Loading...

13 Jun 2026 20:47

Leadership Perspectives Tech & Start Up

App vs. API Security? Bots don’t care. Defend Your Digital Assets- Lori MacVitte, F5 Distinguished Engineer

If you’re confused and can’t decide, that’s okay. That’s the point. App and API endpoints look pretty much the same. That’s because in technical terms if they’re RESTful (and most are) they are invoked in the same way, via HTTPS and usually with a GET method. What’s often different is the payload sent with the request. For APIs that typically contains some data in a JSON or XML format while web app requests may contain, well, nothing.

Still, one of the key findings from F5’s annual State of Application Strategy report implies that organizations treat APIs as different from applications when it comes to security. We infer this based on the finding that 41% of organizations have at least the same or greater number of APIs than they do applications and yet place a lesser value on the same security services that protect them.

You might wonder how organizations would end up with more APIs than apps. Thanks for asking! While APIs used for internal, service-to-service communication (a la microservices) are certainly tightly coupled to the service they support, this is not necessarily true when APIs are used to present external interfaces.

Where do APIs come from?

Consider that in our 2021 research, 61% of respondents told us they were “adding a layer of APIs to enable modern user interfaces” as a method of modernization. In 2022 that number was 45%. What that means is the APIs enabling modern user interfaces are not necessarily artifacts directly attached to applications.

They might be façades that facilitate modern user interfaces and applications, like mobile apps and digital services, or they might be façades designed to enable partner and supply chain communications. These use cases are supported by API Gateways and layer 7 routing in load balancers, which often provide some level of transformation capabilities that allow them to translate from API endpoint to app endpoint, thus enabling an API façade like those that make old American west buildings appear much more impressive than they are.

And of course, a goodly number of APIs are public-facing entities attached to apps and accessed via the web (typically HTTPS).

Regardless of how they got there, public-facing APIs are subject to many of the same attacks as applications. This is especially true when bots are involved, as APIs with good documentation simply make it easy for attackers to script attacks at scale.

For example, just over 13% of transactions protected by F5 Distributed Cloud Bot Defense in 2023 were automated. That is, a script or software was used instead of a human using a web browser or mobile app. Those transactions occur via both APIs and apps. Some percentage of those automated transactions were certainly “bad bots” that the presence of our security service prevented from doing whatever bad thing they were trying to do. (You can dig deeper into what they were trying to do in this F5 Labs report)

So, when we looked at how respondents perceive bot management based on their self-reported number of APIs, we were somewhat shocked to discover that bot management is pretty low on the importance scale.

While the importance placed on API Gateways appears to be appropriate to the number of APIs under management, the same is not true for bot management. In fact, it’s completely the opposite! As the number of APIs grows, the importance of bot management appears to decline rapidly.

It could certainly be the case that the bulk of those APIs are internal. That is, they are east-west APIs between microservices that are not exposed to external actors that might be bad bots with malicious intent.

But then again, they might be. Given the number of articles I’ve read in the past year about attackers gaining access via APIs, I’m going to guess there are a lot more external than we think.

So, it’s time to remind folk that while there are a number of annoying bots out there—grinch bots, sneaker bots, etc.—that disrupt business by gobbling up high-demand goods, there are also a significant number of bots whose only purpose it is to sniff out vulnerabilities and attack them. In both APIs and applications.

Thus, it would be a good idea for organizations to employ a full range of security options to protect their APIs and ultimately, their business. Bot management is certainly one of those security options and should be considered a critical component of any security strategy.

At the end of the day, the bots don’t care whether that endpoint belongs to an app or an API. They’re going to attack both.

Which means organizations need to be protecting both apps and APIs by detecting bots and preventing them from doing whatever bad thing they’re trying to do.

(Visited 227 times, 1 visits today)
peri hokiperihokiduta 76AWSBEThttps://sintnicolaasschool.com/https://abc1131aa.com/kincir88cakar76Slot mahjonghttps://www.abc1131.it.com/Gerakan99Era77stc76duta76duta76 loveduta76 careduta76bduta76 sejiwaduta76 lokasiterdekatduta76 africafuelduta76 oscarmykeduta76 naptimepkduta76 daikinduta76 raes-munichduta76 destyduta76 bio-linkduta76 lynkduta76 heylinkduta76 bioduta76 radarkeduWar138navigasi rtp live eksploitasi peluang taktik mahjong wild deluxe analisa dadu sicbo strategi gates of olympusanalisa komprehensif rtp live pola algoritma strategi mahjong ways 2 pgsoft taktik baccarat teknik starlight princessoptimasi presisi analisa strategi blackjack teknik membaca pola mahjong wins 3 taktik peluang rtp live sweet bonanza pragmaticdekonstruksi peluang taktis strategi analisa roulette pemetaan pola mahjong ways 2 pgsoft teknik membaca rtp live wild west goldeksekusi taktis analisa probabilitas strategi komprehensif sv388 teknik membaca peluang blackjack pola mahjong wins 3 pemetaan rtp live sugar rushstrategi rasional baca rtp live analisa pola gates of olympus taktik sicbo teknik mahjong wild deluxe jitutaktik eksekusi presisi sinkronisasi analisa rtp live pola mahjong ways 2 pgsoft teknik baccarat kuantitatif peluang starlight princesseksploitasi algoritma analisa strategi taktis menaklukkan blackjack pemetaan pola mahjong wins 3 teknik rtp live sweet bonanza pragmaticmetodologi optimasi peluang analisa teknik roulette klasik taktik pola mahjong ways 2 pgsoft strategi rtp live wild west goldanalisa matriks peluang sinkronisasi teknik blackjack taktik sv388 strategi pola rtp live mahjong wins 3 sugar rush pragmatichttps://www.thewayofthespirit.com/contact/kalkulasi taktik cerdas strategi peluang sicbo teknik pola mahjong wild deluxe analisa rtp live gates of olympusdekonstruksi varians strategi pola mahjong ways 2 pgsoft analisa peluang baccarat taktik teknik rtp live starlight princesseksekusi silang taktik teknik strategi blackjack analisa pola mahjong wins 3 pragmatic peluang rtp live sweet bonanzaformulasi taktik peluang roulette analisa pola mahjong ways 2 pgsoft teknik jitu strategi rtp live wild bounty hunternavigasi probabilitas analisa pola mahjong wins 3 pragmatic taktik peluang blackjack strategi sv388 teknik rtp live sugar rushcara mahjong ways 2 tetap dibicarakanmahjong wins 3 super scatter berbedamengapa mahjong ways 2 simbol emasscatter emas mahjong ways 2 polascatter emas mahjong ways tempo permainanwild berlapis mahjong wins pola unikanalisis mahjong ways alasan kembali memainkangates of olympus super scatter 2026mahjong ways 2 pola menarik waktu berbedamahjong wins 3 simbol emas berantaievaluasi manajemen struktur taruhan mahjong waysanalisis retensi pemain pg soft mahjong wins 3pengaruh tren mahjong ways hiburan domestikbedah eksistensi mekanik mahjong wins 3evaluasi dampak peluang tren mahjong waysinovasi estetika metrik rasio mahjong ways 2fenomena kontra siklus pasar mahjong wins 3model skema progresif sistem probabilitaspengukuran interval distribusi simbol mahjong waysintegrasi infrastruktur big data pgsoftanatomi struktur wild tengah mahjong wins 3 karakter mekanik baru pasca update versi klasikanomali perilaku scatter hitam parameter baru perubahan karakter kemunculan yang ramai diperbincangkandekonstruksi algoritma putaran cepat manajemen waktu konsistensi pemetaan pola sugar rush terstrukturevolusi karakteristik wild tengah mahjong ways efek pembagian simbol durasi putaran efektiffenomena anomali simbol kembar beruntun statistik dinamika formasi gates of olympus modern digitalintegrasi metodologi rtp live pragmatic statistik sweet bonanza kalibrasi pola dinamis adaptifkonvergensi pola mahjong wild deluxe logika dadu sicbo strategi sistematis perubahan ritme modernmetodologi pemetaan probabilitas pragmatic distribusi rtp live sweet bonanza sugar rush rasional modernprotokol taktis kalkulasi peluang blackjack integrasi manajemen risiko kalibrasi strategi analisa sv388 modernstrategi komparatif logika dadu sicbo blackjack mengukur titik jenuh probabilitas pendekatan analitikkeindahan simbol mahjong menari scattersimfoni tarian mahjong ways scatteraksi memikat simbol mahjong hujanmomen magis simbol mahjong scattertransisi lembut scatter hitam mahjong besargates of olympus 1000 sensitivity mapping variansi hasilpemodelan stokastik mahjong wins rtp variansimahjong wins 3 frekuensi fitur distribusi datamahjong ways analisis scatter wild variansitutorial rtp live gates of olympus scatter datadilema validitas rtp live gates of olympus indikator visual fluktuasi dinamika analisis modern adaptifeksplorasi efisiensi taktis analisa sv388 manajemen risiko anomali putaran strategi rasional terukuridentifikasi variabel unik wild tengah mahjong wins 3 pembaharuan visual durasi simbol langka dinamiskalkulasi deviasi pola distribusi sweet bonanza pemetaan terstruktur perubahan algoritma statistikkatalisator perubahan algoritma scatter hitam fenomena visual komunitas kontemporer dinamika diskusimekanisme trigger scatter hitam terbaru analisis komparatif perubahan karakter mekanik dinamika visual modern berkembangprotokol defensif manajemen modal sugar rush indikator rotasi simbol langka pendekatan taktis analitissinergi analisa sv388 taktik peluang blackjack komposisi rasional fluktuasi sistem data polatransformasi geometris formasi grid transisi simbol premium dinamis pola visual ritme perubahanvalidasi empiris indikator struktural gates of olympus formasi dinamis deviasi rtp live analisis teknismetodologi manajemen informasi keputusan gameimplementasi analitik cerdas platform pgsoftarsitektur ai big data kasino virtualevaluasi konfigurasi observatif midas fortunepemetaan ritme putaran strategi mahjong wayseksplorasi efek kumulatif variabel wild tengah mahjong wins 3 stabilitas pengali bertingkat komparatifkajian fenomenologi perilaku scatter hitam lonjakan minat komunitas pasca pembaharuan sistem analisis persepsilonjakan multiplier free spin pg soft kecenderungan mahjong ways 2 persentase rtp malam harimetodologi pemetaan densitas kategori mahjong ways kecepatan runtuhan distribusi simbol langka analisis strukturaluji probabilitas matematis black scatter putaran cepat mahjong wins 3 wild bertingkat analisismulti wild mahjong ways pendekatan data historis berita komunitas minat pemain baru analisispemetaan alur permainan pragmatic play strategi blackjack baccarat uji keaslian terkini analisisperhitungan waktu presisi mahjong wins trigger tumbling uji valid berbasis pengalaman analisisprobabilitas wild keakuratan rtp pragmatic mahjong wins 3 perbedaan ritme analisis statistiktrik blackjack dan baccarat acuan mahjong wins 3 target harian analisis ritme strategigates of olympus 1000 sensitivity mapping variansi hasil​pemodelan stokastik mahjong wins rtp variansi​ Top