Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 

Repository files navigation

Comprehensive API Security Resources

This repository contains a curated list of comprehensive resources, learning paths, and tools for mastering API Security.

1. Foundational Frameworks & Learning Paths

  • OWASP API Security Top 10: The industry standard for understanding the most critical API security risks. Many training programs and tools are mapped directly to this project.
  • Security Journey's OWASP API Security Learning Path: Offers video lessons and hands-on sandbox exercises focused on the OWASP API Top 10 to help developers identify and defend against real-world vulnerabilities.
  • Snyk Learn - API Security Path: Interactive learning path that provides a deep understanding of API security threats and actionable strategies for mitigation.
  • PortSwigger Web Security Academy: Offers specialized learning paths on topics like GraphQL API vulnerabilities and broader web security that impact APIs.
  • Pluralsight API Security Path: A structured path covering the role of APIs, common threats, the OWASP API Top 10, and testing methodologies.

2. Outstanding GitHub Repositories & Curated Lists

3. Professional Training & Certifications

Top Industry Certifications

Top Udemy Courses

4. Industry Tools & Platforms

Understanding the tools used in the industry is vital for securing APIs across the lifecycle:

5. Books & Publications

  • "Hacking APIs" by Corey J. Ball: An excellent practical guide to breaking and securing web application programming interfaces.
  • "Advanced API Security" by Prabath Siriwardena: A comprehensive look at OAuth 2.0, OpenID Connect, JWS, and JWE.

6. Best Practices & White Papers (Vendors, Consulting, Institutions)

  • Gartner Research on API Security: Strategic research on API security market trends, the evolution of attack vectors, and recommendations for security architecture.
  • NIST Cybersecurity Framework (CSF): Provides foundational practices for integrating API security into a broader organizational risk management strategy, alongside specific microservices and API publications.
  • SANS Institute Reading Room: Offers white papers and technical resources focused on the hands-on implementation of security controls, defensive programming, and incident response for APIs.
  • Akamai (formerly Noname Security) Reports: Detailed white papers and state-of-API-security reports covering continuous discovery, shadow APIs, and runtime protection strategies.
  • Salt Security Labs & Reports: Frequently publishes the "State of API Security Report", outlining top vulnerabilities found in the wild, common attack patterns, and mitigation strategies.
  • IBM Security - API Management & Security: Consulting and product-driven guidance emphasizing API lifecycle management, robust authentication, and gateway security controls.
  • Cequence Security Resources: Excellent white papers focused on understanding and defending against automated API bot attacks and utilizing behavioral analysis.

Maintained for continuous learning and reference in API Security.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors