Apigee (NASDAQ:APIC), developer of an intelligent API platform for digital business, today released Apigee Sense, new software that represents the industry’s first intelligent API security product. Apigee Sense is a data-driven security solution that leverages a high volume of API call data and predictive analytics to continually and proactively identify bad “bots” – the automated software programs deployed over the Internet for malicious purposes like identity theft. Apigee Sense software uses sophisticated machine learning to intelligently improve security as bad bots evolve; it extends the security capabilities of the Apigee Edge API management platform.
Apigee Sense is designed to help protect organizations from the cyber security threats that stem from the proliferation of API-powered, internet-connected devices and enterprise systems. Recent research has shown that bots accounted for almost 60 percent of all website traffic in 2014, and 23 percent were malicious in nature1.
“APIs deliver the data and information powering our hyper-connected world, so protecting APIs from cyber threats is key for safeguarding data,” said Chet Kapoor, Apigee CEO.
“Apigee customers have processed hundreds of billions of API calls through our platform in the past year to deliver rich digital experiences to their users,” he continued. “Apigee Sense delivers a new kind of API security that combines that API call volume with predictive analytics to quickly identify patterns for potentially malicious bots and then – most importantly — it learns and adapts as these bots evolve.”
The number of active wireless connected devices has been forecasted to balloon from 16 billion in 2014 to over 40 billion in 20202. With business-critical functions shifting to connected devices, enterprises are discovering new ways to innovate and grow. However, these new opportunities are also giving rise to new vulnerabilities. Cyber-attacks are inflicting damage to enterprises in the form of operational disruption, intellectual property loss, brand reputation and financial fraud. The annual cost of cybercrime to the global economy has been estimated at $400 billion3.
The new Apigee Sense software uses sophisticated bot detection algorithms built on predictive analytics and anomaly detection techniques aimed at distinguishing good bots and humans from the bad bots; potentially bad bots are then automatically identified and can be blocked by the customer from engaging in malicious activities on customers’ applications. ¬New capabilities include:
• Data-Driven Risk Models – Apigee Sense software includes a set of data-driven risk models that monitor billions of API calls in the Apigee Cloud, identify transaction anomalies, uncover hidden bot patterns and attacks, and provide insights for counter measures and investigation support. The risk models are powered by a high volume of API call data, machine learning algorithms and predictive analytics to continually adapt to threats.
• Advanced Security Analytics – Apigee Sense software presents the customer with visual dashboards that illustrate security analytics including bot traffic, bot activities and trends, and customized bot analytics based on a customer’s traffic profile. Using the customizable, browser-based interface, customer security analysts can quickly be notified of potentially bad bots and focus on counter measures.
• Automated Risk Mitigation – An API firewall engine identifies requests originating from potentially bad bots and can take appropriate counter-measures to immediately mitigate threats. Protective actions available to the customer include blocking, throttling, and ensnaring bots.
APIs are programming instructions that enable software applications to exchange data and “talk” to other applications; behind every mobile app, smart device and connected experience sits at least one API. The Apigee Edge API management platform enables organizations to securely deliver and manage APIs, with agility and at scale. Apigee Sense software extends the API security and governance features already available in the Apigee Edge platform.
Apigee Sense software is available immediately; it works with the Apigee Edge API management platform. More information about Apigee Sense can be found here.
API Security Best Practices at “I Love APIs” 2015
The 2015 “I Love APIs” conference, October 12-14 in San Jose, will feature sessions about how to protect your enterprise and safeguard privacy in today’s interconnected digital world, such as “Managing Identities in the world of APIs”, “Privacy in the world of Apps, Devices and Things,” “Securing the API Lifecycle”, “Protecting your APIs from Mobile Threats,” and “Data Driven Security.”