API Security is complex! Vendors like Forum Systems, IBM, CA and Axway have invested almost 2 decades of engineering effort and significant capital in building API Security stacks to lockdown APIs. The API Security stack diagram shown below is essential for rapidly locking down APIs. In the article, we review "The Four Pillars of API Security" --- SSL, Identity, Content Validation and Architecture.
Before addressing the Four Pillars of API Security, it is essential to recognize that a robust PKI is a must of enterprise-grade API Security. Without proper key life-cycle management, the API Security Pillars cannot be built.
Once a solid PKI foundation is in place, the following API Security four pillars should be built to ensure that an enterprise API attack surface area is significantly reduced. To implement API Security: