Ammune™ presents a unique "API-centric" AI protection model. Once a new API endpoint is discovered through ammune™ ongoing traffic analysis, a set of “micro-AI/ML machines” are cloned and initiated, aimed to protect the newly discovered API-Discovery aimed to assist the security teams to control APIs and discover potential excessive data exposure. It generates a dynamically updated API endpoints catalog.
API-WAF | protects APIs from content-based attacks and common argument tampering techniques. It automatically protects API traffic from challenging API attacks by detecting and mitigating subtle and stealthy attacks in real-time.
API-DDoS | protects from DDoS attacks targeting specific API(s). These attacks may use camouflage techniques, such as rotating source IPs, users or requests content randomization while using optimization algorithms. The module analyzes the API(s) traffic to find exceptional API-related resource consumption within seconds.
API-Bot | protects APIs from business-related bot attacks, such as object enumeration attacks, credential brute forces, carding brute forces, and scraping. The module performs analysis of API/user traffic content, context, and metadata according to specific bot activity measurements.
API-Business Logic | protects APIs from Business Logic (BL) attacks that can lead to forbidden data or functionality access or abused business processes and fraud. The module performs an in-session, source-based traffic analysis to identify attack patterns in real-time.
APIs have become the building blocks of today’s applications. As rapid publishing and updating APIs go wild, here are major demands from API security:
A dynamic, "API-centric" protection shield is critical to protect API endpoints that are changing on a daily basis.
"Zero trust" protection model is needed as attacks coming from authenticated users have become the new norm in API Security.
Context-aware "stateful protection" is essential as APIs expose sensitive data and complex logical functionality to users and 3rd parties.
AI-based "automatic protection" is critical as the number of API endpoints can reach hundreds and more at standard organizations.