Defending APIs: Uncover advanced defense techniques to craft secure application programming interfaces
暫譯: 保護API:揭示高級防禦技術以打造安全的應用程式介面
Domoney, Colin
- 出版商: Packt Publishing
- 出版日期: 2024-02-09
- 售價: $1,580
- 貴賓價: 9.5 折 $1,501
- 語言: 英文
- 頁數: 384
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1804617121
- ISBN-13: 9781804617120
-
相關分類:
資訊安全
立即出貨 (庫存=1)
相關主題
商品描述
Get up to speed with API security using this comprehensive guide full of best practices for building safer and secure APIs
Key Features:
- Develop a profound understanding of the inner workings of APIs with a sharp focus on security
- Learn the tools and techniques employed by API security testers and hackers, establishing your own hacking laboratory
- Master the art of building robust APIs with shift-left and shield-right approaches, spanning the API lifecycle
- Purchase of the print or Kindle book includes a free PDF eBook
Book Description:
Along with the exponential growth of API adoption comes a rise in security concerns about their implementation and inherent vulnerabilities. For those seeking comprehensive insights into building, deploying, and managing APIs as the first line of cyber defense, this book offers invaluable guidance. Written by a seasoned DevSecOps expert, Defending APIs addresses the imperative task of API security with innovative approaches and techniques designed to combat API-specific safety challenges.
The initial chapters are dedicated to API building blocks, hacking APIs by exploiting vulnerabilities, and case studies of recent breaches, while the subsequent sections of the book focus on building the skills necessary for securing APIs in real-world scenarios.
Guided by clear step-by-step instructions, you'll explore offensive techniques for testing vulnerabilities, attacking, and exploiting APIs. Transitioning to defensive techniques, the book equips you with effective methods to guard against common attacks. There are plenty of case studies peppered throughout the book to help you apply the techniques you're learning in practice, complemented by in-depth insights and a wealth of best practices for building better APIs from the ground up.
By the end of this book, you'll have the expertise to develop secure APIs and test them against various cyber threats targeting APIs.
What You Will Learn:
- Explore the core elements of APIs and their collaborative role in API development
- Understand the OWASP API Security Top 10, dissecting the root causes of API vulnerabilities
- Obtain insights into high-profile API security breaches with practical examples and in-depth analysis
- Use API attacking techniques adversaries use to attack APIs to enhance your defensive strategies
- Employ shield-right security approaches such as API gateways and firewalls
- Defend against common API vulnerabilities across several frameworks and languages, such as .NET, Python, and Java
Who this book is for:
This book is for application security engineers, blue teamers, and security professionals looking forward to building an application security program targeting API security. For red teamers and pentesters, it provides insights into exploiting API vulnerabilities. API developers will benefit understanding, anticipating, and defending against potential threats and attacks on their APIs. While basic knowledge of software and security is required to understand the attack vectors and defensive techniques explained in the book, a thorough understanding of API security is all you need to get started.
商品描述(中文翻譯)
透過這本全面的指南,掌握 API 安全性,內含建立更安全 API 的最佳實踐
主要特色:
- 深入了解 API 的內部運作,專注於安全性
- 學習 API 安全測試人員和駭客所使用的工具和技術,建立自己的駭客實驗室
- 掌握使用 shift-left 和 shield-right 方法構建穩健 API 的藝術,涵蓋 API 生命週期
- 購買印刷版或 Kindle 書籍可獲得免費 PDF 電子書
書籍描述:
隨著 API 採用的指數增長,對其實施和固有漏洞的安全擔憂也隨之上升。對於那些尋求全面見解以建立、部署和管理 API 作為網路防禦第一道防線的人來說,這本書提供了寶貴的指導。由一位資深的 DevSecOps 專家撰寫的《保護 API》針對 API 安全的迫切任務,提出了創新的方法和技術,以應對特定於 API 的安全挑戰。
前幾章專注於 API 的基本組件、利用漏洞駭客攻擊 API 以及近期違規案例的研究,而書籍的後續部分則著重於在現實場景中保護 API 所需的技能建設。
在清晰的逐步指導下,您將探索測試漏洞的攻擊技術、攻擊和利用 API。轉向防禦技術,本書為您提供有效的方法,以防範常見攻擊。書中穿插了大量案例研究,幫助您將所學技術應用於實踐,並提供深入見解和大量最佳實踐,以從基礎開始構建更好的 API。
在本書結束時,您將具備開發安全 API 的專業知識,並能針對針對 API 的各種網路威脅進行測試。
您將學到什麼:
- 探索 API 的核心要素及其在 API 開發中的協作角色
- 了解 OWASP API 安全十大漏洞,剖析 API 漏洞的根本原因
- 獲得高調 API 安全違規事件的見解,並附有實際範例和深入分析
- 使用對手用來攻擊 API 的攻擊技術來增強您的防禦策略
- 採用 shield-right 安全方法,如 API 閘道和防火牆
- 防範多個框架和語言(如 .NET、Python 和 Java)中的常見 API 漏洞
本書適合誰:
本書適合應用安全工程師、藍隊成員和希望建立針對 API 安全的應用安全計劃的安全專業人員。對於紅隊成員和滲透測試人員,本書提供了利用 API 漏洞的見解。API 開發人員將受益於理解、預測和防範對其 API 的潛在威脅和攻擊。雖然理解書中解釋的攻擊向量和防禦技術需要基本的軟體和安全知識,但對 API 安全的透徹理解是您開始的唯一需求。