F5 API Discovery

F5 DevCentral CommunityAbout 4 min readJun 3, 2025Watch original
THE SUMMARYAI-generated

Key Concepts:

  • API Discovery (Code Analysis, Traffic Detection, Surface Mapping/Crawling)
  • API Inventory
  • OpenAPI Specification
  • Shift-Left Security
  • Runtime API Discovery
  • Drift Detection
  • Shadow APIs
  • Zombie APIs
  • Behavioral Modeling
  • API Surface Mapping (Crawling)
  • F5 Distributed Cloud API Security
  • F5 BIG-IP Application Delivery Controller

1. Introduction to API Discovery

  • API discovery is crucial for understanding and securing an application's API landscape.
  • It dynamically identifies and classifies all API endpoints, including documented and undocumented ones.
  • It helps find shadow and zombie APIs and provides deep insights into the API ecosystem.
  • A comprehensive implementation involves code analysis, traffic detection, and surface mapping (crawling).
  • The process compiles a comprehensive list of discovered APIs with metadata (request types, parameters, response formats, authentication methods).
  • The result is a visual map of the API environment, showcasing endpoint connections, supported methods, and exposed resources.

2. F5 Distributed Cloud API Security: Multi-Lens Discovery

  • F5 Distributed Cloud API Security provides multiple discovery lenses, from development time to runtime.

3. Code Scanning (Shift-Left Discovery)

  • Process:
    1. Analyzes application source code to identify all API endpoints.
    2. Examines code repositories.
    3. Generates a comprehensive API inventory and OpenAPI specification directly from the code.
  • Benefits:
    • Enables early detection of security vulnerabilities.
    • Helps teams address potential risks and compliance issues before they escalate.
    • Streamlines development by integrating security and regulatory checks early.
    • Ensures robust API design and faster time to market.
  • Implementation:
    • Onboarding repositories to the platform is streamlined with support for multiple repository services and authentication methods.
    • Assign the codebase to a distributed cloud load balancer.
    • Full visibility into the API inventory is provided via the API endpoints dashboard.
  • Key Argument: Proactive discovery of APIs and potential issues before deployment.

4. Inline Runtime API Discovery

  • Process:
    1. Analyzes request and response traffic in real-time.
    2. Identifies HTTP methods, valid parameter values, and baselines behavior.
    3. Generates an OpenAPI specification based on observed traffic.
  • Benefits:
    • Enhances the API inventory.
    • Complements shift-left discovery.
    • Enables anomaly detection.
    • Detects drift by comparing live behavior with defined schemas.
    • Tracks frequent API changes and uncovers shadow APIs.
    • Updates or supplements code-based schemas.
  • Behavioral Modeling: Detects anomalies such as spikes in request rates, latency, response size, and instances of sensitive data.
  • API Authentication Discovery: Documents authentication methods, header and payload details, and JWT token structures, highlighting user roles, IDs, and sensitive data fields.
  • Key Argument: Reactive API discovery by observing APIs in operation.

5. Out-of-Band API Discovery with F5 BIG-IP

  • Process:
    1. Onboard the BIG-IP via a distributed cloud customer edge node.
    2. The platform discovers virtual servers and presents them for management by the Web App and API Protection (WAAP) service.
    3. Enable discovery and provide an OpenAPI specification to create an inventory.
  • Benefits:
    • Visualize discovered data in dashboards.
    • Perform drift detection by comparing live behavior with inventoried schemas.
    • Analyze vulnerabilities found by the platform.

6. API Surface Mapping (Crawling)

  • Process:
    1. Starts with a seed URL.
    2. Sends HTTP requests to uncover additional endpoints.
    3. Iteratively explores further by analyzing response data for links, parameters, or references that lead to other APIs.
  • Benefits:
    • Enhances runtime discovery by identifying endpoints that might not currently see active traffic.
    • Uncovers exposed APIs that could exist in areas outside the reach of traditional security proxies.
    • Ensures comprehensive monitoring of attack surfaces that might go otherwise unnoticed.
  • Key Argument: Provides an additional layer of visibility, especially adept at sniffing out zombie APIs.

7. Conclusion

  • A fresh perspective and a more comprehensive approach to API security are essential due to the evolving landscape of application architectures and sophisticated attack methods.
  • Modern defenses must adapt by increasing API visibility through effective multi-lens discovery.
  • F5 Distributed Cloud API Security allows leveraging each of these lenses of discovery to gain a deeper understanding of the API landscape.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.