Op werkdagen voor 23:00 besteld, morgen in huis Gratis verzending vanaf €20

Advanced API Security

OAuth 2.0 and Beyond

Specificaties
Paperback, blz. | Engels
Apress | 2e druk, 2020
ISBN13: 9781484220498
Rubricering
Hoofdrubriek : Computer en informatica
Apress 2e druk, 2020 9781484220498
Verwachte levertijd ongeveer 9 werkdagen

Samenvatting

Prepare for the next wave of challenges in enterprise security. Learn to better protect, monitor, and manage your public and private APIs.
Enterprise APIs have become the common way of exposing business functions to the outside world. Exposing functionality is convenient, but of course comes with a risk of exploitation. This book teaches you about TLS Token Binding, User Managed Access (UMA) 2.0, Cross Origin Resource Sharing (CORS), Incremental Authorization, Proof Key for Code Exchange (PKCE), and Token Exchange. Benefit from lessons learned from analyzing multiple attacks that have taken place by exploiting security vulnerabilities in various OAuth 2.0 implementations. Explore root causes, and improve your security practices to mitigate against similar future exploits.
Security must be an integral part of any development project. This book shares best practices in designing APIs for rock-solid security. API security has evolved since the first edition of this book, and the growth of standards has been exponential. OAuth 2.0 is the most widely adopted framework that is used as the foundation for standards, and this book shows you how to apply OAuth 2.0 to your own situation in order to secure and protect your enterprise APIs from exploitation and attack.

What You Will Learn

-Securely design, develop, and deploy enterprise APIs
-Pick security standards and protocols to match business needs
-Mitigate security exploits by understanding the OAuth 2.0 threat landscape
-Federate identities to expand business APIs beyond the corporate firewall
-Protect microservices at the edge by securing their APIs
-Develop native mobile applications to access APIs securely
-Integrate applications with SaaS APIs protected with OAuth 2.0

Who This Book Is For

Enterprise security architects who are interested in best practices around designing APIs. The book is also for developers who are building enterprise APIs and integrating with internal and external applications.

Specificaties

ISBN13:9781484220498
Taal:Engels
Bindwijze:paperback
Uitgever:Apress
Druk:2
Verschijningsdatum:15-3-2020

Inhoudsopgave

1. APIs Rule!2. Designing Security for APIs3. Securing APIs with Transport Layer Security (TLS)4. OAuth 2.0 Fundamentals5. Edge Security with an API Gateway6. OpenID Connect (OIDC)7. Message Level Security with JSON Web Signature8. Message Level Security with JSON Web Encryption9. OAuth 2.0 Profiles10. Accessing APIs via Native Mobile Apps11. OAuth 2.0 Token Binding12. Federating Access to APIs13. User Managed Access14. OAuth 2.0 Security15. Patterns and Practices16: A. The Evolution of Identity Delegation17: B. OAuth 1.018: C. How Transport Layer Security Works19: D. UMA Evolution20. E. Base64URL Encoding21: F. Basic/Digest Authentication
22: G. OAuth 2.0 MAC Token Profile

Rubrieken

Populaire producten

    Personen

      Trefwoorden

        Advanced API Security