Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
APIDays_Design_API_Security.pdf
Search
Emmanuel Paraskakis
July 31, 2018
Programming
110
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
APIDays_Design_API_Security.pdf
Keynote at API Days San Francisco, 2018. A Design-First Approach for API Security.
Emmanuel Paraskakis
July 31, 2018
More Decks by Emmanuel Paraskakis
See All by Emmanuel Paraskakis
The Double Life of the API Product Manager
paraskakis
0
130
The AI-Powered API Builder: Speeding Up API Delivery with AI Tools
paraskakis
0
70
How to break into API Product Management
paraskakis
0
99
API Best Practices
paraskakis
0
270
Outside-in Development for APIs and Microservices
paraskakis
0
77
Become a Pro at API Management: A declarative approach
paraskakis
0
380
API Design Hands-On Lab
paraskakis
0
100
Bring Design Thinking to your API Lifecycle
paraskakis
0
160
Decomposing Service Descriptions: The Future of API Design
paraskakis
0
890
Other Decks in Programming
See All in Programming
Japan Community Day at Kubecon + CloudNativeCon Japan 2026: Learning Container Privilege Control by Building My Own Low-Level Container Runtime
ternbusty
1
170
DynamoDBの基礎を振り返りながらベクトル検索機能を理解する
musan
2
210
「人を評価する AI」の設計と実装
ryoyanara
0
240
属人化した知識を、 AIが辿れる地図にする
pkshadeck
PRO
1
210
Jindong: Introducing Declarative Haptics in Compose Multiplatform
l2hyunwoo
0
130
仕様書を書く前にハーネスを作る - Agent Native開発は「探索を速く、判定を固く」
gotalab555
4
1.8k
楽しそうなつよつよエンジニアと目が死んでる僕/A brilliant engineer having a blast, and dead-eyed me.
3l4l5
2
250
TSX の <Hoge<Fuga>> という構文に驚いた話 / tsx-type-argument-syntax
kanaru0928
0
240
初めての模倣学習とVLA
natsutan
0
250
AWS DevOps AgentのAzure接続機能を検証して見えた活用法/Use Cases Verified for the AWS DevOps Agent's Azure Connectivity Feature
masakiokuda
1
270
Webエンジニアなのにブラウザの仕組みがわからないので、Pythonで自作してみた
tatsuki12
4
1.1k
書籍「プロフェッショナルAI駆動開発」紹介スライド
juntaromatsumoto
0
590
Featured
See All Featured
What the history of the web can teach us about the future of AI
inesmontani
PRO
1
670
Sharpening the Axe: The Primacy of Toolmaking
bcantrill
46
3k
From Legacy to Launchpad: Building Startup-Ready Communities
dugsong
0
310
JAMstack: Web Apps at Ludicrous Speed - All Things Open 2022
reverentgeek
1
580
HDC tutorial
michielstock
2
820
Building AI with AI
inesmontani
PRO
1
1.2k
Impact Scores and Hybrid Strategies: The future of link building
tamaranovitovic
0
420
Avoiding the “Bad Training, Faster” Trap in the Age of AI
tmiket
0
210
Leveraging LLMs for student feedback in introductory data science courses - posit::conf(2025)
minecr
1
360
Claude Code どこまでも/ Claude Code Everywhere
nwiizo
67
57k
Building Experiences: Design Systems, User Experience, and Full Site Editing
marktimemedia
0
580
How to audit for AI Accessibility on your Front & Back End
davetheseo
0
510
Transcript
Emmanuel Paraskakis @manp A Design-First Approach for Delivering Better API
Security
apiary + 441,401 APIs 3M+ API Consumers 346,105 API Designers
Infosec Goals 1. Confidentiality 2. Integrity 3. Availability
What’s Different About APIs? Attack Surface is Huge!
Defense In-Depth • Enforce CIA at every layer in your
stack • Assume there will be a failure in each
What does Design-First Mean? • Think about Security upfront •
Don’t bolt it on at the end • Buying Silver Bullets won’t save you
Design For API Security • Architecture • Processes • API
Interface
Design your Architecture
Design your Processes
Design your API Interface • Authentication Scheme • Leverage the
Protocol • Data Structures & Validation
openapi: "3.0.1" info: title: Online Store API version: 1.0 …
servers: - url: https://staging.example.com/ description: Staging environment … security: - api_key: [] … x-ibm-configuration: enforced: true cors: enabled: true … paths: /customers/{id}/orders: get: … content: application/json: schema: $ref: "#/components/schemas/Orders" … components: schemas: Orders: … metadata deployment runtime interface schema
Learn More: • OWASP API Security Project • Dredd •
Apiary • Oracle API Platform • Oracle+Dyn (Zenedge)