Implementing Adaptive Rate Limiting and Honeytokens for Enhanced REST API Security in JavaScript Web Applications
Chinelo Lauren Nwobbi · NORMA · 2025
Application Programming Interfaces used for transmitting information remain vulnerable to various attack vectors. Current mitigation strategies involve employing API best practices such as static rate limiting, encryption and input validation, using machine learning algorithms to detect API misuse and other security frameworks. While these strategies support security, issues like computational complexity, costs and inflexibility hinder progress and security effectiveness. This paper analyses adaptive rate limiting and honeytoken mechanisms as a tool to enhance REST API security by proposing a model that integrates these mechanisms, analysing request behaviour when handling traffic. The proposed model obtained an accuracy rate of 86.36% when detecting bots and effectively applied rate limiting for identified bot and human threat actor traffic. This paper will support developers when building REST APIs with a ready tool for enhancing rate-limiting capabilities and strengthening API endpoints.