Akamai Finds API Vulnerabilities to be a High-Stakes Game for Companies and Individuals Worldwide
APIs are inherently designed to be fast and easy pipelines between different platforms. While this priority on convenience and user experience leads APIs to be highly essential to many businesses, it also makes them appealing targets for cybercriminals. Akamai's report highlights the frustrating patterns of API vulnerabilities, despite the improvements that have been made in Software Development Life Cycles (SDLCs) and testing tools. Often, API security is relegated to an afterthought in the rush to bring them to market, with many organizations relying on traditional network security solutions that are not designed to protect the wide attack surface that APIs can introduce.
"From broken authentication and injection flaws, to simple misconfigurations, there are numerous API security concerns for anyone building an internet-connected application," said
It's not always clear where API vulnerabilities live. For example, APIs are often hidden within mobile apps, leading to the belief that they are immune to manipulation. Developers make the assumption that users will only interact with the APIs via the mobile user interface (UI), but, as noted in this report, that's not the case.
Spikes in
Also detailed in the report, Akamai reviewed 18 months of attack traffic between
While difficult to pinpoint the above attacks in terms of the percentage of purely API attacks, the
Additional report highlights include:
- Credential stuffing attacks tracked across the 18 months between
January 2020 andJune 2021 remained steady, with single day peaks of over 1 billion attacks recorded inJanuary 2021 andMay 2021 . - The
U.S. was the top target for web application attacks during this observed period, with nearly six times the amount of traffic thanEngland , which ranked second. - The
U.S. was also in the top spot on the source list for attacks, taking first place away fromRussia , with almost four times the amount of traffic. - DDoS traffic has remained consistent in 2021 so far, with peaks recorded earlier in Q1 2021. In
January 2021 , Akamai recorded 190 DDoS events in a single day, followed by 183 in March.
Read the Akamai 2021 'API: The Attack Surface That Connects Us All' report, on our State of the Internet page.
For additional information, the security community can access, engage with, and learn from Akamai's threat researchers and the insight that the Akamai Intelligent Edge Platform affords into the evolving threat landscape by visiting Akamai's Threat Research Hub.
About Akamai
Akamai powers and protects life online. The most innovative companies worldwide choose Akamai to secure and deliver their digital experiences - helping billions of people live, work, and play every day. With the world's largest and most trusted edge platform, Akamai keeps apps, code, and experiences closer to users - and threats farther away. Learn more about Akamai's security, content delivery, and edge compute products and services at www.akamai.com, blogs.akamai.com, or follow
Contacts:
Media Relations
858-404-1436
hyang@akamai.com
Investor Relations
617-274-7130
tbarth@akamai.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/akamai-finds-api-vulnerabilities-to-be-a-high-stakes-game-for-companies-and-individuals-worldwide-301409125.html
SOURCE
