What Developers Need to Know About Business Logic Attacks

What Developers Need to Know About Business Logic Attacks

In this episode of The New Stack Makers, Peter Klimek, director of technology in the Office of the CTO at Imperva, discusses the vulnerability of business logic in a distributed, cloud-native environment. Business logic refers to the rules and processes that govern how applications function and how users interact with them and other systems. Klimek highlights the increasing attacks on APIs that exploit business logic vulnerabilities, with 17% of attacks on APIs in 2022 coming from malicious bots abusing business logic.

The attacks on business logic take various forms, including credential stuffing attacks, carding (testing stolen credit cards), and newer forms like influence fraud, where algorithms are manipulated to deceive platforms and users. Klimek emphasizes that protecting business logic requires a cross-functional approach involving developers, operations engineers, security, and fraud teams.

To enhance business logic security, Klimek recommends conducting a threat modeling exercise within the organization, which helps identify potential risk vectors. Additionally, he suggests referring to the Open Web Application Security Project (OWASP) website's list of automated threats as a checklist during the exercise.

Ultimately, safeguarding business logic is crucial in securing cloud-native environments, and collaboration among various teams is essential to effectively mitigate potential threats and attacks.

More from The New Stack, Imperva, and Peter Klimek:

Why Your APIs Aren’t Safe — and What to Do about It

Zero-Day Vulnerabilities Can Teach Us About Supply-Chain Security

GraphQL APIs: Greater Flexibility Breeds New Security Woes

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(300)

Dynatrace's $915M Arize deal bets AI agents are just another app to monitor

Dynatrace's $915M Arize deal bets AI agents are just another app to monitor

Dynatrace completed its $915 million acquisition of Arize on Oct. 1, combining Dynatrace’s application and infrastructure monitoring with Arize’s AI agent tracing and evaluation capabilities. The deal...

5 Okt 20min

Bit Cloud’s next chapter starts after the AI builds your app

Bit Cloud’s next chapter starts after the AI builds your app

For many developers, turning an AI-generated prototype into maintainable software requires more than generating code—it requires infrastructure, collaboration, testing and review. In this episode of T...

1 Okt 31min

CloudBees just committed to an AI-first pivot. Here's why it matters for enterprise DevOps teams

CloudBees just committed to an AI-first pivot. Here's why it matters for enterprise DevOps teams

CloudBees CEO Mo Plassnig is leading the CI/CD company through a major transformation as generative AI reshapes software development. Returning to CloudBees eight years after joining through its acqui...

30 Sep 23min

A third option is emerging in the fight over AI and your data

A third option is emerging in the fight over AI and your data

The AI industry has faced a growing enterprise dilemma: companies want access to powerful proprietary AI models without risking sensitive data or intellectual property, while AI labs want to protect t...

23 Sep 30min

Drowning in AI pull requests: Harness's field CTO on code review and a Git repo built for agents

Drowning in AI pull requests: Harness's field CTO on code review and a Git repo built for agents

Harness Field CTO Martin Reynolds joins The New Stack to talk about what happens after coding agents start opening pull requests faster than anyone can review them. He explains how he first saw the bo...

7 Sep 26min

How to find failures without drowning in tracing data

How to find failures without drowning in tracing data

Traces provide a detailed view of a request’s journey through data, microservices and applications, helping SREs pinpoint where failures occur and resolve issues faster. But while tracing can reduce d...

3 Sep 31min

Why CPUs still matter in the age of AI agents

Why CPUs still matter in the age of AI agents

As AI evolves from conversational chatbots to autonomous agents, CPUs are becoming an increasingly important part of the infrastructure equation. In this episode, The New Stack speaks with Bhumik Pate...

11 Aug 26min

Why Doist Says Less AI Can Deliver More

Why Doist Says Less AI Can Deliver More

Doist CTO Gonçalo Silva says AI is reshaping software development, but success depends on restraint rather than rapid feature expansion. Instead of chasing every AI capability, Doist prioritizes “subt...

31 Jul 35min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
forklart
popradet
fotballpodden-2
stopp-verden
det-store-bildet
dine-penger-pengeradet
rss-espen-lee-usensurert
nokon-ma-ga
rss-gukild-johaug
hanna-de-heldige
aftenbla-bla
rss-ness
frokostshowet-pa-p5
bt-dokumentar-2
e24-podden
rss-penger-polser-og-politikk
ta-dokumentar