Securing HTTP-based APIs
Page 5 of 8
4. Input validation
On this page
Input validation is the process of inspecting and validating data received by an API before it is processed. This validation ensures that the input adheres to specified criteria (such as data type, format, length, and range), and is free from potentially malicious or unexpected content. For more information refer to the ‘Make compromise difficult’ section of the NCSC's Secure design principles.
Effective input validation is essential for preventing various security vulnerabilities, including injection attacks, data tampering, and denial-of-service (DoS) attacks which can compromise the confidentiality, integrity, and availability of API resources.
You should validate input as early as possible, ideally when data is received from external sources and to ensure validation at every system layer. Unintentional inconsistencies between layers are a well-known cause of vulnerabilities. At the user interface layer, it helps catch basic errors early. The application logic layer enforces business rules, ensuring only valid data proceeds, while the data access layer prevents injection attacks and enforces database constraints. Consistent validation across all layers reduces risks and creates a more secure, defence-in-depth architecture.
If using an API gateway, it should perform initial validation but should not be the sole validation point. Implement a multi-layered approach where the gateway handles basic checks, while backend services perform detailed, context-specific validation. To streamline this process and ensure consistency, consider implementing a central input validation library or process, so you don't need to reimplement validation logic for each function.
Syntactic and semantic validation
Input validation should be applied on both a syntactic and semantic level:
- Syntactic validation ensures the correct syntax and structure of input data, typically focusing on predefined patterns, formats, and constraints. The validation examines whether the input conforms to expected standards and patterns, such as the correct format of email addresses, phone numbers, dates, or currency symbols.
- Semantic validation verifies the correctness of the data within the relevant business context (such as confirming that the start date precedes the end date, or falls within the expected range).
By enforcing both syntactic and semantic validation, developers can reject any input that does not adhere to the specified syntax rules and is accurate within the intended context, mitigating the risk of processing errors, data corruption, security vulnerabilities and enhancing data accuracy.
Syntactic validation good practice
JSON parsers
Strict JSON parsers ensure that the data is syntactically correct, validating that it adheres to the proper JSON format. If the input data contains structural errors, such as incorrect brackets or misplaced commas, the parser will raise errors or exceptions.
Centralised validation libraries
Use well-tested libraries or frameworks designed for input validation. These libraries often provide features like type checking, range validation and sanitisation, reducing reliance on complex and difficult-to-maintain regex patterns.
Allow lists
Allow list validation explicitly defines authorised input and ensures only permitted values are accepted. For example, with structured data from fixed options (like drop-down lists), exact matching of data formats should be employed.
Semantic validation good practice
Schema validation
JSON schema can be used to define the structure of data exchanged via APIs and validate incoming payloads against these schemas. Schema validation should also be used to ensure that an attacker is not sending extra clauses (key value pairs) that are not expected.
Data type validators
Many programming languages provide built-in mechanisms for type checking. For instance, in statically-typed languages like Java or TypeScript, the compiler can enforce data type correctness. In dynamically-typed languages like Python or JavaScript, libraries or custom functions can be used to perform type checking.
Minimum and maximum value range
Ensure numerical parameters and dates fall within specified minimum and maximum ranges, and that strings meet defined length criteria.
Escaping and encoding
Escaping and encoding user input is a crucial security measure, ensuring that special characters are properly handled to prevent vulnerabilities (such as SQL injection or cross-site scripting) by converting user input into a format that doesn't hold any functional meaning within the application.