sacon - api security (suhas desai)

15
SACON SACON International 2017 Suhas Desai Aujas VP – Digital Security @desai_suhas India | Bangalore | November 10 – 11 | Hotel Lalit Ashok API Economy: Trends, Risks & Security Governance

Upload: priyanka-aash

Post on 21-Jan-2018

1.354 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: SACON - API Security (Suhas Desai)

SACON

SACONInternational2017

SuhasDesaiAujas

VP– DigitalSecurity@desai_suhas

India|Bangalore|November10– 11|HotelLalit Ashok

APIEconomy:Trends,Risks&SecurityGovernance

Page 2: SACON - API Security (Suhas Desai)

SACON 2017

Trends– BankRobots

Page 3: SACON - API Security (Suhas Desai)

SACON 2017

Trends– TelematicsInsurance

Page 4: SACON - API Security (Suhas Desai)

SACON 2017

Trends– ArtificialIntelligence

Page 5: SACON - API Security (Suhas Desai)

SACON 2017

Trends– DigitalIndia&Aadhaar

Page 6: SACON - API Security (Suhas Desai)

SACON 2017

Trends– APIBanking

Page 7: SACON - API Security (Suhas Desai)

SACON 2017

Quiz

main(){int i=7;printf(“%d”,i++*i++);

return0;

}

Page 8: SACON - API Security (Suhas Desai)

SACON 2017

236358

477 552 625 658

2015 2016 2017 2018 2019 2020

APIManagementMarketSize- US($m)

Top10Trends&Predictionsfor2017

Page 9: SACON - API Security (Suhas Desai)

SACON 2017

API API Management Platforms API Banking

An ApplicationProgrammingInterface (API)isAset

of routine definitions,protocols,andtoolsforbuilding softwareand

applications. (Source:Wikipedia)

ManagesAPIlifecycle.Itistheprocessofpublishing,promotingandoverseeingAPIsinasecure,scalableenvironment.

APIBankingenablesdigitisationoftheB2Bsupplychain.ItallowsorganisationsERPandB2BsystemstointegratewithBankspayment

Systems.

WhatisAPIsandAPIManagementPlatforms?

Page 10: SACON - API Security (Suhas Desai)

SACON 2017

APIBankingInitiative

Page 11: SACON - API Security (Suhas Desai)

SACON 2017

Why we need API Security

Digitalbusinessesexperiencinghackersattentiontoexploremonetarybenefitsbyexploiting:

§ AuthenticationModuleIntegrations

§ APIIntegrationswithGateways

§ APIMessageCryptography

§ GovernanceissuesinAPIEconomy

§ WeakCommunicationChannels

§ InsecureAPIPlatformImplementations

§ GovernanceissuesinAPIandCryptoKeys

During digital initiatives, organizations opens its APIs and APImanagement platforms. There are possibilities to haveunauthorized access to these exposed APIs during various insecureintegrations

WhyweneedAPISecurity?

Page 12: SACON - API Security (Suhas Desai)

SACON 2017

APIinDigitalChannels- ArchitectureandSecurityRiskAreas

Page 13: SACON - API Security (Suhas Desai)

SACON 2017

SecureAPILifeCycleManagement

Page 14: SACON - API Security (Suhas Desai)

SACON 2017

SecureGovernance

Page 15: SACON - API Security (Suhas Desai)

SACON 2017

• HappyAPIEconomy!

• SecureAPIIntegrations

• APIManagementPlatforms

• SecureGovernance

Summary