$400 Fullstack Live Event Free With a Membership!
In this workshop, you will get to know vulnerabilities and how they can be exploited to break into an application through an API. A closer look at OWASP’s API Security Top 10 will provide you with details about some possible attacks and their prevention. You will learn to protect APIs against attacks using secure coding practices, software architecture, and security infrastructure like API gateways.
This practice-oriented workshop is not about compliance and papers. It’s about technology and methodology with lots of demonstrations and exercises. APIs are connecting Single Page Applications on the Web with backend systems containing sensitive data. Companies are becoming platforms by exposing business functions as APIs. The ever-growing attack surface of APIs is opening backdoors into applications. IT security has just started to recognize APIs as a vector for attacks.
To effectively protect APIs, it is important to understand potential attacks and their targeting. In the workshop, you learn how to think like a hacker and apply several techniques to break into an application through an API. You will learn how to discover API-related security issues and vulnerabilities. We will discuss current best practices and strategies for improving API security.
API security and vulnerabilities – using the OWASP API Security Top 10.
Attack techniques from a hacker’s perspective – through hands-on live-hacking demonstrations and exercises.
Robust protection mechanisms with secure code and architecture – with best practices, API gateways, and authentication strategies.
Integrating API security effectively into your development process – learn immediately applicable security strategies that seamlessly fit into your existing software architecture and provide long-term protection.
Software developers who want to not only develop APIs but also actively secure them against attacks.
Backend and full-stack developers who want to identify security risks in APIs early and implement robust protection measures.
Security engineers and DevOps teams who want to integrate API security into existing systems and workflows to sustainably minimize security gaps.
Tech leads and architects who want to evaluate secure API designs and implement best practices for authentication, authorization, and defense mechanisms.
Tobias has been a software architect for over 10 years. He supports customers operationally in achieving a real increase in security in a target-orientated manner. He is as well known as a speaker at conferences in the Netherlands, England and Australia as he is in Germany. Yoga and Asian cuisine are among his favourite hobbies.