您的浏览器禁用了JavaScript(一种计算机语言,用以实现您与网页的交互),请解除该禁用,或者联系我们。[Google]:2022年API安全性研究报告 - 发现报告
当前位置:首页/行业研究/报告详情/

2022年API安全性研究报告

信息技术2022-11-28-Google看***
2022年API安全性研究报告

GoogleCloud APISecurity:Latest Insights&KeyTrends 2022ResearchReport HowAPIsecurityisimpactingthepaceofinnovationatenterprisesand whatITleadersaredoingtomitigaterisks TableofContents ExecutiveSummary3 Threatsabound4 Affectingthepaceofinnovation ActiveAPIsecuritypostureisnecessary CurrentAssessment ConfidentinthefaceofthreatsIsthisconfidencemisplaced? CompaniesprioritizebeingproactivewithAPIsecurity8 Opportunities9 Consolidation,end-to-endmonitoring,oversightneeded6 Moretrainingandcertificationinthisspaceisneeded9 MostagreetheirstrategyneedsimprovementoL APIsecuritystrategynotalwaysatoppriority11 TheimpactofAPlmanagementandAPlgatewaysolutions11 APIsecurityisakeyelement ofalargerAPIstrategy12 2022GoogleLLC.AIrightsreservedN ExecutiveSummary Withtheincreasingadoptionofdigitalexperiences,theuseofApplicationProgrammingInterfaces,orAPlsisontherise.Assuch,APlsrepresentasignificantareaofvulnerabilityfororganizationsworldwide ThefollowingreportexaminesthelandscapeofAPIsecuritythreatsandtheirimpactonthepaceofinnovation.ItdelvesintotheworldviewofthetechnologyleadersasitpertainstoAPIsecurityposture andstrategy,andoffersaperspectiveonopportunitiestoimproveAPIsecurityhealth. ThisreportisbasedonresearchconductedbyGoogleCloudbetweenMayandJune2022among technologyleadersfromcompaniesintheUnitedStateswithatleast1,500employeeswhohaveasignificantinfluenceordecision-makingauthorityonpurchasesoftechnologysolutionsrelatedtoAPlinitiativeswithintheirorganization "WhyAPISecuritylsaKeyElementofaLargerAPIStrategyexplainsthatAPIsecuritypostureisa growingconcernforITexecutivesduetotheprevalenceofthreats,butthatmostorganizationsneedtoimprovetheirAPIsecuritystrategy.Thereisaneedforproactivesecuritycapabilitiesandmeasuresas wellasend-to-endAPIsecuritysolutionssuchasApigee,afullifecycleAPImanagementplatform TheThreatLandscape Threatsabound CompaniesworldwiderelyonApplicationProgrammingInterfaces,orAPls,tofacilitatedigitalexperiencesandunleash Morethanthreeoutof thepotentialenergyoftheirowndataandprocesses.APlsareafiveC-SuiteITDMs criticallinkinblendingproprietarydatawithassetsfromthird parties.Theyalsoserveacriticalroleintheracetomodernize applications,fuelinginteroperabilityand,inturn,efficient reportexperiencingan APIsecurityincident functionality.inthepast12months. ButtheproliferationandimportanceofAPlscomeswitharisk. AsagatewaytoawealthofinformationandsystemsAPlshavebecomeafavoritetargetforhackers. "Therateatwhich APlsaredeveloped Ourresearchconfirmsthewidespreadimpactofthesethreats. todayexceedstherate HalfofthemreportexperiencinganAPIsecurityincidentintheatwhichour past12months.Thatpercentageishigherorlowerdependingorganizationcan onwhoyouask.62%ofC-Suiteexecutivessurveyedindicatedthatthey'vehadasecurityincidentinthepast12monthswhile ensurethesecurityof only37%ofthosewhoareacouplelevelsremovedfromthe eachoftheseAPls." C-Suitesaidthesame. ThiscouldpointtowardthelimitedpurviewoffunctionalIT teams,oritcouldbeanindicationofhowsalienttheissueisfor -ITSupervisor/Manager, ComputerHardware/ Software/Services thosewithgreaterresponsibility.Orboth. APISecurityIncidents 50%62% oforganizationshaveofITDMsintheC-Suite experiencedanAPI securityincidentinthe reporthavingAPIi securityincidentinthe past12monthspast12months Tocompoundtheissue,threatssurfacefromamyriadofAPIsecurityareaswithIT leaderseachidentifyingmorethanthreeareasonaverage.Whilenosingleareastands outasaglaringvulnerability,thethreemostcommonsourcesofpotentialthreatsaresecuritymisconfigurations,outdatedAPls/data/components,andbots/spam/abuse. Misconfigurations,asacategory,arethemostidentifiedthreatareawith2of5ITleaders selectingeithersecuritymisconfigurationormisconfiguredAPIs. SourcesofAPISecurityThreats MisconfiguredAPIs,Security(NET) 40% OutdatedAPls,Data,Components(NET)35% Spam,Abuse,Bots(NET)34% Affectingthepaceofinnovation Thesethreatsandincidentshavereal-worldimplications.APIsecurityisslowingthepace therolloutofanewserviceorapplicationduetoAPIsecurityconcerns.Forthosewho haveexperiencedanincidentinthepast12months,morethanthreequarters(77%)havedelayedtherolloutofanewserviceorapplication. DelayedtheRolloutofaNewServiceorApplicationDuetoAPISecurityConcerns 53%77% oforganizationsdelayedoforganizationsthat therolloutofanewexperiencedanAPI serviceorapplicationduetoAPIsecurity securityincidentdelayed arollout e2022GoogleLLC.AIrightsreservedn ActiveAPlsecuritypostureisnecessary Withsecurityvulnerabilitiesbeingintroducedfromavarietyof sourcesthroughoutdevelopment,itwillcomeasnosurprisethat C-Suiterespondents securityissuesareidentifiedateveryphaseoftheAPIlifecycleweremorelikelythan fromdesigntotestingtodeploymentandbeyond.Naturally.securityissuesaremostcommonlydiscoveredduringtesting performedaspartofthereleasemanagementprocess(67%), ITleaderswhoreport uptoexecutivesto butasubstantialnumberofvulnerabilitiesareidentifiedaspartsayvulnerabilitiesare oftheprocesstodeploytoproduction(64%).Thisindicatedan caughtduringthe areaofriskforvulnerabilitiestobedeployedtoproductionasaconsiderablepercent

你可能感兴趣

hot

2022年API安全性研究报告

信息技术
Google2022-12-07
hot

2022年中国企业邮箱安全性研究报告

信息技术
奇安信2023-05-04
hot

2021中国企业邮箱安全性研究报告

信息技术
奇安信2022-11-27