F5 API Security: Attack and Defend

F5 DevCentralAbout 4 min readMay 27, 2025Watch original
THE SUMMARYAI-generated

F5 Distributed Cloud Platform API Security Demo Summary

Key Concepts:

  • API Security
  • F5 Distributed Cloud Platform
  • API Inventory
  • Risk Score
  • SSRF (Server-Side Request Forgery)
  • Schema Validation
  • WAF (Web Application Firewall)
  • SQL Injection
  • Mass Assignment
  • Service Policy
  • Regular Expressions (Regex)
  • API Protection Rule
  • Authentication (Auth) Header
  • Defense-in-depth

API Inventory and Risk Assessment

The F5 Distributed Cloud Platform provides an API inventory with detailed information about each endpoint, including:

  • Discovered sensitive data types.
  • Threat level based on attack traffic volume.
  • Authentication status.
  • API category.
  • Calculated risk score.

The risk score helps prioritize investigation and remediation efforts. A high risk score indicates potential vulnerabilities or active attacks.

Example: The "contact mechanic" endpoint has a risk score of 90, prompting further investigation.

SSRF Vulnerability and Remediation

The "contact mechanic" endpoint is vulnerable to SSRF because it passes a URL inside the request body without proper validation.

  • Evidence: The platform provides a link to the request monitoring tab, showing the base64 encoded body containing the URL. Decoding the body reveals an SSRF attack targeting Google search.
  • Remediation Options:
    • Fix the application code.
    • Update the OpenAPI Specification (OAS) to include schema validation.
    • Configure a rule using regular expressions to enforce allowed URL values.
    • Enable WAF and SSRF signatures.
  • Step-by-step Remediation:
    1. Modify the OAS to define a specific pattern for the URL field.
    2. Set a maximum number of repeated attempts (e.g., 5).
    3. Upload the updated specification to the API definition.
    4. Edit the inventory validation enforcement type and set it to "block."

SQL Injection Attack and WAF Configuration

The platform detects a SQL injection attack targeting the "coupon validation" endpoint.

  • Alert: A WAF alert indicates a violation in the coupon field.
  • Remediation:
    1. Set the WAF to blocking mode to mitigate the attack.
    2. Optionally, add the attacker to the blocked client list.
  • Step-by-step Remediation:
    1. Edit the app firewall.
    2. Change the enforcement mode to "blocking."

Mass Assignment Vulnerability and Service Policy

The "create order" API has a mass assignment vulnerability where passing a negative number in the quantity field increases the attacker's wallet balance.

  • Remediation Options:
    • Implement a quick fix using a service policy with regular expressions.
    • Modify the specification to prevent negative numbers from passing validation.
  • Service Policy Implementation:
    1. Edit the load balancer.
    2. Navigate to common security controls and apply specific service policies.
    3. Create a new policy and add a rule to deny requests with negative quantity values.
    4. Use a regular expression to match the quantity field and ensure it's a whole number.
    5. Apply the rule and save the changes.
  • Specification Modification:
    1. Edit the API definition.
    2. Upload the latest version of the specification with validation for non-negative numbers.

Missing Authentication Header and API Protection Rule

The "get order" API has a risk score of 90 because requests are being passed without the required authentication (Auth) header, even though the specification defines authentication.

  • Remediation:
    • Create an API protection rule to block requests without the Auth header.
  • API Protection Rule Configuration:
    1. Navigate to the security posture tab for the API.
    2. Click "configure" to create a new rule.
    3. Set the rule to "deny."
    4. Under HTTP headers, add an item for the "Authorization" header.
    5. Set the match option to "not present."
    6. Save the rule.

Defense-in-Depth API Security Strategy

The platform's runtime monitoring and protection capabilities are only part of a comprehensive API security strategy. A well-rounded approach includes:

  • Secure coding practices.
  • Testing OpenAPI specifications prior to production deployment.
  • Conducting API threat surface mapping.
  • Penetration testing APIs after deployment.

Conclusion

The F5 Distributed Cloud Platform provides a range of API security capabilities, including vulnerability detection, remediation, and runtime protection. By combining the platform's features with secure coding practices and thorough testing, organizations can build a robust defense-in-depth API security strategy.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.