Traceable AI CSO Richard Bird on Best Practices for Fighting API-Based Attacks
“There’s a huge amount of inertia and friction to try and orient your organization toward solving for API issues,” Bird said. “And yet, the bad actors are moving extremely quickly and discovering even more interesting, new ways to leverage APIs to do bad things.”
See Also: Live Webinar | Unmasking Pegasus: Understand the Threat & Strengthen Your Digital Defense
For example, Bird said, he recently observed a bad actor employing API volumetric attacks, application hacks, DoS attacks and fraudulent account creation – all in one campaign, which succeeded in stealing data. “When you think about how security organizations are structured over the last 20 years, we are almost singularly focused on a plane of attack or a point of attack,” he said.
In this video interview with Information Security Media Group at Black Hat USA 2023, Bird discussed:
- Why API vulnerabilities are so hard for large enterprises to tackle;
- How bad actors are exploiting APIs;
- Best practices for securing APIs.
Bird has nearly 30 years of experience in the cybersecurity and IT operations industry. He has been a CIO and a CISO, and he is the former global head of identity for JPMorgan Chase. Bird has held multiple C-level roles advising organizations of all sizes and served as the chief customer information officer for Ping Identity, building security solutions for the market as a chief product officer.