{"id":28616,"date":"2017-12-29T13:00:21","date_gmt":"2017-12-29T18:00:21","guid":{"rendered":"https:\/\/sdtimes.com\/?p=28616"},"modified":"2018-01-05T14:33:11","modified_gmt":"2018-01-05T19:33:11","slug":"automating-api-security-testing-devsecops-approach","status":"publish","type":"post","link":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/","title":{"rendered":"Automating API security testing with a DevSecOps approach"},"content":{"rendered":"<p>There has been a lot of recent focus of shifting testing left, but a part of that which doesn\u2019t get much attention is API testing. <\/p>\n<p>Akshay Aggarwal, CEO of PeachTech and founder and COO of Deja Vu Security, believes that companies can better manage API testing by approaching it in a DevSecOps way. It needs to be integrated around teams\u2019 current workflow in order to be effective, according to him. <\/p>\n<p>Aggarwal believes there are seven fundamentals to API testing in a DevSecOps setting. The first is that testing needs to be specific to APIs. He says that teams need to test against vulnerability lists, such as the OWASP Top 10. <\/p>\n<p>The second point is that test cases need to be automatically generated. \u201cUnless you can automate, you\u2019re at least two orders of magnitude behind in terms of the amount of time and effort spent looking for issues,\u201d Aggarwal said. <\/p>\n<p>Aggarwal recommends that teams configure their testing in a way that allows them to convert their current unit tests into security tests. <\/p>\n<p>Third, security tests should be built into the existing developer workflows using normal tools. This allows vulnerable code to be sent back to development and prevented from entering into production. Using tools that developers are already familiar with prevents them from having to learn new tools, which saves time and money. Similarly, data should populate into the normal databases so that they don\u2019t have to use a specific tool to view results, Aggarwal explained. <\/p>\n<p>The fourth fundamental is a term known as fuzzing, which is when teams mutate valid messages to find additional vulnerabilities that were not discovered during automated OWASP testing. Fuzzing reduces the number of zero-day vulnerabilities present in code. <\/p>\n<p>Creating testing profiles that accommodate business needs is also important. For example, creating a profile that bypasses certain tests for projects with tight deadlines. <\/p>\n<p>Sixth, the test results should include information that developers will need in order to fix issues quickly. Finally, configuring how faults are managed is important because it ensures that false positives don\u2019t slow down development.<\/p>\n<p>\u201cEssentially what happens is that the tests transform as time goes on, but the fundamentals of that sound security remain constant,\u201d said Aggarwal.<\/p>\n<p>According to Aggarwal, organizations are not always clear on whose responsibility API testing is. When asked as part of a survey who is responsible for API testing, 49 percent said it was the development team and 51 percent said it was the security team, said Aggarwal.<\/p>\n<p>\u201cIf you dug down deeper into who was answering, it depended on the role that they had,\u201d said Aggarwal. \u201cDevelopers overwhelmingly said it was the security team\u2019s responsibility and security teams overwhelmingly said it was the developer\u2019s responsibility.\u201d<\/p>\n<p>This mismatch is one of three challenges to scaling API security. Because API security depends on the consumer to provide security, not knowing who is providing that security can have negative effects.<\/p>\n<p>Another challenge he lists is that APIs have increasingly complex actions. This makes it difficult to use tradition tooling, such as security vulnerability scanners, because those tools cannot \u201cdetect bugs that they can\u2019t see.\u201d<\/p>\n<p>The third challenge to scaling API security is that manual API testing is too expensive. But when companies don\u2019t find bugs until code is in production, it is too late to prevent losses from those bugs. <\/p>\n<p>By overcoming these challenges and following the fundamentals needed to approach testing in a DevSecOps way, companies can realize the full benefits of API testing. <\/p>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>There has been a lot of recent focus of shifting testing left, but a part of that which doesn\u2019t get much attention is API testing. Akshay Aggarwal, CEO of PeachTech and founder and COO of Deja Vu Security, believes that companies can better manage API testing by approaching it in a DevSecOps way. It needs  &hellip; <a class=\"read-more\" href=\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/\">continue reading<\/a><!-- AddThis Advanced Settings generic via filter on get_the_excerpt --><!-- AddThis Share Buttons generic via filter on get_the_excerpt --><\/p>\n","protected":false},"author":752,"featured_media":28617,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"cybocfi_hide_featured_image":"","footnotes":"","_links_to":"","_links_to_target":""},"categories":[1],"tags":[6670,1823,4000,8749,11148,3244,706],"coauthors":[11687],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Automating API security testing with a DevSecOps approach - SD Times<\/title>\n<meta name=\"description\" content=\"Automating API security testing with a DevSecOps approach to realize the full benefits\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Automating API security testing with a DevSecOps approach - SD Times\" \/>\n<meta property=\"og:description\" content=\"Automating API security testing with a DevSecOps approach to realize the full benefits\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/\" \/>\n<meta property=\"og:site_name\" content=\"SD Times\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/SDTimesD2\" \/>\n<meta property=\"article:published_time\" content=\"2017-12-29T18:00:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-01-05T19:33:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"640\" \/>\n\t<meta property=\"og:image:height\" content=\"457\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jenna Barron\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@sdtimes\" \/>\n<meta name=\"twitter:site\" content=\"@sdtimes\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jenna Barron\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/\"},\"author\":{\"name\":\"Jenna Barron\",\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/person\/f2524e55ae19da07ea3613577da9f786\"},\"headline\":\"Automating API security testing with a DevSecOps approach\",\"datePublished\":\"2017-12-29T18:00:21+00:00\",\"dateModified\":\"2018-01-05T19:33:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/\"},\"wordCount\":589,\"commentCount\":3,\"publisher\":{\"@id\":\"https:\/\/sdtimes.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg\",\"keywords\":[\"3D rendering API\",\"API\",\"API testing\",\"DevSecOps\",\"OWASP Top 10\",\"software security\",\"zero-day\"],\"articleSection\":[\"Latest News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/\",\"url\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/\",\"name\":\"Automating API security testing with a DevSecOps approach - SD Times\",\"isPartOf\":{\"@id\":\"https:\/\/sdtimes.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg\",\"datePublished\":\"2017-12-29T18:00:21+00:00\",\"dateModified\":\"2018-01-05T19:33:11+00:00\",\"description\":\"Automating API security testing with a DevSecOps approach to realize the full benefits\",\"breadcrumb\":{\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#primaryimage\",\"url\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg\",\"contentUrl\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg\",\"width\":640,\"height\":457},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/sdtimes.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Automating API security testing with a DevSecOps approach\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/sdtimes.com\/#website\",\"url\":\"https:\/\/sdtimes.com\/\",\"name\":\"SD Times\",\"description\":\"Software Development News\",\"publisher\":{\"@id\":\"https:\/\/sdtimes.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/sdtimes.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/sdtimes.com\/#organization\",\"name\":\"SD Times\",\"url\":\"https:\/\/sdtimes.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2014\/05\/deafaultlogo.png\",\"contentUrl\":\"https:\/\/sdtimes.com\/wp-content\/uploads\/2014\/05\/deafaultlogo.png\",\"width\":225,\"height\":90,\"caption\":\"SD Times\"},\"image\":{\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/SDTimesD2\",\"https:\/\/x.com\/sdtimes\",\"https:\/\/www.linkedin.com\/company\/sdtimes\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/person\/f2524e55ae19da07ea3613577da9f786\",\"name\":\"Jenna Barron\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/sdtimes.com\/#\/schema\/person\/image\/b4be3423b187642936e62f121111345e\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b128943929626cdcafccbac86bd306f9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b128943929626cdcafccbac86bd306f9?s=96&d=mm&r=g\",\"caption\":\"Jenna Barron\"},\"description\":\"Jenna Barron is News Editor of SD Times.\",\"url\":\"https:\/\/sdtimes.com\/author\/jennifer-sargent\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Automating API security testing with a DevSecOps approach - SD Times","description":"Automating API security testing with a DevSecOps approach to realize the full benefits","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/","og_locale":"en_US","og_type":"article","og_title":"Automating API security testing with a DevSecOps approach - SD Times","og_description":"Automating API security testing with a DevSecOps approach to realize the full benefits","og_url":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/","og_site_name":"SD Times","article_publisher":"https:\/\/www.facebook.com\/SDTimesD2","article_published_time":"2017-12-29T18:00:21+00:00","article_modified_time":"2018-01-05T19:33:11+00:00","og_image":[{"width":640,"height":457,"url":"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg","type":"image\/jpeg"}],"author":"Jenna Barron","twitter_card":"summary_large_image","twitter_creator":"@sdtimes","twitter_site":"@sdtimes","twitter_misc":{"Written by":"Jenna Barron","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#article","isPartOf":{"@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/"},"author":{"name":"Jenna Barron","@id":"https:\/\/sdtimes.com\/#\/schema\/person\/f2524e55ae19da07ea3613577da9f786"},"headline":"Automating API security testing with a DevSecOps approach","datePublished":"2017-12-29T18:00:21+00:00","dateModified":"2018-01-05T19:33:11+00:00","mainEntityOfPage":{"@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/"},"wordCount":589,"commentCount":3,"publisher":{"@id":"https:\/\/sdtimes.com\/#organization"},"image":{"@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#primaryimage"},"thumbnailUrl":"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg","keywords":["3D rendering API","API","API testing","DevSecOps","OWASP Top 10","software security","zero-day"],"articleSection":["Latest News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/","url":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/","name":"Automating API security testing with a DevSecOps approach - SD Times","isPartOf":{"@id":"https:\/\/sdtimes.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#primaryimage"},"image":{"@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#primaryimage"},"thumbnailUrl":"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg","datePublished":"2017-12-29T18:00:21+00:00","dateModified":"2018-01-05T19:33:11+00:00","description":"Automating API security testing with a DevSecOps approach to realize the full benefits","breadcrumb":{"@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#primaryimage","url":"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg","contentUrl":"https:\/\/sdtimes.com\/wp-content\/uploads\/2017\/12\/startup-photos-4.jpg","width":640,"height":457},{"@type":"BreadcrumbList","@id":"https:\/\/sdtimes.com\/3d-rendering-api\/automating-api-security-testing-devsecops-approach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sdtimes.com\/"},{"@type":"ListItem","position":2,"name":"Automating API security testing with a DevSecOps approach"}]},{"@type":"WebSite","@id":"https:\/\/sdtimes.com\/#website","url":"https:\/\/sdtimes.com\/","name":"SD Times","description":"Software Development News","publisher":{"@id":"https:\/\/sdtimes.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sdtimes.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/sdtimes.com\/#organization","name":"SD Times","url":"https:\/\/sdtimes.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sdtimes.com\/#\/schema\/logo\/image\/","url":"https:\/\/sdtimes.com\/wp-content\/uploads\/2014\/05\/deafaultlogo.png","contentUrl":"https:\/\/sdtimes.com\/wp-content\/uploads\/2014\/05\/deafaultlogo.png","width":225,"height":90,"caption":"SD Times"},"image":{"@id":"https:\/\/sdtimes.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/SDTimesD2","https:\/\/x.com\/sdtimes","https:\/\/www.linkedin.com\/company\/sdtimes\/"]},{"@type":"Person","@id":"https:\/\/sdtimes.com\/#\/schema\/person\/f2524e55ae19da07ea3613577da9f786","name":"Jenna Barron","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sdtimes.com\/#\/schema\/person\/image\/b4be3423b187642936e62f121111345e","url":"https:\/\/secure.gravatar.com\/avatar\/b128943929626cdcafccbac86bd306f9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b128943929626cdcafccbac86bd306f9?s=96&d=mm&r=g","caption":"Jenna Barron"},"description":"Jenna Barron is News Editor of SD Times.","url":"https:\/\/sdtimes.com\/author\/jennifer-sargent\/"}]}},"_links":{"self":[{"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/posts\/28616"}],"collection":[{"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/users\/752"}],"replies":[{"embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/comments?post=28616"}],"version-history":[{"count":2,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/posts\/28616\/revisions"}],"predecessor-version":[{"id":28756,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/posts\/28616\/revisions\/28756"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/media\/28617"}],"wp:attachment":[{"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/media?parent=28616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/categories?post=28616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/tags?post=28616"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/sdtimes.com\/wp-json\/wp\/v2\/coauthors?post=28616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}