Securing HTTP-based APIs
Page 7 of 8
6. Logging and monitoring
On this page
Logging and monitoring, while closely related and often used together, serve different purposes. Logging is retrospective, providing a comprehensive audit trail that can be used for troubleshooting, forensic analysis, compliance audits, and incident response. It focuses on storing information for later review and analysis. Monitoring, on the other hand, involves the continuous, real-time observation and analysis of system behaviour, performance metrics, and security indicators.
Best practices for logging and monitoring focus on detecting, investigating and responding to potential threats while maintaining compliance and performance. If you are not sure what you should be logging, please refer to the following NCSC guidance which explains what data to collect for security purposes and when to collect it.
Logging
Logging is the systematic recording of events, actions, and transactions within a system. These logs serve as a chronological record, documenting user activities, system changes and data access, enabling comprehensive visibility into the API’s operational landscape. In API security, logging serves as an important component for maintaining visibility into the operations and interactions within an API ecosystem.
Log security events
Ensure logs capture important security-related events, including authentication and authorisation activities such as login attempts, permission changes, failed requests, errors and sensitive operations like password changes, account modifications, and privilege escalations.
Implement centralised logging
If possible, implement a centralised logging system to aggregate and analyse logs, ensuring data from multiple services and microservices are collected in one place.
Record access, error and transaction logs
Track access logs, error logs and transaction data to monitor API activity and ensure security. Record details of each API call including the timestamp, source IP, user identity and accessed endpoints. This helps identify unauthorised access, track user interactions, and detect unusual transaction patterns that could indicate potential security threats or fraudulent activity.
Protect sensitive data in logs
Sensitive data such as passwords, API keys, access tokens, and personally identifiable information (PII) should never be logged. Instead, use data redaction or masking to protect confidential information, and ensure logs are encrypted both at rest and in transit.
Monitoring
Monitoring systems track key metrics such as API response times, uptime, resource utilisation, and security events. They detect anomalies, generate alerts, and notify administrators or security teams when predefined thresholds are exceeded or suspicious activities are identified.
Monitoring is proactive and preventive, aiming to identify and address issues as they occur, ensuring the ongoing health and security of the API infrastructure. It plays a crucial role in maintaining the integrity and availability of APIs, as well as in detecting and mitigating security threats.
Enable real-time monitoring and alerts
Use SIEM (Security Information and Event Management) tools to monitor logs, detect threats, and enable anomaly detection. Set up alerts for suspicious activity, such as multiple failed login attempts (indicating a potential brute-force attack) or spikes in API traffic (which could signal a DoS attack), sudden log stoppages (which may indicate tampering or an attack in progress) or unusual/large data transfers (which could suggest data exfiltration). Ensuring continuous log integrity and monitoring data movement helps detect and mitigate security threats before they escalate.
Endpoint performance tracking
Implement endpoint performance tracking, which focuses on monitoring the availability and performance of API endpoints. It tracks response times, error rates and availability to ensure they are functioning as expected and detects any issues that may affect API usability or reliability.