Richard Bird
speaker
50 appearances
1 recordings
1 series
first heard Oct 2024
last heard Oct 2024
Richard Bird’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
you have to look at the reality of a next-gen set of capabilities because the first and second gen have shown themselves incapable of being able to apply the necessary level of granularity and context to achieve API security. So the first is admitting you have a problem.
The second, truthfully, from a pure outcomes standpoint, evaluate your current tool base and recognize that in every API security breach of the last decade, Six years, every one of those organizations had a web application firewall or CDN in place. So why did they get breached if those technologies are now telling them we could have stopped that or we can stop that?
And then the next step is to move into where API security is actually happening today from a startup and solution standpoint, which is in the API security platform space. and recognize that this is a holistic effort, not a point solution. It's not enough to know all the APIs that you have. You need to understand the risk and criticality of those APIs.
It's not enough to test those APIs, say, on the AST DevOps side of the equation. You need to be able to address the current vulnerabilities and risk associated with the APIs that have been in production in your organization for years. Threatened vulnerability management. It's not enough to understand signature attacks from a tooling standpoint.
You have to have a platform that has the capability to divine and understand unknown unknowns because it's comparing known normal of an API, what that spec is, to how that API is being abused and used for bad purposes.
And unless you understand the delta between those two, then you're always going to be relying on somebody giving you vulnerabilities in the old kind of semantic AVG way of giving you a subscription list, as opposed to finding those exploits and vulnerabilities without having to sign up for all of that research feed. And then I think finally, you have to look at an API security tool
from the standpoint of what will come next, which is a move into runtime protection, where a signal will be taken off of that intelligent engine that's comparing normal to abnormal. And then that signal will be passed to an application to a microservice
to any number of other ways that APIs are used, where security will be invoked in that moment, and it doesn't go through some kind of policy creation, some firewall somewhere, some other type of kludgy method to try and protect an organization with a sledgehammer by doing an IP block, but you'll be able to use a surgical scalpel to be able to address the actual weakness that's manifesting.
The short answer to the long answer I just gave is, is the API security platform you need to be looking for needs to be answering all those questions because APIs operate across that entire infinite loop lifecycle. They don't just one and done. And so you need to be able to actually address security across the entirety of an API's existence.
And not just one, but the hundreds and the thousands and tens of thousands you're exposed to.
Showing 41–50 of 50 · page 3 of 3
← Previous