{"id":18103,"date":"2024-01-16T10:00:15","date_gmt":"2024-01-16T10:00:15","guid":{"rendered":"https:\/\/staging2022.42crunch.com\/?p=18103"},"modified":"2024-02-28T16:28:00","modified_gmt":"2024-02-28T16:28:00","slug":"how-42crunch-and-microsoft-are-solving-the-api-security-challenge","status":"publish","type":"post","link":"https:\/\/staging2022.42crunch.com\/how-42crunch-and-microsoft-are-solving-the-api-security-challenge\/","title":{"rendered":"How 42Crunch and Microsoft are Solving the API Security Challenge"},"content":{"rendered":"

42Crunch and Microsoft have partnered to provide continuous protection for APIs<\/h3>\n

Recently 42Crunch and MIcrosoft announced a partnership to address the number one security issue challenging organizations today, namely the large and growing attack surface represented by APIs.\u00a0\u00a0<\/span><\/p>\n

Application security practitioners have come to realize that application security tooling like SAST\/DAST and Web Application Firewalls (WAFs) are not optimized to protect against the unique and varied threats posed by APIs. A complementary API-specific security approach is required.\u00a0\u00a0<\/span><\/p>\n

Key challenges according to Gartner \u00ae<\/sup> are \u201cProtecting web APIs with general purpose application security solutions alone continues to be ineffective. Each new API represents an additional and potentially unique attack vector into your systems.\u201d1<\/sup><\/p><\/blockquote>\n

By integrating our API security testing capabilities with the runtime protection features provided by Microsoft\u2019s Defender for APIs, we are excited to jointly deliver an end to end API security solution that embodies modern DevSecOps principles.\u00a0\u00a0\u00a0<\/span><\/p>\n

What is end to end API security?<\/b>\u00a0<\/span><\/p>\n

End to end API security refers to a comprehensive approach to securing the entire lifecycle of an API, from its design and development to its deployment and ongoing operation. A key hallmark of this approach is that API security is a shared responsibility across various teams responsible for build and delivery. Given that security professionals are vastly outnumbered by developers in most companies, making security part of everyone\u2019s job is the only way to scale.\u00a0 At 42Crunch, our mission is to give tools to developers that help them build more secure APIs without sacrificing productivity or agility. <\/span>\u00a0<\/span><\/p>\n

Gartner recommends enterprises \u201cadopt a continuous approach to API security across the API development and delivery cycle, designing security into APIs. Include API security testing and the creation and application of reusable API security policies.\u201d2<\/sup><\/p><\/blockquote>\n

The integration of our API security audit and vulnerability testing solutions with Microsoft Defender for Cloud now provides Microsoft customers across all industries with continuous protection of their APIs from design to runtime.\u00a0\u00a0<\/span><\/p>\n

Achieving Continuous API Security<\/b>\u00a0<\/span><\/p>\n

As we discussed in a recent<\/span> blog post<\/span><\/a>, much of the early attention in the API Security space has been given to API behavior monitoring tools which have produced mixed results. As the space has evolved, security teams have begun to expand the scope of their API Security programs to include developer tooling and security testing. By adding a more proactive approach towards API Security, enterprises have benefited in numerous ways:\u00a0<\/span><\/p>\n