Keamanan API adalah add-on berbayar untuk WAF yang menggunakan kebijakan deteksi bawaan dan kustom untuk menemukan aset API, mendeteksi risiko, serta melaporkan peristiwa serangan. Fitur ini juga mendukung tinjauan data lintas batas dan pelacakan kebocoran data sensitif demi memenuhi persyaratan kepatuhan.
Kasus penggunaan
Temukan API yang tidak dikenal dan bangun inventaris asetSeiring pesatnya pertumbuhan jumlah API akibat iterasi bisnis yang cepat, pengembang mungkin menerbitkan API tanpa melalui tinjauan tim keamanan atau lupa menonaktifkan API yang sudah usang. Hal ini menciptakan celah dalam inventaris aset API Anda dan menimbulkan titik buta dalam manajemen keamanan. Fitur asset management menganalisis log akses bisnis secara offline untuk secara otomatis mendeteksi semua endpoint API dalam lalu lintas Anda serta mengidentifikasi tujuan bisnisnya berdasarkan karakteristik antarmuka. | Deteksi risiko keamanan API dan pantau serangan terhadap APIDesain atau konfigurasi API yang tidak tepat dapat menimbulkan kerentanan keamanan, memungkinkan penyerang mengakses antarmuka sensitif tanpa otorisasi atau menyebabkan kebocoran informasi sensitif—seperti nomor telepon dan nomor kartu bank—melalui tanggapan. Fitur risks and events memungkinkan analisis risiko yang akurat dan memberikan rekomendasi remediasi yang dapat ditindaklanjuti untuk membantu mendeteksi akses anomali dan serangan secara tepat waktu. | Identifikasi risiko data lintas batas dan lacak kebocoran data sensitif(Hanya untuk Tiongkok daratan) Jika bisnis Anda perlu mentransfer data ke wilayah luar Tiongkok daratan, Anda harus mengajukan permohonan penilaian keamanan ekspor data kepada administrasi siber nasional melalui administrasi siber provinsi. Fitur security compliance review and traceability audit melakukan tinjauan dan pelacakan terhadap data outbound untuk membantu Anda mengidentifikasi risiko data serta melakukan cross-reference terhadap event keamanan. |
Assess your API security posture
Sebelum mengaktifkan Keamanan API, Anda dapat menggunakan fitur Basic Detection untuk menilai postur keamanan API Anda. Fitur ini diaktifkan secara default dan gratis di semua instans WAF 3.0, menganalisis log WAF secara offline, serta menyediakan ikhtisar peristiwa keamanan, ikhtisar aset, dan daftar peristiwa keamanan. Halaman ini menampilkan statistik mengenai aset API dan peristiwa anomali, serta mencantumkan 10 peristiwa panggilan API anomali terbaru.
Basic Detection memiliki kemampuan deteksi yang lebih terbatas dibandingkan layanan Keamanan API berbayar. Hasilnya mungkin mengalami ketidaksesuaian atau keterlambatan.
Basic Detection tidak menyediakan tampilan data terperinci.
Buka halaman API Security. Dari bilah menu atas, pilih kelompok sumber daya dan wilayah (Chinese Mainland atau Outside Chinese Mainland).
Pada bagian Basic Detection, Anda dapat melihat data deteksi dasar.
Ikhtisar peristiwa keamanan: Total peristiwa keamanan API dan jumlah berdasarkan tingkat risiko (tinggi, sedang, rendah).
Ikhtisar aset: Total aset API, API aktif, dan API tidak aktif.
Peristiwa keamanan: Kartu yang menampilkan nama peristiwa, jalur API, domain, sumber serangan, dan waktu untuk setiap peristiwa.
Aktifkan layanan keamanan API
Keamanan API melakukan semua perhitungan dan analisis secara offline. Layanan ini tidak melakukan probing aktif terhadap API Anda dan tidak berdampak pada operasi bisnis Anda.
Keamanan API mengidentifikasi risiko kebocoran data dengan mendeteksi permintaan dan respons yang sesuai dengan karakteristik tertentu. Dengan mengaktifkan Keamanan API, Anda memberi otorisasi kepada WAF untuk melakukan analisis tersebut. Sebelum mengaktifkan, Anda harus mengevaluasi layanan ini berdasarkan skenario bisnis aktual Anda.
Buka halaman API Security. Dari bilah menu atas, pilih kelompok sumber daya dan wilayah (Chinese Mainland atau Outside Chinese Mainland).
Aktifkan Keamanan API.
Mulai uji coba gratis Keamanan API
CatatanEdisi Pro, Enterprise, dan Ultimate menawarkan uji coba gratis satu kali selama 7 hari untuk Keamanan API.
Setelah masa uji coba berakhir, jika Anda belum membeli versi resmi, data analisis yang dihasilkan selama uji coba akan segera dihapus. Untuk menyimpan data uji coba, beli versi resmi Keamanan API sebelum masa uji coba berakhir.
Pada halaman API Security, klik Request a Free 7-Day POC.
Beli versi resmi Keamanan API
Pada halaman API Security, klik Enable Now. Setelah memilih untuk mengaktifkan Keamanan API, klik Buy Now dan selesaikan pembayaran.
Kemampuan keamanan API
Klasifikasi tujuan bisnis
Bagaimana Keamanan API mengklasifikasikan tujuan bisnis API?
Keamanan API mengklasifikasikan tujuan bisnis API dengan mencocokkan karakteristik URL dan nama parameter menggunakan kebijakan bawaan. Anda juga dapat mengonfigurasi kebijakan identifikasi kustom.
Tujuan | Nama tipe |
User authentication | Account password-based logon, mobile verification code-based logon, email verification code-based logon, WeChat logon, Alipay logon, OAuth authentication, OIDC authentication, SAML authentication, SSO authentication, logon, logoff, password reset |
User registration | Account password-based registration, mobile verification code-based registration, email verification code-based registration, WeChat registration, Alipay registration, registration service |
Data operations | Database query, data upload, data download, data addition, data modification, data update, data sharing, data deletion, data synchronization, data submission, data copy, data auditing, data saving, data check |
Order management | Order query, order export, order update, order payment |
Log management | Log query, log reporting, log export, log service |
File management | File upload, file download, file service |
Notification | SMS message sending, mail sending, information sending, verification code verification |
Backend management | Backend management, data dashboard, monitoring service |
System control | Cancel, start, batch processing, pause, bind, debugging, settings, close, status check |
Technical services | GraphQL, SQL service, large model dialogue, MCP service |
Bagaimana Keamanan API mengidentifikasi objek layanan suatu API?
Tag objek layanan mengidentifikasi tipe pemanggil untuk suatu endpoint API berdasarkan karakteristik penamaan API dan pengelompokan sumber akses:
Internal office: API yang menyediakan layanan untuk karyawan internal.
Third-party cooperation: API yang menyediakan layanan untuk mitra ekosistem pihak ketiga.
Public service: API yang menyediakan layanan melalui Internet.
Deteksi data sensitif
Jenis data sensitif apa saja yang dapat dideteksi oleh Keamanan API?
Keamanan API mendeteksi informasi sensitif dalam permintaan dan respons API menggunakan model identifikasi bawaan. Anda juga dapat mengonfigurasi kebijakan deteksi kustom. Tingkat sensitivitas berkisar dari S1 hingga S4 (semakin tinggi = semakin sensitif), konsisten dengan standar Data Security Center (DSC).
Informasi identitas
Tipe data sensitif | ID tipe | Tingkat sensitivitas | Kategori |
ID Card Number (Chinese mainland) | 1000 | S3 | Personal information, Personal sensitive information |
Full Name (Simplified Chinese) | 1002 | S2 | Personal information |
Passport Number (Chinese mainland) | 1006 | S3 | Personal information, Personal sensitive information |
Mainland Travel Permit for Hong Kong and Macao Residents | 1007 | S3 | Personal information, Personal sensitive information |
License Plate Number (Chinese mainland) | 1008 | S3 | Personal information |
Military Officer Card | 1010 | S3 | Personal information, Personal sensitive information |
Gender | 1011 | S1 | Personal information |
Ethnic Group | 1012 | S1 | Personal information |
ID Card Number (Hong Kong, China) | 1015 | S3 | Personal information, Personal sensitive information |
Full Name (Traditional Chinese) | 1016 | S2 | Personal information |
Full Name (English) | 1017 | S2 | Personal information |
ID Card Number (Malaysia) | 1018 | S3 | Personal information, Personal sensitive information |
ID Card Number (Singapore) | 1019 | S3 | Personal information, Personal sensitive information |
SSN | 1023 | S3 | Personal information, Personal sensitive information |
Religious Belief | 1025 | S2 | Personal information, Personal sensitive information |
KARTU KELUARGA(KK) | 4412 | S3 | Personal information, Personal sensitive information |
Kartu Indonesia Pintar(KIP) | 4418 | S2 | Personal information |
Kontak dan lokasi
Tipe data sensitif | ID tipe | Tingkat sensitivitas | Kategori |
Address (Chinese mainland) | 1003 | S2 | Personal information |
Mobile Number (Chinese mainland) | 1004 | S3 | Personal information |
Email Address | 1005 | S2 | Personal information |
Phone Number (Chinese mainland) | 1009 | S2 | Personal information |
Province (Chinese mainland) | 1013 | S1 | N/A |
City (Chinese mainland) | 1014 | S1 | N/A |
Telephone Number (United States) | 1024 | S2 | Personal information |
Address(English) | 4410 | S2 | Personal information |
Keuangan dan pembayaran
Tipe data sensitif | ID Jenis | Tingkat sensitivitas | Kategori |
Debit Card | 1001 | S3 | Personal information, Personal sensitive information |
Lending Bank Card | 1020 | S3 | Personal information, Personal sensitive information |
SWIFT Code | 1022 | S1 | N/A |
Identifier jaringan dan perangkat
Tipe data sensitif | Type ID | Tingkat sensitivitas | Kategori data |
IP Address | 2000 | S2 | Personal information |
MAC Address | 2001 | S2 | Personal information |
IPv6 Address | 2007 | S2 | Personal information |
IMEI | 2010 | S2 | Personal information |
MEID | 2011 | S2 | Personal information |
URL | 2015 | S1 | N/A |
Kredensial dan kunci
Tipe data sensitif | Type ID | Tingkat sensitivitas | Kategori |
JDBC Connection String | 2002 | S3 | Personal information, Personal sensitive information |
PEM Certificate | 2003 | S3 | Personal information |
Private Key | 2004 | S3 | Personal information, Personal sensitive information |
AccessKey ID | 2005 | S3 | Personal information, Personal sensitive information |
AccessKey Secret | 2006 | S3 | Personal information, Personal sensitive information |
Linux Password File | 2013 | S3 | N/A |
Linux Shadow File | 2014 | S3 | N/A |
Alibaba Cloud AKSK key pair | 4399 | S3 | Personal information, Personal sensitive information |
Legacy OpenAI API Key | 4400 | S3 | Personal information, Personal sensitive information |
OpenAI Project API Key | 4401 | S3 | Personal information, Personal sensitive information |
Bailian API Key | 4402 | S3 | Personal information, Personal sensitive information |
HuggingFace API Key | 4403 | S3 | Personal information, Personal sensitive information |
Groq API Key | 4404 | S3 | Personal information, Personal sensitive information |
PAI-EAS Token | 4405 | S3 | Personal information, Personal sensitive information |
Identifier perusahaan dan umum
Tipe data sensitif | ID Jenis | Tingkat sensitivitas | Kategori |
Date | 2009 | S1 | N/A |
Business License Number | 4000 | S2 | N/A |
Tax Registration Certificate Number | 4001 | S2 | N/A |
Organization Code | 4002 | S2 | N/A |
Unified Social Credit Code | 4003 | S2 | N/A |
Vehicle Identification Number | 4004 | S2 | N/A |
Bagaimana tingkat sensitivitas API diklasifikasikan?
Tingkat sensitivitas API diklasifikasikan sebagai Tinggi, Sedang, Rendah, dan Tidak Ada:
Tinggi: Respons API berisi data sensitif tingkat S3 atau lebih tinggi, atau satu respons mengembalikan lebih dari 20 item data sensitif tingkat S2.
Sedang: Respons API berisi data sensitif tingkat S2.
Rendah: Respons API berisi data sensitif tingkat S1.
Tidak Ada: Respons API tidak berisi data sensitif.
Risiko dan peristiwa
Jenis risiko API apa saja yang dapat dideteksi oleh Keamanan API?
Spesifikasi keamanan
Insecure HTTP methods
Risk level: Low
Risk description: This API uses insecure HTTP methods. An attacker can use these methods to probe server information or tamper with server data, for example, by using PUT to upload malicious files or DELETE to remove server resources.
Suggestion: Disable insecure HTTP methods such as PUT, DELETE, TRACE, and OPTIONS, based on your business needs.
Weak JWT signature algorithm
Risk level: Low
Risk description: This API uses a weak JSON Web Token (JWT) signature algorithm.
Suggestion: Use a more secure signature algorithm such as RS256. Ensure the key is strong and that it is transmitted and stored securely.
Parameter as URL
Risk level: Low
Risk description: A request parameter for this API contains a URL value. This can create a Server-Side Request Forgery (SSRF) risk.
Suggestion: Redesign the API to avoid using user-controlled URLs directly in parameters. Implement strict validation and filtering on parameter content.
Keamanan akun
Password plaintext transmission
Risk level: Low
Risk description: This API transmits account passwords in plaintext. An attacker could intercept credentials during transmission through methods like sniffing, leading to account takeover.
Suggestion: Encrypt or hash password fields before transmission to prevent them from being intercepted.
Weak password tolerance
Risk level: Low
Risk description: This logon API allows weak passwords. An attacker could exploit this to brute-force accounts.
Suggestion: Enforce a strong password policy. A strong password is at least 8 characters long and includes characters from at least three of the following categories: uppercase letters, lowercase letters, numbers, and symbols. Notify users with existing weak passwords to change them promptly.
Weak password vulnerability in internal application
Risk level: High
Risk description: The logon API of this internal application allows weak passwords. An attacker could exploit this to brute-force accounts.
Suggestion: Enforce a strong password policy. A strong password is at least 8 characters long and includes characters from at least three of the following categories: uppercase letters, lowercase letters, numbers, and symbols. Notify users with existing weak passwords to change them promptly.
Presence of default passwords
Risk level: Medium
Risk description: This application may have a default password. An attacker could use the default password to take over accounts where the password has not been changed.
Suggestion: For applications with default passwords, force a password change on the first logon. For existing accounts with default passwords, notify users to change them immediately.
Return of plaintext password
Risk level: Low
Risk description: This API's response contains a plaintext password. An attacker could intercept user credentials during transmission, leading to account takeover.
Suggestion: Redesign the API to avoid returning plaintext passwords in responses.
Password storage in cookies
Risk level: Low
Risk description: This API stores account password information in a cookie, where it can be easily stolen by an attacker.
Suggestion: Redesign the API to avoid storing sensitive credentials in cookies.
Unrestricted logon
Risk level: Medium
Risk description: This logon API does not have a CAPTCHA or similar verification mechanism. An attacker could exploit this to perform unlimited brute-force attacks on passwords.
Suggestion: Add a verification mechanism, such as a CAPTCHA, especially after multiple failed logon attempts, to prevent brute-force attacks.
Unreasonable logon failure prompt
Risk level: Low
Risk description: This API's logon failure prompt reveals whether a username exists. An attacker can use this information to enumerate valid accounts for further attacks.
Suggestion: When a logon fails, return a generic message like "Incorrect username or password" instead of revealing whether the username is valid.
URL-based account password transmission
Risk level: Medium
Risk description: This API transmits account passwords in the URL. If the URL is compromised, the credentials are leaked. URLs are often recorded in server logs, referer headers, and browser history.
Suggestion: Use the POST method to transmit credential data in the request body.
Kontrol akses
Internal application accessible from the Internet
Risk level: Low
Risk description: This API belongs to an internal application and is accessible from the Internet without access restrictions. This could allow attackers to exploit or attack the internal application.
Suggestion: Add an access control policy, such as an IP address whitelist, to restrict access sources.
Unrestricted access sources
Risk level: Low
Risk description: This API is being accessed from sources (IP addresses or regions) outside its normal baseline.
Suggestion: Add an access control policy. Use IP blacklists and whitelists or the Location Blacklist feature to restrict access sources.
Unrestricted access tools
Risk level: Low
Risk description: The client type used to access this API does not match the API's client access baseline.
Suggestion: Add an access control policy to restrict access tools and prevent attackers from using malicious scripts to attack the API or scrape data.
Unrestricted access rate
Risk level: Low
Risk description: This API is accessed from a single IP address a certain number of times per minute.
Suggestion: Add a rate-limiting policy to control high-frequency access and prevent abuse.
Manajemen izin
Insufficiently random credentials
Risk level: Medium
Risk description: This API uses authentication credentials not sufficiently random and may be guessable. An attacker could brute-force these credentials to gain unauthorized or escalated access.
Suggestion: Increase the randomness of authentication credentials. Avoid using short or easily guessable formats.
Unauthenticated access to sensitive API
Risk level: High
Risk description: This API, which contains high-sensitivity data, can be accessed without authentication. This could lead to a serious data leak.
Suggestion: Add a strict and comprehensive identity verification mechanism to prevent unauthorized use of the API.
Unauthorized access to internal API
Risk level: High
Risk description: This API, which belongs to an internal application, can be accessed without authentication. This could lead to unauthorized use of internal services or an internal data leak.
Suggestion: Add a strict and comprehensive identity verification mechanism to prevent unauthorized use of the API.
URL-based credential transmission
Risk level: Medium
Risk description: This API transmits authentication credentials in the URL. If the URL is compromised, the credentials can be abused. URLs are often recorded in server logs, referer headers, and browser history.
Suggestion: Use another method to transmit authentication credentials, such as custom headers, cookies, or the request body.
AccessKey pair information leak
Risk level: High
Risk description: The response from this API contains an AccessKey ID and an AccessKey Secret, which could be exploited by an attacker.
Suggestion: Redesign the API to avoid returning AccessKey pair information. In addition, immediately disable or delete the leaked AccessKey pairs.
Unauthorized access to obtain STS token
Risk level: Medium
Risk description: The API security risk detection model has identified that this API can be accessed without authentication, and the response contains a cloud platform STS token (temporary security credential). An attacker can use this API to directly obtain temporary credentials with cloud resource operation permissions, which may lead to unauthorized cloud service calls, sensitive data theft, compute resource abuse, malicious operations, and even full account takeover, large-scale business data exfiltration, and significant financial losses.
Suggestion: Immediately implement strict identity authentication and access control mechanisms for this API to ensure that only authorized entities can call STS-related APIs in trusted environments, preventing unauthorized or escalated access. Additionally, thoroughly review the permission scope and usage records of any leaked STS tokens, promptly revoke the temporary credentials, and strengthen the security of associated IAM role policies. Ensure that STS APIs are never exposed externally, and never embed or call such high-risk APIs in frontend code, client applications, or public repositories.
Proteksi data
Excessive types of sensitive data in response
Risk level: Medium
Risk description: The response from this API contains an excessive number of sensitive data types. This may indicate unnecessary data exposure, increasing the risk of a data leak.
Suggestion: Review the business need for each data type returned. Mask important sensitive data and remove any data types that are not essential.
Excessive sensitive data in response
Risk level: Medium
Risk description: The response from this API contains sensitive data and does not limit the amount of data returned. This could be exploited to cause a large-scale data leak.
Suggestion: Limit the amount of data returned in a single response based on your business needs. This prevents attackers from using the API to obtain large amounts of sensitive data.
Inadequate data de-identification
Risk level: Medium
Risk description: The response from this API returns both a de-identified (masked) and a non-de-identified (plaintext) version of the same data, defeating the purpose of de-identification.
Suggestion: Review the sample data to confirm this risk. Ensure that data intended to be masked is not also exposed in plaintext elsewhere in the response.
Sensitive server information leak
Risk level: High
Risk description: The response from this API contains sensitive server information. An attacker could use this information to plan an attack and gain control of the server.
Suggestion: Review the sample data to confirm the risk. Avoid returning internal server information directly to the client.
Internal IP address leak
Risk level: Medium
Risk description: The response from this API appears to contain an internal IP address, leaking internal network information. An attacker could use this information to attack internal applications.
Suggestion: Redesign the API to prevent internal network information from being leaked in responses.
URL-based sensitive data transmission
Risk level: Medium
Risk description: This API transmits high-sensitivity data in the URL. If the URL is compromised, a sensitive data leak may occur. URLs are often recorded in server logs, referer headers, and browser history.
Suggestion: Use the POST method and transmit sensitive data in the request body.
OpenAPI documentation leak
Risk level: Medium
Risk description: The API security risk detection model has identified that this API exposes interface definition documents such as OpenAPI or Swagger. Attackers can use these documents to obtain business API paths, parameter structures, and business details, enabling them to precisely construct requests for batch probing, data theft, business logic attacks, and even discover sensitive interfaces and potential unauthorized operations. In severe cases, this can lead to system sensitive data leaks or unauthorized operations.
Suggestion: Strictly limit external access permissions for interface definition documents based on your actual business needs. Disable or encrypt open API document interfaces in production environments to prevent unauthorized access. If access is necessary, restrict it to trusted accounts or internal network calls only. Additionally, regularly review API document exposure policies to avoid carrying sensitive fields and business descriptions. Strengthen security controls through identity authentication, IP whitelists, and API gateways to prevent external attackers from obtaining interface metadata.
Large model API key leak
Risk level: High
Risk description: The API security risk detection model has identified that this API can be accessed without authentication and the response contains an API key for a large model service. An attacker can use this API to steal the large model API key, which may lead to unauthorized data access, real-time quota consumption, sensitive information theft, malicious content generation, business data exfiltration, and account abuse.
Suggestion: Implement strict and complete identity authentication mechanisms to prevent unauthorized or escalated access to the API. Additionally, immediately review the actual usage of the API key, promptly rotate the key, and ensure that API keys are only used in secure, controlled environments. Never expose API keys directly in frontend code or public repositories.
Desain API
Request parameter traversability
Risk level: Low
Risk description: The request parameters for this API have a fixed and predictable format. An attacker could iterate through parameter values based on this pattern to access data in batches.
Suggestion: Increase the randomness of parameters. Avoid using simple, sequential, or easily guessable values such as short numbers.
Modifiable volume of returned data
Risk level: Low
Risk description: A request parameter for this API controls the number of items returned and can be set to any value. An attacker could modify this parameter to obtain a large amount of data in a single request.
Suggestion: Add restrictions to this parameter. For example, provide only a few fixed options instead of allowing an arbitrary number, to prevent abuse.
Database query
Risk level: High
Risk description: A request parameter for this API contains a database query statement. An attacker could use this API to execute arbitrary database operations, attack the database, or steal important data.
Suggestion: Redesign the API to avoid passing raw database query statements from the client. Implement strict validation and filtering on all parameters.
Command execution API
Risk level: High
Risk description: A request parameter for this API contains a system command. An attacker could use this API to execute arbitrary system commands, gain control of the server, or steal important data.
Suggestion: Redesign the API to avoid passing raw command statements from the client. Implement strict validation and filtering on all parameters.
Arbitrary SMS message sending
Risk level: Medium
Risk description: The request parameters of this SMS message sending API contain a phone number and message content. An attacker could use this API to send malicious messages to any phone number.
Suggestion: Redesign the API to use fixed message templates on the backend instead of accepting arbitrary content from the client.
Arbitrary email content sending
Risk level: Medium
Risk description: The request parameters of this email sending API contain an email address and email content. An attacker could use this API to send malicious emails to any email address.
Suggestion: Redesign the API to use fixed email templates on the backend instead of accepting arbitrary content from the client.
SMS message verification code leak
Risk level: High
Risk description: The response of this SMS sending API appears to contain the verification code itself. An attacker could use this API to directly obtain the verification code, bypassing the security check.
Suggestion: Do not return the verification code to the client. The verification process should be completed on the backend.
Email verification code leak
Risk level: High
Risk description: The response of this email sending API appears to contain the verification code itself. An attacker could use this API to directly obtain the verification code, bypassing the security check.
Suggestion: Do not return the verification code to the client. The verification process should be completed on the backend.
Specified file download
Risk level: Medium
Risk description: A request parameter for this file download API contains a file path. An attacker could modify this parameter to download arbitrary files and steal important data.
Suggestion: Redesign the API to prevent downloads using full file paths. Strictly validate and filter parameter content to prevent path traversal attacks.
Application exception information leak
Risk level: Medium
Risk description: The response from this API contains application exception details. An attacker could use this information to learn about server application configurations and other sensitive details.
Suggestion: Improve the business exception handling mechanism. When an exception occurs, return a generic error message or redirect to a standard error page instead of leaking raw exception details.
Database exception information leak
Risk level: Medium
Risk description: The response from this API contains database exception details. An attacker could use this information to learn about database query statements and table structures, enabling attacks like SQL injection.
Suggestion: Optimize the business exception handling mechanism. When an exception occurs, return a generic error message or redirect to a standard error page instead of leaking raw database exception details.
Custom
Custom risk detection rule
Risk level: Custom level
Risk description: This API matched a custom risk detection rule that you configured.
Suggestion: The suggestion displays the content you configured in the policy.
Jenis aktivitas anomali apa saja yang dapat dideteksi oleh Keamanan API?
Pengecualian garis dasar
Abnormally high-frequency access
Event description: The access frequency is significantly higher than the daily baseline for this API, which may indicate malicious activities such as API abuse or HTTP flood attacks.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. Additionally, configure a rate-limiting policy based on the API's daily rate baseline.
Access to internal API from unusual IP address
Event description: The source IP address does not match the API's daily access IP distribution baseline. This may indicate anomalous calling behavior.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. You can also configure an IP whitelist policy based on the API's daily IP distribution baseline and block access from other IP addresses to ensure reasonable use of API resources.
Access to internal API from unusual location
Event description: The region of the IP address does not match the API's daily access region distribution baseline. This may indicate anomalous calling behavior.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. You can also configure a location blacklist policy based on the API's daily region distribution baseline to ensure reasonable use of API resources.
Access using anomalous tools
Event description: The tool used for access does not match the API's daily access tool distribution baseline. This may indicate an anomalous call.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. You can also configure an ACL access control policy or enable the Bot Management module based on the API's daily access tool distribution baseline to ensure reasonable use of API resources.
Access during unusual time period
Event description: The API was called during an anomalous time period, which may indicate an anomalous call.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist.
Access using abnormal parameter values
Event description: The format of request parameters does not match the daily characteristics of requests to this API, which may indicate anomalous calling or an attack.
Suggestion: Review sample request data and log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. If a web attack is confirmed, use the Core Web Protection module to protect the API and ensure reasonable use of API resources.
Risiko akun
Weak password-based logon to internal application
Event description: An IP address is suspected of using a weak password to log on to an internal application.
Suggestion: Check the log details to confirm if the logon was successful. For account services, enforce a stronger password policy. A strong password should typically include at least three of the following character types: uppercase letters, lowercase letters, digits, and symbols, and be at least 8 characters long. For existing accounts with weak passwords, notify users to change their passwords.
Brute-force attack against username
Event description: An IP address made multiple logon attempts using a relatively fixed password while constantly changing the username. This suggests a username brute-force attack.
Suggestion: Check log details to see if any attempts were successful. Change passwords regularly and ensure no weak passwords are used. For logon services, add a verification code to limit logon attempts or configure a rate-limiting policy to ensure reasonable use of the logon API.
Brute-force attack against password
Event description: An IP address made multiple logon attempts for a specific account while cycling through many different passwords. This is suspected to be a password brute-force attack.
Suggestion: Check log details to see if any attempts were successful. Change passwords regularly and ensure no weak passwords are used. For logon services, add a verification code to limit logon attempts or configure a rate-limiting policy to ensure reasonable use of the logon API.
Dictionary attack
Event description: An IP address made multiple logon attempts using many different usernames and passwords. This suggests a dictionary attack.
Suggestion: Check log details to see if any attempts were successful. Change passwords regularly and ensure no weak passwords are used. For logon services, add a verification code to limit logon attempts or configure a rate-limiting policy to ensure reasonable use of the logon API.
Brute-force attack against SMS message verification code
Event description: An IP address made multiple attempts to verify an SMS message code using many different codes. This is suspected to be a brute-force attack against the verification code.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. You can also configure a rate-limiting policy based on the API's daily rate distribution baseline to ensure reasonable use of API resources.
Brute-force attack against email verification code
Event description: An IP address made multiple attempts to validate an email verification code using many different codes. This is suspected to be a brute-force attack against the verification code.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. You can also configure a rate-limiting policy based on the API's daily rate distribution baseline to ensure reasonable use of API resources.
Batch registration
Event description: An IP address has made an unusual number of registration requests, which suggests a batch registration activity. This can lead to many spam accounts.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. You can also configure a rate-limiting policy based on the API's daily rate distribution baseline to ensure reasonable use of API resources.
Penyalahgunaan API
Malicious consumption of SMS resources
Event description: An IP address made multiple requests to send SMS. This suggests malicious consumption of SMS resources or the use of the API for SMS flooding, which can cause business losses.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. You should also limit the frequency of sending SMS to a single phone number and configure a rate-limiting policy based on the API's daily rate distribution baseline to ensure reasonable use of API resources.
Malicious consumption of email resources
Event description: An IP address made multiple requests to send emails, which is suspected to be a malicious attempt to consume email service resources or launch an email bombing attack. This could affect the stability of your email service.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. You should also limit the frequency of sending emails to a single mailbox and configure a rate-limiting policy based on the API's daily rate distribution baseline to ensure reasonable use of API resources.
Batch download
Event description: An IP address has made an unusual number of data export or download requests, obtaining many files. This may pose a data leak risk.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. You can also configure a rate-limiting policy based on the API's daily rate distribution baseline to ensure reasonable use of API resources.
Data crawling
Event description: An IP address called the API multiple times with traversing parameter values, which is suspected to be an attempt to crawl API data.
Suggestion: Investigate the log details to confirm the activity. For clearly malicious IP addresses, block them by configuring an IP blacklist. Increase the randomness of parameters based on your business needs. Avoid using simple and guessable parameter values, such as short numbers.
API attack
Event description: An IP address launched a web attack against the API. All attacks have been blocked by the web attack protection module.
Suggestion: Analyze the IP behavior using the log details. For clearly malicious IP addresses, block them by configuring an IP blacklist.
Kebocoran data sensitif
Unauthorized access to sensitive data
Event description: An IP address is suspected of making an unauthorized call to the API and has obtained sensitive data, which may pose a data leak risk.
Suggestion: Investigate the log details to confirm the activity. For important APIs, implement a strict and complete identity authentication mechanism to prevent unauthorized or escalated use.
Mass sensitive data access
Event description: An IP address called the API and obtained an unusually large amount of sensitive data, which may pose a data leak risk.
Suggestion: Investigate the log details to confirm the activity. De-identify important sensitive data where possible and remove unnecessary data types from the response. Additionally, configure a rate-limiting policy for the API.
Mass sensitive data access by IP addresses outside your country
Event description: An IP address from your country called the API and obtained multiple pieces of sensitive data. This may pose data breach and data compliance risks.
Suggestion: Investigate the log details to confirm the activity. Cross-border transmission of sensitive data may pose compliance risks. If there is a genuine business need for this transfer, we recommend conducting an assessment and complete any required declarations or filings.
Pengecualian respons
Return of error message
Event description: During an API call, the API returned an exception error message, which could leak important information such as application configurations.
Suggestion: Investigate the log details to confirm whether the API is functioning normally. Optimize your application's exception handling to return a generic error message or redirect to a specified page, instead of returning raw exception details.
Return of database error message
Event description: During an API call, the API returned a database error message, which could leak important information such as database query statements and table names.
Suggestion: Investigate the log details to confirm whether the API is functioning normally. Optimize your application's exception handling to return a generic error message or redirect to a specified page, instead of returning raw exception details.
Return of sensitive system information
Event description: During an API call, the API returned important sensitive server information, posing a data leak risk.
Suggestion: Investigate the log details to confirm whether the returned data is expected. Avoid returning such data directly to the client.
Abnormal response
Event description: During a series of API calls, the proportion of abnormal HTTP status codes in responses exceeded 80%, suggesting a possible issue with the origin server.
Suggestion: Investigate the log details and check your origin server logs to confirm whether the API is functioning normally.
Peristiwa kustom
Custom event rule
Event description: The API call from this IP address matched a custom event detection policy that you configured.
Suggestion: The suggestion displays the content you configured in the policy.
Jenis peristiwa anomali akun apa saja yang dapat dideteksi oleh Keamanan API?
Anomali akun
Account accessed using anomalous tools
Event description: Based on analysis by the API security event detection model, the account ${account} used multiple tools such as ${attack_client} to access the API ${attack_cnt} times between ${start_ts} and ${end_ts}, suggesting a batch automated attack or script-based API abuse.
Suggestion: Review the log details to confirm the activity. If illegal tools are identified, restrict the account's access promptly. Additionally, configure ACL access control policies or enable the Bot Management module based on the API's daily access tool distribution baseline to ensure reasonable use of business resources.
Kebocoran data
Anomalous access to large amounts of sensitive data
Event description: Based on analysis by the API security event detection model, the account ${account} obtained more than ${data_count} pieces of sensitive data such as ${data_type} between ${start_ts} and ${end_ts}, suggesting sensitive data collection behavior and a risk of sensitive data leakage.
Suggestion: Review the log details to confirm the activity. If no legitimate business justification exists, restrict the account's access promptly and implement data access quotas and tightened permission policies for the relevant accounts. Additionally, de-identify important sensitive data transmitted in business and remove unnecessary data types.
Cross-border access to sensitive data
Event description: Based on analysis by the API security event detection model, the account ${account} initiated access from overseas regions such as ${location} and obtained more than ${data_count} pieces of sensitive data such as ${data_type} between ${start_ts} and ${end_ts}, suggesting malicious scraping or external attacks, with risks of sensitive data leakage or data compliance violations.
Suggestion: Review the log details to confirm the activity. Cross-border transmission of sensitive data may pose compliance risks. If there is a genuine business need, conduct an assessment and complete any required declarations or filings promptly.
Anomalous download of large files
Event description: Based on analysis by the API security event detection model, the account ${account} downloaded or exported a large number of files through APIs such as ${api_format} between ${start_ts} and ${end_ts}, posing a data leak risk.
Suggestion: Review the log details to confirm the activity. If the behavior is unauthorized, limit the download frequency and total volume, and add authorization or approval mechanisms for large file download APIs.
Attempt to obtain other users' sensitive information
Event description: Based on analysis by the API security event detection model, the account ${account} obtained data such as ${data_type} for multiple different users by using different ${param} parameter values through APIs such as ${api_format} between ${start_ts} and ${end_ts}, suggesting a horizontal privilege escalation attack with risks of user data leakage.
Suggestion: Review the log details including request parameters, target user IDs, and permission context to confirm the activity. If privilege escalation is identified, immediately restrict the account's access permissions, strengthen the API's permission verification logic, and conduct a risk assessment and handling for the affected account.
Traversing and scraping business data
Event description: Based on analysis by the API security event detection model, the account ${account} traversed ${param} parameter values to obtain data through APIs such as ${api_format} between ${start_ts} and ${end_ts}, suggesting a business data crawler or batch collection activity.
Suggestion: Review the log details to confirm the activity. If automated scraping is identified, configure a dynamic rate-limiting policy based on the API's daily frequency baseline distribution, and add anti-traversal protection (such as parameter signatures or CAPTCHAs) for critical APIs.
Operasi anomali
High-frequency API calls
Event description: Based on analysis by the API security event detection model, the account ${account} made high-frequency calls to APIs such as ${api_format} between ${start_ts} and ${end_ts}, suggesting an automated attack or malicious API abuse, posing a business risk.
Suggestion: Review the log details to confirm the activity, and configure a dynamic rate-limiting policy based on the API's daily frequency baseline distribution to ensure reasonable use of API resources.
Access triggers multiple exception error responses
Event description: Based on analysis by the API security event detection model, the account ${account} triggered multiple application or database exception errors during access between ${start_ts} and ${end_ts}, suggesting malicious probing or attack behavior.
Suggestion: Review the log details to confirm the activity. If probing or attack behavior is identified, restrict the account's access. Additionally, optimize the business exception handling mechanism to return a generic error message or redirect to a specified page when exceptions occur, instead of returning raw exception details that could leak application information.
Abnormal response status codes
Event description: Based on analysis by the API security event detection model, the account ${account} received abnormal response status codes (4xx/5xx) exceeding ${except_rate}% of responses during access between ${start_ts} and ${end_ts}, suggesting malicious probing or attack.
Suggestion: Review the log details to confirm the activity. If probing or attack behavior is identified, restrict the account's access. Additionally, confirm whether the business is operating normally.
Bagaimana Keamanan API membantu perusahaan mengurangi risiko kebocoran data?
Keamanan API mendeteksi kerentanan API, merekonstruksi peristiwa anomali, dan memberikan saran penanganan.
Kerentanan API: API internal (untuk penggunaan kantor, pengujian, atau operasi) yang diekspos ke Internet dapat memungkinkan penyerang mengakses data sensitif.
Peristiwa API anomali: Perilaku yang menyimpang dari garis dasar normal, di luar persyaratan bisnis dan skenario akses yang telah ditentukan.
Transfer data lintas batas
(Hanya untuk Tiongkok daratan) Apa standar untuk deklarasi dan pengarsipan transfer data lintas batas?
Deklarasi diperlukan (jika memenuhi salah satu kondisi berikut)
Jumlah kumulatif orang yang informasi pribadinya ditransfer ke luar negeri sejak 1 Januari tahun sebelumnya lebih dari 100.000.
Jumlah kumulatif orang yang informasi pribadi sensitifnya ditransfer ke luar negeri sejak 1 Januari tahun sebelumnya lebih dari 10.000.
Data ditransfer ke luar negeri sejak 1 Januari tahun sebelumnya, dan jumlah kumulatif orang yang informasi pribadinya diproses oleh organisasi Anda lebih dari 1.000.000.
Deklarasi tidak diperlukan
Jumlah kumulatif orang yang informasi pribadinya ditransfer ke luar negeri sejak 1 Januari tahun sebelumnya kurang dari 100.000.
Jumlah kumulatif orang yang informasi pribadi sensitifnya ditransfer ke luar negeri sejak 1 Januari tahun sebelumnya kurang dari 10.000.
Data ditransfer ke luar negeri sejak 1 Januari tahun sebelumnya, dan jumlah kumulatif orang yang informasi pribadinya diproses oleh organisasi Anda kurang dari 1.000.000.
Lihat halaman ikhtisar keamanan API
Pada tab Overview halaman API Security, lihat grafik API Asset Trend, Risk Trend, Attack Trend, Risky Site Statistics, Statistics on Attacked Sites, Statistics on Request Sensitive Data Types, dan Statistics on Response Sensitive Data Types. Periode statistik default adalah 30 hari.
Operasi kueri dan filter yang didukung
Pada grafik API Asset Trend, Risk Trend, dan Attack Trend, klik item dalam legenda grafik, seperti Total API Assets dan Active APIs, untuk memfilter data yang ditampilkan dalam grafik.
Pada tabel Risky Site Statistics, Statistics on Attacked Sites, Statistics on Request Sensitive Data Types, dan Statistics on Response Sensitive Data Types, Anda dapat mengurutkan data yang ditampilkan secara ascending atau descending. Di pojok kanan atas setiap tabel, klik More untuk melihat detail pada tab yang sesuai.
Batasan
Fitur Keamanan API tidak tersedia untuk objek yang dilindungi yang ditambahkan melalui Function Compute (FC). Jika Anda menggunakan Microservices Engine (MSE), versi mesin gateway cloud-native harus 2.0.4 atau lebih baru.
Edisi Dasar berlangganan tidak mendukung Keamanan API.