Webinar

Positive API Security Model, and Why You Need It!

December 10, 2019

Webinar Thumb Preview-1024x585px copy

Many of the issues on the OWASP API Security Top 10 are triggered by the lack of input or output validation.

To protect APIs from such issues, an API-native, positive security approach is required: we create an allowlist of the characteristics of allowed requests. These characteristics are used to validate input and output data for things like data type, min or max length, permitted characters, or valid values ranges. But how do we fill the gap between security and development mentioned above?

What you’ll learn:

    • Why WAFs fail in protecting APIs
    • How an allowlist protects against A3, A6 and A8 of the OWASP API Security Top 10 – (with real-life examples)
    • How to build a proper allowlist for API security

Speaker

Isabelle Mauny
Isabelle Mauny

Field CTO and Co-founder

   

Watch the Webinar

Browse the Deck

Latest Resources

BLOG

Mind the Gap! How API Security Testing Tools Complement API Gateways for Enhanced API Security

By Axel Grosse | March 15, 2023

“I want security, yeah Without it I had a great loss, no now Security, yeah And I want it at any cost …” (Otis Redding, 1964) Otis Redding may well have been singing about the love for another in these famous lines, but taken literally, his message will […]

NEWS

42Crunch Announces Next Generation of API Security Testing Services at Gartner® Security & Risk Management Summit 2023

By Hugh Carroll | June 5, 2023

42Crunch announces the latest set of API security testing and threat protection capabilities:
Support for scenarios testing
Automatic authorization testing to detect API 1 and API 5
Automatic authentication testing to detect API 2 issues

DataSheet

Datasheet Cover Images P1-02

Product Datasheet Addressing API Security Challenges

APIs are the core building block of every enterprise’s digital strategy, yet they are also the number one attack surface for hackers. 42Crunch makes developers’ and security practitioners' lives easier by protecting APIs, with a platform that automates security into the API development pipeline and gives full oversight of security policy enforcement at every stage of the API lifecycle.

Ready to Learn More?

Developer-first solution for delivering API security as code.