  • Broken authentication and authorization are common vulnerabilities in API security, requiring specific measures to mitigate.
  • AI has a significant impact on detection and visibility in security, but there is still room for innovation in response and enforcement.
  • The industry terminology for API security varies, including terms like next-gen WAF and RASP, but the focus is on achieving better security outcomes.
  • WAFs have evolved from analyzing single requests to considering requests over time, providing better context and visibility for security decisions. API Security tools have evolved even further to include much more context than just “over time” to make more informed security decisions.
  • One of the biggest challenges in API security is protecting against authorization exploitation, as traditional WAFs are not effective in addressing this issue.
  • Managing and securing a large number of APIs is a common problem for security teams, as visibility and control over these APIs are often lacking.
  • Security tools need to align with modern engineering practices, providing engineering teams with the ability to customize and test security policies in a similar way to how they test production code.

‍

Contact us at try.imp.art and remember to follow us on LinkedIn to stay up-to-date with the latest and greatest.

Table of contents
TOC Element
currentColor
Get a Demo

SOC 2 Type II

GDPR Ready

Platform

The Engine
Runtime Defense Agents

Trust

Performance

Surfaces

LLM
MCP
Agent
WAF
API

Company

About
Why Impart
Newsroom
Careers
Contact

Resources

Resource Center
Events

Trust

Performance
Subscribe*
Thank you! Your submission has been received!
Something went wrong while submitting the form.
Privacy Policy
Cookies Settings
© {{year}} Impart Security. All rights reserved.