Securing HTTP-based APIs
Page 6 of 8
5. DoS attack mitigation
A common attack against an API will be to exhaust the resources available to the API, which can lead to a DoS or an increase in cost of hosting an API. Consider throttling or rate-limiting the use of an API. 'Throttling' refers to applying a quota on how often/how fast an API can be called. This is often measured in how many requests can be made per second, and should allow for spikes in use by legitimate consumers. When APIs lack rate limiting and throttling, they become vulnerable to excessive requests that can overwhelm servers, leading to denial of service (DoS) attacks or resource exhaustion.
It is good practice to allow for a spike in usage as there are times that a consumer of the API may need to make more legitimate requests. You should also keep logs on the number of times a consumer will try to access an API so you can analyse if there is a legitimate spike in traffic, or if you’re being subjected to a potential DoS attack. For more information on how to understand and mitigate DoS attacks, please refer to the NCSC’s Denial of Service (DoS) guidance.