Salt Security API Protection Platform Updated
October 20, 2021

Salt Security announced new capabilities in its next-generation Salt Security API Protection Platform to secure GraphQL APIs.

This update will enable users of GraphQL, an open-source query language used to build APIs, to leverage Salt Security to discover APIs, mitigate data exposure, stop attacks, and eliminate vulnerabilities at their source.

As a purpose-built API security tool that can protect GraphQL APIs across their full life cycle, the Salt Security platform delivers critical capabilities the industry needs now. APIs built using GraphQL are inherently difficult to secure because of their unique structure and high level of flexibility. Predictably, malicious actors have been quick to develop attack techniques that leverage GraphQL capabilities such as nested queries and query batching to run DoS attacks and to take advantage of the complex access control structure in GraphQL to uncover and exploit critical vulnerabilities.

"IT practitioners assume that GraphQL is harder to attack than other API technologies because they are relatively novel, but in reality, these APIs are just as attackable. In fact, the flexibility of GraphQL can easily lead to misconfigurations that accidentally expose valuable data," said Elad Koren, CPO, Salt Security. "Although attacks on GraphQL are not as common as on more widely used API formats, our priority here at Salt is to ensure that all API ecosystems are secure at all times. We're seeing GraphQL used by our customers with increasing frequency, so we took the initiative to invest significant development efforts in building the unique protections needed to support the growing community of GraphQL users."

GraphQL has been quickly embraced by the developer community for its ability to efficiently exchange information. However, its call and response formats also present unique risks, and users should expect attacks against GraphQL APIs to become increasingly frequent. As a result, the ability to automatically discover and secure GraphQL-based APIs offered by Salt Security will be critical for protecting digital-first business operations that rely on the open-source query language.

Utilizing its patented AI- and ML-based Big Data engine, the Salt Security platform baselines legitimate system behavior to effectively identify attackers in real time, stopping these bad actors while they're still performing reconnaissance and using their probing activities like penetration testers to gain insights for hardening APIs. The Salt platform's new capabilities for securing GraphQL parse the complex structure of each query to identify unique object entities, building a complete inventory of GraphQL APIs and creating the baseline for identifying and stopping attacks. The Salt Security API Protection Platform integrates with DevOps tools such as Jira and Slack to ensure that remediation details are routed to the right development team and can help track tickets to ensure remediation fixes are implemented and business risk eliminated. It also ties into SIEM platforms such as Splunk and Sumo Logic to enable incident response for SecOps teams.

Share this

Industry News

November 21, 2024

Red Hat announced the general availability of Red Hat Enterprise Linux 9.5, the latest version of the enterprise Linux platform.

November 21, 2024

Securiti announced a new solution - Security for AI Copilots in SaaS apps.

November 20, 2024

Spectro Cloud completed a $75 million Series C funding round led by Growth Equity at Goldman Sachs Alternatives with participation from existing Spectro Cloud investors.

November 20, 2024

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, has announced significant momentum around cloud native training and certifications with the addition of three new project-centric certifications and a series of new Platform Engineering-specific certifications:

November 20, 2024

Red Hat announced the latest version of Red Hat OpenShift AI, its artificial intelligence (AI) and machine learning (ML) platform built on Red Hat OpenShift that enables enterprises to create and deliver AI-enabled applications at scale across the hybrid cloud.

November 20, 2024

Salesforce announced agentic lifecycle management tools to automate Agentforce testing, prototype agents in secure Sandbox environments, and transparently manage usage at scale.

November 19, 2024

OpenText™ unveiled Cloud Editions (CE) 24.4, presenting a suite of transformative advancements in Business Cloud, AI, and Technology to empower the future of AI-driven knowledge work.

November 19, 2024

Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade developer portal based on the Backstage project.

November 19, 2024

Pegasystems announced the availability of new AI-driven legacy discovery capabilities in Pega GenAI Blueprint™ to accelerate the daunting task of modernizing legacy systems that hold organizations back.

November 19, 2024

Tricentis launched enhanced cloud capabilities for its flagship solution, Tricentis Tosca, bringing enterprise-ready end-to-end test automation to the cloud.

November 19, 2024

Rafay Systems announced new platform advancements that help enterprises and GPU cloud providers deliver developer-friendly consumption workflows for GPU infrastructure.

November 19, 2024

Apiiro introduced Code-to-Runtime, a new capability using Apiiro’s deep code analysis (DCA) technology to map software architecture and trace all types of software components including APIs, open source software (OSS), and containers to code owners while enriching it with business impact.

November 19, 2024

Zesty announced the launch of Kompass, its automated Kubernetes optimization platform.

November 18, 2024

MacStadium announced the launch of Orka Engine, the latest addition to its Orka product line.