Welcome to Technology Trends

Providing technology buying information for more than 10 million IT and business executives.

Home >> Resources >> 什么是 API 网关 ?

为什么 API 网关不足以 确保 API 安全


  • 现代 API 威胁情势已变得相当复杂且多样化。多数 攻击者都可以轻松逃避传统的安全特征库和基于速 率规则。根据 Security Magazine 所发布的研究结果, 94% 的企业曾遭受过 API 安全事件,且 API 攻击流量已成长至整体 API 流量速率的三倍以上。1. 与实际有效防护相比,根据基本特征库的规则可造 成更多危害(如误报)。
  • OWASP API Security Top 102. 确定了众多攻击媒 介,这些攻击手段需要有效安全策略,远远超出了 基于特征库的防御和被动安全模型。例如,OWASP Top 10 中排名第 1 的威胁是恶意机器人,其可通过 应用程序的 API 创建不同类型的攻击─从账户接管 (ATO)到应用程序分布式拒绝服务(DDoS)攻击 和 Web 爬取。尽管机器人每次发送的唯一 API 调用可能看起来合法无害,但必须检测所有 API 调 用的顺序并进行拦截
  • 另一个例子是通过不同应用程序组件之间的内部 API 调用导致东西向流量的激增。API 网关位于用户 与应用前端服务器之间,因此可监控来自外部(南北向流量)的 API 调用,但无法监控不 同应用程序组件之间(东西向流量)的 API 调用。只有集成到各种应用微服务中的企业级 API 保护解决方案才能保护东西向 API 调用。
  • API 网关的安全功能(如客户端认证与授权)是任何 API 部署策略的重要组成部分。但是, API 网关从设计之初并未考虑提供高级的安全功能,这就是为什么许多 API 厂商提供更全 面的 API 安全解决方案的原因。

If you engage with the content, Technology Trends will share your data with radware. For details on their information practices and how to unsubscribe, see their Privacy Statement. You can unsubscribe at any time. Privacy Statement.

White Paper from Technology Trends

Get your free copy now!

* - marks a required field

Answer the following questions about your organization below:



You have been directed to this site by Technology Trends. For more details on our information practices, please see our Privacy Policy, and by accessing this content you agree to our Terms of Use. You can unsubscribe at any time.