2

Cequence Security API Security Testing framework encourages early discovery of v...

 1 year ago
source link: https://siliconangle.com/2023/02/06/cequence-security-api-security-testing-framework-encourages-shift-left-efforts/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Cequence Security API Security Testing framework encourages early discovery of vulnerabilities

cequence.png
SECURITY

Application programming interface security startup Cequence Security Inc. today announced enhanced testing capabilities within its Unified API Protection Platform.

The new API Security Testing framework encourages so-called “shift-left” efforts, giving security and development teams tools to uncover and remediate API vulnerabilities in preproduction environments that could otherwise lead to business disruption when they go into production.

Using the newly enhanced service, security and development teams can integrate continuous and automated testing of their pre-production APIs into their development and release cycle. Where no API specifications exist, security teams can leverage real-time API traffic analysis to baseline API specifications based on runtime traffic, removing the need to search for legacy APIs or create specifications from scratch.

Key capabilities of the new offering include continuous integration/continuous development and collaboration tools integration with support for Gitlab, Azure DevOps, Jenkins and Bamboo. The integration allows developers to run tests against their preproduction APIs to detect and report security risks.

The new offering allows users to visualize results and remediate test failures, drilling down into details to understand quickly the compliance issues identified in preproduction APIs. Summary reports allow results to be exported and shared with API owners and development teams for quick remediation and re-execution of tests.

On the security side, the new offering scans for OWASP API and business logic risks, including shadow APIs and sensitive data exposure. Users can define customized sensitive data exposure and custom risk categories for different groups of APIs based on the industry.

“Driven by the rapid rise in API exploits caused by coding errors, security and development teams are looking at ways to improve their API testing efforts without jeopardizing their continuous development release cycles,” Varun Kohli, chief marketing officer at Cequence Security, said in a statement. “API Security Testing complements our runtime compliance capabilities that detect security risks such as business logic abuse and OWASP API Top 10 risks in production APIs.”

Subbu Iyer, vice president of product management, and Ameya Talwalka, founder and chief executive officer of Cequence, spoke with theCUBE, SiliconANGLE Media’s livestreaming studio, in September on how APIs are becoming an irresistible target for attackers:

Image: Cequence Security

A message from John Furrier, co-founder of SiliconANGLE:

Show your support for our mission by joining our Cube Club and Cube Event Community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger and many more luminaries and experts.

Join Our Community 

Click here to join the free and open Startup Showcase event.

“TheCUBE is part of re:Invent, you know, you guys really are a part of the event and we really appreciate your coming here and I know people appreciate the content you create as well” – Andy Jassy

We really want to hear from you, and we’re looking forward to seeing you at the event and in theCUBE Club.

Click here to join the free and open Startup Showcase event.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK