Skip to main content

New guidance on securing HTTP-based APIs

Why it’s essential to secure your APIs to build trust with your customers and partners.
traffic_analyzer via Getty Images

From social media platforms to the financial sector, to healthcare and telecoms. APIs (application programming interfaces) underpin a vast range of digital functions, and facilitate seamless data exchange between systems and services.

Unfortunately, this increasing use of APIs provides attackers with greater opportunities to exploit vulnerabilities within their design and implementation.

Recent public reports on high-profile API security breaches include:

In response to this increased threat, the NCSC has published new guidance on securing HTTP-based APIs, which is designed to help technical staff to design or build secure applications that offer an HTTP API. 

Relying on outdated security methods (such as basic authentication using base64-encoded usernames and passwords) is no longer sufficient. Other bad practices that the guidance addresses includes:

  • the absence of rate limiting or user throttling
  • leaving endpoints vulnerable to denial of service or brute-force attacks
  • storing credentials in code
  • transmitting sensitive data in URLs
  • poor input validation
  • failing to encrypt API traffic using HTTPS
  • minimising unnecessary exposure to the internet
  • neglecting proper logging and monitoring

Historically, API keys have been a popular choice for authenticating and authorising API requests, acting as shared credentials between clients and servers. But they come with significant security risks:

  1. They are prone to theft through methods like phishing, exposure in leaked source code or improper storage.
  2. The absence of built-in expiration means that if a key is compromised it can be exploited indefinitely (unless manually revoked or rotated).
  3. API keys fail to provide granular control, often enabling unrestricted access instead of tailored permissions (which combined with an absence of rate limiting can allow attackers swift and unrestricted access to sensitive data).

For all these reasons, relying solely on API keys is no longer considered best practice, which is why the guidance includes information about stronger authentication frameworks such as OAuth 2.0 or token-based authentication. 

As the above examples illustrate, the impact of your API being compromised could disrupt operations, damage your organisation’s reputation and may even lead to fines from regulatory bodies. Strengthening API security should not simply be seen as a protective measure; it can also enable organisations to enhance agility, simplicity and productivity.

We hope that you use the new guidance to secure your APIs and build trust with your customers and partners, whilst mitigating the risk of financial or reputational damage.

James H
Telecoms Security Consultant

Written by

James H Telecoms Security Consultant

Published

Part of blog