Impart and Chill Blog

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Know Your Enemy, Know Yourself: Why WAFs can't protect your APIs

My initial take on API Security was that we could provide API security with a WAF. After all, API traffic is predominantly HTTP, just like a web application. I thought that all we needed to do to provide API security is to block bad API requests. It also didn’t hurt that I worked at a WAF vendor at the time.However, the more I spoke with customers and CISOs, the more I realized that this approach didn’t work. Our WAF had no way to answer the most basic API security questions I was being asked by customers...
Brian Joe
September 25, 2023
Read article

Innovating with Our Security Advisory Board

Impart Security
July 10, 2023
Read article

Shift Left, Shift Right, or Other?

Impart Security
June 14, 2023
Read article

Thoughts on The New 2023 OWASP API Security Top 10 Release

Impart Security
June 7, 2023
Read article

Detect and Fix API Vulnerabilities Using Validation, Secure Principles and Real-time Response

Impart Security
May 11, 2023
Read article

Why Complete API Documentation Makes Your APIs More Secure

Impart Security
May 2, 2023
Read article

A Comprehensive Guide to Rate Limiting in the Age of APIs and Microservices

Impart Security
April 17, 2023
Read article

Pairing Reinforcement Learning and Online Training in API Security

Impart Security
January 23, 2023
Read article

The Importance of Speed in Security: Why Easy Deployment Matters

Impart Security
January 17, 2023
Read article

Why Shadow APIs are a Cultural Problem, Not a Technical One

Impart Security
January 11, 2023
Read article

Mass Assignment 101

Impart Security
December 13, 2022
Read article

API Security 101 - The Basics

Impart Security
December 6, 2022
Read article