Welcome to Technology Trends

Providing technology buying information for more than 10 million IT and business executives.

Home >> Resources >> 什麼是 API 閘道 ?

為什麼 API 閘道不足 以確保 API 安全


  • 現代 API 威脅情勢已變得相當多樣化且複雜。多數 攻擊者都可以輕鬆躲避傳統的安全特徵碼與根據 速率的規則。根據 Security Magazine 所發布的 研究結果,94% 的企業曾遭受 API 安全事件,且 API 攻擊流量已成長至整體 API 流量速率的三倍 以上。1. 與實際有效防護相比,根據基本特徵碼的 規則可能造成更多危害(如誤報)。
  • OWASP 安全十大 2. 辨識出許多攻擊向量,這些 攻擊手段所需要的有效安全策略,遠超越根據特徵 碼防禦和被動安全模式所能提供的防護。舉例來說, OWASP 十大排名第一的威脅是惡意機器人,其可透 過應用程式的 API 創造不同類型的攻擊─從 帳戶盜用(ATO)到應用程式分散式阻斷服務(DDoS) 攻擊和網頁抓取。儘管機器人傳送的每個唯一的 API 呼叫可能看起來正當且無害,但必須偵測與封鎖的 是所有 API 呼叫的序列及總和。
  • 另一個範例是,不同應用程式組成部分之間透過內部 API 進行東西向流量擴散。API 閘道 置於使用者與應用程式的前端伺服器之間,因此可監控來自外部(南北流量)的 API 呼叫, 但防止其監控在不同應用程式組成部分之間(東西向)執行的 API 呼叫。只有整合到各種 應用程式微服務中的企業級 API 防護解決方案,才能保護東西向 API 呼叫。
  • API 閘道的安全功能(如用戶端認證與授權)是任何 API 部署策略上的重要部分。不過, API 閘道並非專為提供先進的安全能力所設計,因此很多 API 廠商以整合的方式,提供更 全方位的 API 安全解決方案

If you engage with the content, Technology Trends will share your data with radware. For details on their information practices and how to unsubscribe, see their Privacy Statement. You can unsubscribe at any time. Privacy Statement.

White Paper from Technology Trends

Get your free copy now!

* - marks a required field

Answer the following questions about your organization below:



You have been directed to this site by Technology Trends. For more details on our information practices, please see our Privacy Policy, and by accessing this content you agree to our Terms of Use. You can unsubscribe at any time.