F5 API Security BIG-IP Integrations: Out-of-Band API Discovery

F5 DevCentralAbout 3 min readMay 27, 2025Watch original
THE SUMMARYAI-generated

Key Concepts:

  • Out-of-band API Discovery
  • F5's API Security Solution
  • Big IP Application Delivery Controllers
  • Distributed Cloud Regional Edges
  • Distributed Cloud Customer Edge Node Site
  • Web App and API Protection Service
  • API Inventory
  • Sensitive Data Discovery
  • Authentication State
  • Risk Score
  • API Specification
  • Drift Detection
  • Vulnerability Detection
  • Shadow APIs
  • Open API Specification
  • Advanced WAF (Web Application Firewall)
  • API Security Policy

1. Out-of-Band API Discovery with F5's API Security Solution:

  • The demo showcases F5's API security solution's out-of-band API discovery capabilities.
  • This is achieved by integrating with Big IP application delivery controllers.
  • This integration provides deep insight into APIs hosted on-premise or in the public cloud.
  • Crucially, this insight is gained without traffic needing to pass through distributed cloud regional edges.

2. Onboarding and Virtual Server Discovery:

  • The process begins with onboarding the Big IP via a distributed cloud customer edge node site.
  • After onboarding, the platform automatically discovers virtual servers.
  • These discovered virtual servers are then presented for management by the Web App and API Protection service within the distributed cloud console.

3. Enabling Discovery and Visualizing Data:

  • Within the console, the user enables the API discovery process.
  • Once enabled and run, the discovered data is visualized in security dashboards.

4. API Inventory and Key Information:

  • The security dashboards provide a full API inventory.
  • This inventory includes critical information such as:
    • Discovered sensitive data
    • Authentication state
    • Overall risk score

5. Endpoint Analysis and API Specification:

  • Selecting a specific endpoint reveals its discovered and inventoried API specification.
  • This allows for drift detection by comparing live API behavior against the inventoried schema.

6. Vulnerability Detection and Remediation:

  • The system notifies users of any vulnerabilities found.
  • Information provided for each vulnerability includes:
    • Description
    • Risk score
    • Remediation recommendations
    • A link to the evidence found in the logs

7. API Definition and Shadow API Identification:

  • Users can create and apply an API definition based on their specification.
  • This allows for easy differentiation between inventoried APIs and shadow APIs (APIs not officially documented or managed).

8. Comprehensive Traffic Analysis:

  • API discovery analyzes all traffic, regardless of whether the destination endpoint is known or unknown to the platform.
  • This provides insight into both shadow APIs and known APIs, uncovering hidden vulnerabilities.

9. Open API Specification Generation:

  • The discovery process generates an Open API Specification (OAS) based on the discovered information.
  • This OAS can be downloaded manually or programmatically.

10. Applying API Security Policy on Big IP:

  • The generated OAS can be used as the basis for an API security policy on the Big IP advanced WAF.
  • The process involves:
    1. Uploading the specification to the policy.
    2. Assigning the policy to the virtual server.
    3. Setting learning and blocking preferences.
    4. Saving the configuration.

11. Continuous Monitoring and Policy Updates:

  • The Big IP continuously feeds traffic data to the discovery process in the distributed cloud.
  • This ensures that any changes introduced to the application are detected.
  • This continuous monitoring keeps the policies protecting critical applications up-to-date.

12. Conclusion:

  • F5's out-of-band API discovery solution provides comprehensive API visibility and security.
  • It enables organizations to discover, inventory, and protect their APIs, both known and shadow, by leveraging Big IP and distributed cloud technologies.
  • The continuous monitoring and policy update capabilities ensure ongoing protection against evolving threats.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.