Insight

[Opinion] In the Age of AI, It Is Time to Review API Security

IT DAILY ·

Mark O'Neill, Gartner VP analyst. [Photo: Gartner]

✦ AI Summary

API is one of the fastest-growing attack surfaces in enterprise environments, and its importance is growing even further as AI spreads.

LLMs, RAG pipelines, fine-tuning, and AI agents all use API, and AI agents connect to external services through frameworks such as MCP.

Accordingly, he emphasized the need for a security framework that covers the entire API lifecycle, along with visibility, threat modeling, multi-layered defense, and strong access control.

In his opinion piece, Mark O'Neill, a VP analyst at Gartner, noted that API is one of the fastest-growing attack surfaces in enterprise environments. He explained that API plays a role in delivering modern user experiences across web and mobile channels, supporting system integration, and enabling automation.

He added that API's importance is growing even further as AI spreads. LLMs are delivered through API-based services, and the means by which LLMs interact with other systems is also API.

He also noted that many AI systems, including retrieval-augmented generation (RAG) pipelines, fine-tuning, and AI agents, use API. He added that AI agents connect to external services through frameworks such as the Model Context Protocol (MCP). Based on this, he stressed the need to review API security as AI becomes part of everyday life, saying that there is no AI without API.

Many companies argue that API traffic has surged as AI use cases have increased, and that the number of APIs has risen sharply as automation has spread. At the same time, dependence on API is increasing and the scale of API is expanding explosively. The spread of API-centric architectures is also continuing.

In this environment, attackers are shifting their attention to API. If API keys for AI platforms such as Anthropic and OpenAI are stolen, serious damage could occur. In fact, there have been cases in which large-scale files and user accounts were exposed through API attacks. It has also become clear that when API protection is inadequate, the scale of damage can be large.

However, many companies do not have separate protections in place for internal APIs, and there are also many cases in which public APIs are not properly protected. API can be created and connected quickly, making consistent protection difficult. As a result, a structure in which protection gaps can emerge is expanding.

The spread of AI agents is deepening the security imbalance. Development tools such as coding agents are accelerating the automation of API development and creation, while frameworks such as MCP support agent-based dynamic access to multiple services through API. As a result, controlling agent access privileges and the scope of API use has become necessary, and new security challenges are emerging with the spread of AI agents.

API designed for legitimate use can be misused by attackers for data collection. As automation of service access and API development spreads, the abuse of normal API calls for attacks is being added to the mix, making monitoring for the purpose of distinguishing legitimate from malicious API calls even more important. The rapid expansion of the API ecosystem and the swift widening of the attack surface across managed APIs are also increasing this need.

In this environment, distributed individual controls alone have limits in responding to risk. Accordingly, there is growing demand for a security framework that covers the entire API lifecycle. The starting point of this framework is an exhaustive understanding of the current API landscape.

The scope of verification includes company-owned APIs and third-party APIs the company depends on. The items to identify include APIs in development and APIs in production, and suggested identification methods include traffic pattern analysis and automated tools that inspect code repositories. As security framework elements, organizations need to identify existing APIs, set priorities by risk, and systematically apply protective measures across the entire process from development to operations.

Suggested risk classification criteria include an API's business importance, data sensitivity, external exposure level, and whether AI agents have access. Applying the same controls to all APIs is inefficient, so the goal is to concentrate security capabilities on areas with the highest actual risk.

To secure API, threat modeling is needed to understand attack methods and the security controls required. The targets of threat modeling should include API usage patterns and potential attack paths. Threat modeling should also take into account industry characteristics, regulatory obligations, regional requirements, and the enterprise environment, and the way AI agents interact with API also needs to be reflected in the threat model.

At the same time, organizations need to continuously detect misconfigurations and gaps in protection, and they need to integrate security checks into the development pipeline. They must automate the response to and remediation of identified issues, which will help them respond quickly to vulnerabilities in a rapidly changing API environment. Ultimately, the protection framework should be multi-layered, with defenses against distributed denial-of-service (DDoS) attacks, web application firewalls (WAF), bot countermeasures, and API threat defense as the defense layers to be deployed. In addition, it is necessary to detect and mitigate various types of attacks, and strong access control is essential. To do this, organizations should use standards such as OAuth and control access rights through API gateways, while also needing control functions that detect unusual user behavior and signs of API abuse. Existing ID and access management (IAM) policies must be extended to the AI agent ecosystem.

API discovery and classification, threat modeling, security posture management, multi-layered defense, and access control are not separate tasks for individual measures; they require operating a single system across the entire API lifecycle. The purpose is to respond to the scale, speed, and complexity of APIs that are increasing through AI.

The scope of API security is not limited to problems with API itself; it is linked to LLMs and AI agents accessing data and application functions through API. For this reason, gaps in API security lead to risks in AI workloads, and the proposition that there is no AI without API is paired with the proposition that there is no secure AI without API security.

Accordingly, the key task is presented as accountability and integration. Companies need to make API security a priority and clarify who within the company is responsible. They also need to integrate API security into their overall security strategy, in order to respond to the rapidly expanding attack surface.

Source: IT DAILY · Mark O'Neill
Original: https://www.itdaily.kr/news/articleView.html?idxno=242096

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.