Cybersecurity Threats using Application Programming Interface (API)
Abu Kamruzzaman, Kutub Thakur, Md Liakat Ali · 2024
APIs have become increasingly popular among companies and developers. They are incredibly useful but can be exploited by hackers if proper security measures are not in place. This paper will discuss what APIs are and why companies use them, the different types of APIs, API architecture and protocols, the top cybersecurity threats that companies may encounter when using APIs, and the concepts of authentication and authorization. APIs are sets of rules and definitions that allow different software applications to communicate with each other. Companies use APIs to integrate their services with other applications, enabling interoperability, enhancing functionality, and providing better user experiences. There are various types of APIs, including open APIs, partner APIs, internal APIs, and composite APIs. Each type serves a different purpose and is used in different contexts. Understanding the architecture and protocols of APIs, such as REST, SOAP, and GraphQL, is crucial for developing robust and efficient APIs. However, the use of APIs also introduces several security risks. Companies may face threats such as data breaches, unauthorized access, and API injection attacks. Implementing strong authentication and authorization mechanisms is essential to safeguard APIs from these threats and ensure secure communication between applications. This paper aims to provide a comprehensive overview of APIs, literature review, highlighting APIs importance, usage, and the necessary security practices to protect them from potential vulnerabilities.