F5 Distributed Cloud Platform API Security Demo Summary
Key Concepts:
- API Security
- F5 Distributed Cloud Platform
- API Inventory
- Risk Score
- SSRF (Server-Side Request Forgery)
- Schema Validation
- WAF (Web Application Firewall)
- SQL Injection
- Mass Assignment
- Service Policy
- Regular Expressions (Regex)
- API Protection Rule
- Authentication (Auth) Header
- Defense-in-depth
API Inventory and Risk Assessment
The F5 Distributed Cloud Platform provides an API inventory with detailed information about each endpoint, including:
- Discovered sensitive data types.
- Threat level based on attack traffic volume.
- Authentication status.
- API category.
- Calculated risk score.
The risk score helps prioritize investigation and remediation efforts. A high risk score indicates potential vulnerabilities or active attacks.
Example: The "contact mechanic" endpoint has a risk score of 90, prompting further investigation.
SSRF Vulnerability and Remediation
The "contact mechanic" endpoint is vulnerable to SSRF because it passes a URL inside the request body without proper validation.
- Evidence: The platform provides a link to the request monitoring tab, showing the base64 encoded body containing the URL. Decoding the body reveals an SSRF attack targeting Google search.
- Remediation Options:
- Fix the application code.
- Update the OpenAPI Specification (OAS) to include schema validation.
- Configure a rule using regular expressions to enforce allowed URL values.
- Enable WAF and SSRF signatures.
- Step-by-step Remediation:
- Modify the OAS to define a specific pattern for the URL field.
- Set a maximum number of repeated attempts (e.g., 5).
- Upload the updated specification to the API definition.
- Edit the inventory validation enforcement type and set it to "block."
SQL Injection Attack and WAF Configuration
The platform detects a SQL injection attack targeting the "coupon validation" endpoint.
- Alert: A WAF alert indicates a violation in the coupon field.
- Remediation:
- Set the WAF to blocking mode to mitigate the attack.
- Optionally, add the attacker to the blocked client list.
- Step-by-step Remediation:
- Edit the app firewall.
- Change the enforcement mode to "blocking."
Mass Assignment Vulnerability and Service Policy
The "create order" API has a mass assignment vulnerability where passing a negative number in the quantity field increases the attacker's wallet balance.
- Remediation Options:
- Implement a quick fix using a service policy with regular expressions.
- Modify the specification to prevent negative numbers from passing validation.
- Service Policy Implementation:
- Edit the load balancer.
- Navigate to common security controls and apply specific service policies.
- Create a new policy and add a rule to deny requests with negative quantity values.
- Use a regular expression to match the quantity field and ensure it's a whole number.
- Apply the rule and save the changes.
- Specification Modification:
- Edit the API definition.
- Upload the latest version of the specification with validation for non-negative numbers.
Missing Authentication Header and API Protection Rule
The "get order" API has a risk score of 90 because requests are being passed without the required authentication (Auth) header, even though the specification defines authentication.
- Remediation:
- Create an API protection rule to block requests without the Auth header.
- API Protection Rule Configuration:
- Navigate to the security posture tab for the API.
- Click "configure" to create a new rule.
- Set the rule to "deny."
- Under HTTP headers, add an item for the "Authorization" header.
- Set the match option to "not present."
- Save the rule.
Defense-in-Depth API Security Strategy
The platform's runtime monitoring and protection capabilities are only part of a comprehensive API security strategy. A well-rounded approach includes:
- Secure coding practices.
- Testing OpenAPI specifications prior to production deployment.
- Conducting API threat surface mapping.
- Penetration testing APIs after deployment.
Conclusion
The F5 Distributed Cloud Platform provides a range of API security capabilities, including vulnerability detection, remediation, and runtime protection. By combining the platform's features with secure coding practices and thorough testing, organizations can build a robust defense-in-depth API security strategy.
AI summaries can miss context or contain errors. Check important details against the original video.





