This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP API Security Project"

From OWASP
Jump to: navigation, search
(Remove redundant section - Project About)
(Added parties and individuals to the Acknowledgments section)
Line 90: Line 90:
 
= Acknowledgements =
 
= Acknowledgements =
  
==Contributors==
+
==Founders==
 +
* Erez Yalon
 +
* Inon Shkedy
 +
 
 +
==Sponsors==
 +
[[File:Checkmarx-Logo-Horizontal-black-512px.png|left|Checkmarx Logo]]
 +
[[File:SALT Logo.jpg|512px|none|left|SALT Logo]]
  
The OWASP API Security Project is small, but will be maintained by volunteers. If you'd like to volunteer, please contact the Project Leader.
+
==Main Maintainer==
 +
* Paulo Silva
  
 +
==Contributors==
 +
* David Sopas
 +
* Chris Westphal
  
 
= Road Map =
 
= Road Map =

Revision as of 12:52, 31 May 2019

OWASP Project Header.jpg

OWASP API Security Project

[24-Dec-2018]

The OWASP API Security Project is now under new leadership. A new roadmap and call for contribution will be published by the end of Feb 2019.


This project is designed to address the ever-increasing number of organizations that are deploying potentially sensitive APIs as part of their software offerings. These APIs are used for internal tasks and to interface with third parties. Unfortunately, many APIs do not undergo the rigorous security testing that would render them secure from attack.

The OWASP API Security Project seeks to provide value to software developers and security assessors by underscoring the potential risks in insecure APIs and illustrating how these risks may be mitigated. In order to facilitate this goal, the OWASP API Security Project will create and maintain a Top 10 API Security Risks document, as well as a documentation portal for best practices when creating or assessing APIs.

Description

While working as developers or information security consultants, many people have encountered APIs as part of a project. While there are some resources to help create and evaluate these projects (such as the OWASP REST Security Cheat Sheet), there has not be a comprehensive security project designed to assist builders, breakers, and defenders in the community.

This project aims to create:

  • The OWASP Top Ten API Security Risks document, which can easily underscore the most common risks in the area.
  • Create a documentation portal for developers to build APIs in a secure manner.
  • Work with the security community to maintain living documents that evolve with security trends.

Licensing

The OWASP API Security Project documents are free to use!

The OWASP API Security Project is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.

What is this project?

The OWASP API Security Project seeks to deliver actionable documentation on creating and deploying verifiably secure web APIs, as well as illustrating the major risks and shortfalls that APIs may encounter. By helping developers create resilient software, and helping assessors understand the subtle risks an API may entail, the goal of this project is to bring security to an increasingly programmatic world.

The primary deliverables of this project are the OWASP Top Ten API Security Risks and a secure API development documentation portal.

Presentation

The OWASP API Security Project will be presented at OWASP Global AppSec Tel Aviv, May 2019.

Project Leaders

Related Projects

Quick Download

Once API Security documents are created, they will be available for direct download here.

The initial version of this document, including an up-to-date table of contents, is available here.

News and Events

There has not yet been press coverage of this project.

Classifications

New projects.png Owasp-builders-small.png
Owasp-breakers-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files DOC.jpg

Founders

  • Erez Yalon
  • Inon Shkedy

Sponsors

Checkmarx Logo
SALT Logo

Main Maintainer

  • Paulo Silva

Contributors

  • David Sopas
  • Chris Westphal
API Security Project Road map 2019