Skip to main content
Guidance

Securing HTTP-based APIs

How to ensure that application programming interfaces are designed and built securely.

Page 5 of 8

4. Input validation

Input validation is the process of inspecting and validating data received by an API before it is processed. This validation ensures that the input adheres to specified criteria (such as data type, format, length, and range), and is free from potentially malicious or unexpected content. For more information refer to the ‘Make compromise difficult’ section of the NCSC's Secure design principles.

Effective input validation is essential for preventing various security vulnerabilities, including injection attacks, data tampering, and denial-of-service (DoS) attacks which can compromise the confidentiality, integrity, and availability of API resources. 

You should validate input as early as possible, ideally when data is received from external sources and to ensure validation at every system layer. Unintentional inconsistencies between layers are a well-known cause of vulnerabilities. At the user interface layer, it helps catch basic errors early. The application logic layer enforces business rules, ensuring only valid data proceeds, while the data access layer prevents injection attacks and enforces database constraints. Consistent validation across all layers reduces risks and creates a more secure, defence-in-depth architecture.  

If using an API gateway, it should perform initial validation but should not be the sole validation point. Implement a multi-layered approach where the gateway handles basic checks, while backend services perform detailed, context-specific validation. To streamline this process and ensure consistency, consider implementing a central input validation library or process, so you don't need to reimplement validation logic for each function.


Published

Reviewed

Version

1.0