Imperva has published the State of API Security in 2024 Report, which highlights how APIs and their increased usage are significantly changing the threat landscape. In 2023, the number of API-targeted attacks rose significantly.
Attacks targeting the business logic of APIs constituted 27% of attacks in 2023, a growth of 10% since the previous year. Account Takeover (ATO) attacks targeting APIs also increased from 35% in 2022 to 46% in 2023.
APIs play such a pivotal role in application modernization that API-related traffic is outgrowing normal web traffic. According to the report, API traffic constituted over 71% of web traffic last year. There are many benefits of APIs – facilitating seamless connectivity, enhancing online experiences, and driving innovation – but their widespread adoption is presenting organizations with a whole new range of security challenges that they’re not always equipped to deal with, says the report.
High volumes of non-human automated traffic are linked to a rise in automated attacks on APIs and this requires robust security measures to defend against attacks by bad bots and other automated attacks, such as DDoS attacks and account takeover (ATO). 46% of all Account Takeover attacks targeted API endpoints. Attackers are becoming more savvy in their strategies too, with 28% of all DDoS attacks on APIs targeting financial services organizations, the top targeted industry for this type of attack.
The report recognizes an urgent need for organizations to have visibility into their API ecosystems to enable meticulous identification of every API. API Discovery emerges as a crucial initial step in establishing a robust API security posture. Leveraging advanced techniques and machine learning, the Imperva analysis has uncovered an average of 613 APIs per organization, highlighting potential risks such as deprecated endpoints and Broken Object Level Authorization (BOLA), recognized as one of the OWASP Top 10 API Security Risks in 2023.
Automated attacks and business logic abuse
Automated attacks constitute a significant threat to APIs due to their fundamental makeup which is, by design, oriented towards automation and agnostic to human intervention. Attackers are increasingly leveraging automated attacks, or bad bots, to target API business logic or the core functionality of the API. By mimicking regular automated API traffic, attacks go undetected, enabling threat actors to carry out their malicious activities uninterrupted. In 2023 27% of all API attacks targeted business logic.






