Selecting the correct protections for your APIs
We have covered a number of different shield-right technologies in this chapter, and your ultimate selection will vary according to your budget, technical maturity, skill level, and risk threshold. As a recap, Table 11.1 shows the technologies’ pros and cons.
Solution Type |
Pros |
Cons |
WAFs |
Mature and widely available technology, well understood by support teams. |
Prone to difficulty in configuring, leading to both high false positives and false negatives. |
WAAPs |
Promises high accuracy and specificity for API traffic. |
Nascent technology with few robust implementations in the marketplace. |
API gateways/management |
Widely available... |