ANT0305

API Security

Duration of training: 3 days

sign up for a course

description
course

This course enables participants to study the principles and specific mechanisms for securing application programming interfaces (APIs). The course also covers methodological aspects of designing, implementing, and maintaining API-based applications within an enterprise cybersecurity architecture.

course audience

Engineers responsible for ensuring the cybersecurity of enterprise applications, as well as engineers involved in designing enterprise cybersecurity architectures.

prerequisites

Knowledge of TCP/IP networking at the level of the ANT-N101 course, as well as general cybersecurity knowledge at the level of the ANT0000 course, is required. Knowledge equivalent to the ANT0301 course is recommended.

how it works
education

online course

The online course involves group classes with an instructor via video conferencing, in addition, homework and an exam.

for corporate clients

training for corporate clients includes online and self-study courses, as well as additional services required by corporate clients: organizing training plans for client departments, assessing the effectiveness of training, etc.

program
course

• API operating principles.
• RPC-based API.
• REST-based API.
• Operational logic of applications providing APIs.
• Operational logic of applications consuming APIs.
• Using Key Risk Indicators (KRI) for API threat analysis.
• API threat taxonomies: STRIDE, OWASP Top 10, and the 7 Evil Kingdoms.
• API vulnerabilities and conditions for exploitability.
• Ensuring security of the weakest component.
• Defense in Depth.
• Ensuring security when handling exceptions and errors.
• Applying the principle of least privilege.
• Software decomposition into separate components.
• Using simple software functions and components.
• Maintaining privacy during data processing.
• Protecting and managing secrets.
• Ensuring trust between software functions and components.
• Leveraging the developer community.
• DevSecOps practices and methodologies.
• Access control processes and components: IAAAA.
• API call authentication.
• Token-based authentication.
• Integration with Single Sign-On (SSO) systems.
• Ролевая м Role-based access control for API functions.
• Authorization using OAuth 2.0.
• Data encryption in different states.
• Using TLS to encrypt API communications.
• Using SSH to encrypt network API communications.
• Alternative encryption methods for system API calls.
• API gateways and proxies.
• API call filtering.
• Specific aspects of API security in web applications.
• Monitoring API calls and API status.
• Digital forensics artifacts related to API operations.
• Automation of API security monitoring and management tasks.

Сourse purchase
options

individual

Cost — $1,549.15

Group online classes

Unlimited access to all the materials

Live webinars with teachers

Homework

Exam with certificate

To confirm course dates fill out the form.

SUBMIT YOUR APPLICATION

* By clicking “send”, you agree to the Terms of Service And Privacy Policy

corporate

Cost from $1,549.15

To obtain information about the final cost and clarify the date of the course, please fill out the form.

SUBMIT YOUR APPLICATION

* By clicking “send”, you agree to the Terms of Service And Privacy Policy