tencent cloud

Web Application Firewall

Overview

Download
Modo Foco
Tamanho da Fonte
Última atualização: 2026-08-03 16:49:34
Traduzido por IA

Feature Introduction

API Security is an API security protection capability provided by Tencent Cloud WAF. It covers stages such as API discovery, risk detection, and event handling. This capability analyzes traffic based on WAF's out-of-band traffic mirroring without affecting the normal business forwarding path. It can automatically discover API assets within your business, continuously detect security risks, and provides capabilities for handling risk events and configuring security policies.
After you enable the API security switch, the system automatically identifies and analyzes the API traffic for the domain. The initial analysis is typically completed within approximately 30 minutes, after which the API asset list and statistical data are displayed. Usually, no modifications to your business architecture are required. You can start using the feature after enabling the switch and waiting for the initial analysis to complete.

Activation Methods

1. Log in to the WAF console. In the left sidebar, choose Connection Management > Instance Management.
2. Locate the instance for which you need to enable API Security. Then, click More > API security.
3. In the activation pop-up window, select Enable API Security, purchase the business extension pack, and click Buy Now.

Note:
For details on packages and billing, see Billing Overview.

Feature Details

The API Security feature includes the following four sub-feature pages:
Feature Page
Core Capabilities
Feature Description
Security posture awareness
A data dashboard that displays API asset overview, risk profile, TOP5 statistics, and trend charts, helping users quickly grasp the API security posture.
Full lifecycle management of API assets
API assets are automatically identified based on traffic, including shadow APIs.
API paths, request methods, call volumes, and other information for each domain are displayed in a structured manner through the asset tree.
It supports adding assets to the allowlist, blocking assets, and marking their status as active/inactive.
Security event monitoring and handling
It displays security events detected by API Security, covering business anomalies, permission anomalies, account anomalies, Web attacks, and more.
It supports event classification, batch operations, and status transitions.
Fine-grained management of protection policies
Provides the enabling, configuration, and management of security policy rules, including the following types of rules:
Security Event Detection Rules (System-Built + Custom)
Sensitive Detection Rules (System-Built + Custom)
Authentication Credential Identification Rules (Custom Configuration)
Rate Limiting Rules (Custom Configuration)
Input Parameter Detection Rules (Swagger Import + Manual Addition)
Feature Scenario Identification Rules (System-Built + Custom)
API Asset Discovery Rules (Custom Configuration)
Sensitive Data Allowlist (Custom Configuration)
Invalid Asset Blocking (Custom Configuration)
Note:
The number of system-built rules is continuously updated. For the specific rule items, refer to the console page.

Use Cases

Scenario
Challenges
Recommended Capability
API asset inventory and shadow API discovery
The enterprise has a vast number of APIs but lacks effective management measures, resulting in a large number of unregistered shadow APIs being exposed on the public network.
API asset auto-discovery + feature scenario identification
Sensitive data leakage prevention
API responses may contain sensitive information such as ID card numbers, mobile phone numbers, and bank card numbers. If not desensitized, this could lead to data leakage and compliance risks.
Sensitive data identification + sensitive detection rules
Privilege escalation risk detection
API interfaces lack an authentication mechanism or have insufficient authentication, which may lead to security risks such as unauthorized access and horizontal privilege escalation.
Authentication analysis + authentication credential identification rules
API rate limiting and abuse prevention
API interfaces are maliciously crawled or scraped, leading to backend resource exhaustion and business exceptions.
Access frequency rate limiting + rate limiting rules
Security and compliance audit
Enterprises face compliance requirements such as the Multi-Level Protection Scheme (MLPS), GDPR, and industry regulations, and need to demonstrate that their API security protection measures comply with regulatory requirements.
Risk event detection + rule configuration audit





Ajuda e Suporte

Esta página foi útil?

comentários