Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
APIDays_Design_API_Security.pdf
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
Emmanuel Paraskakis
July 31, 2018
Programming
120
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
APIDays_Design_API_Security.pdf
Keynote at API Days San Francisco, 2018. A Design-First Approach for API Security.
Emmanuel Paraskakis
July 31, 2018
More Decks by Emmanuel Paraskakis
See All by Emmanuel Paraskakis
The Double Life of the API Product Manager
paraskakis
0
130
The AI-Powered API Builder: Speeding Up API Delivery with AI Tools
paraskakis
0
83
How to break into API Product Management
paraskakis
0
110
API Best Practices
paraskakis
0
280
Outside-in Development for APIs and Microservices
paraskakis
0
84
Become a Pro at API Management: A declarative approach
paraskakis
0
390
API Design Hands-On Lab
paraskakis
0
110
Bring Design Thinking to your API Lifecycle
paraskakis
0
170
Decomposing Service Descriptions: The Future of API Design
paraskakis
0
900
Other Decks in Programming
See All in Programming
RAG の “R” を Swift で覗いてみる 〜「意味から探す」検索の仕組み〜
nao_randd
0
120
When benchmarks go bad - what I learned from measuring performance wrong
hollycummins
0
130
コードレビューのボトルネックを"する側"と"される側"の両面から解消する
yub0n
2
1.5k
SalesForceを内製化!? ~ HR事業を支える顧客管理基盤のインフラを大公開 ~
oku053
0
120
ソニーのクラウド共通基盤の変遷とAI時代の開発スタイルに合わせた進化 / The Journey of Sony’s Common Cloud Platform and Its Evolution for AI-Native Development
kenjiyoneyama
0
230
動作中のプログラムの中身をリアルタイムに覗く / Realtime Debugger for CSharp with Roslyn
prota
1
1.8k
すこし踏み込む CancellationToken
htkym
2
1.6k
Herb in Rails 8.2: Your ERB views, now HTML-aware @ Rails World 2026, Austin, Texas
marcoroth
0
190
Domain-Driven Transformation
hschwentner
2
2.3k
Augmenting AI with the Power of Jakarta EE
ivargrimstad
0
450
見えないものを探る要求要件定義に必要な基本的思考 / invisible-requirement-thinking
minodriven
13
6.6k
難しいけど、読めた。- OSSの入口に立った話。
sts11142
0
140
Featured
See All Featured
Game over? The fight for quality and originality in the time of robots
wayneb77
1
300
How Fast Is Fast Enough? [PerfNow 2025]
tammyeverts
3
920
SERP Conf. Vienna - Web Accessibility: Optimizing for Inclusivity and SEO
sarafernandez
2
1.6k
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
50
10k
Efficient Content Optimization with Google Search Console & Apps Script
katarinadahlin
PRO
1
910
Reflections from 52 weeks, 52 projects
jeffersonlam
356
21k
Accessibility Awareness
sabderemane
1
230
Measuring & Analyzing Core Web Vitals
bluesmoon
9
1k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
6.1k
How To Speak Unicorn (iThemes Webinar)
marktimemedia
1
590
The Success of Rails: Ensuring Growth for the Next 100 Years
eileencodes
47
8.4k
New Earth Scene 8
popppiees
4
2.6k
Transcript
Emmanuel Paraskakis @manp A Design-First Approach for Delivering Better API
Security
apiary + 441,401 APIs 3M+ API Consumers 346,105 API Designers
Infosec Goals 1. Confidentiality 2. Integrity 3. Availability
What’s Different About APIs? Attack Surface is Huge!
Defense In-Depth • Enforce CIA at every layer in your
stack • Assume there will be a failure in each
What does Design-First Mean? • Think about Security upfront •
Don’t bolt it on at the end • Buying Silver Bullets won’t save you
Design For API Security • Architecture • Processes • API
Interface
Design your Architecture
Design your Processes
Design your API Interface • Authentication Scheme • Leverage the
Protocol • Data Structures & Validation
openapi: "3.0.1" info: title: Online Store API version: 1.0 …
servers: - url: https://staging.example.com/ description: Staging environment … security: - api_key: [] … x-ibm-configuration: enforced: true cors: enabled: true … paths: /customers/{id}/orders: get: … content: application/json: schema: $ref: "#/components/schemas/Orders" … components: schemas: Orders: … metadata deployment runtime interface schema
Learn More: • OWASP API Security Project • Dredd •
Apiary • Oracle API Platform • Oracle+Dyn (Zenedge)