API Security for Beginners (Paperback)
Idioma: inglés
Editorial: Independently Published, 2025
- Tapa blanda
- Nuevo

Librería: CitiRetail, Stevenage, Reino UnidoCitiRetail
Vendedor de IberLibro desde 29 de junio de 2022
Condición: Nuevo
EUR 30,89
Cantidad disponible: 1 disponible
Añadir al carritoDescripción del artículo del vendedor
Paperback. Imagine it is 3:00 AM. Your phone buzzes on the nightstand. It's a generic alert from your server. You groggily check the screen and freeze-your application's entire user database is being downloaded by an unknown IP address halfway across the world. Your heart races. You panic. Do you shut down the server? Do you unplug the database? Do you even know how they got in?Now, imagine a different reality. The alert buzzes, but you don't panic. You calmly glance at your phone and smile. You know exactly what is happening because you built the monitoring system. You know the attack has already failed because you implemented Rate Limiting and strict Authentication weeks ago. You verify the logs, see the satisfying wall of "403 Forbidden" blocks, and go right back to sleep.This book is the difference between those two realities. It transforms security from a terrifying unknown into a manageable engineering problem that you can solve.What's InsideThis guide takes you through the entire lifecycle of API security, from the first line of code to the final deployment.The Attack Surface: Understand the structural differences between REST, GraphQL, and gRPC and why they break traditional firewalls.The Enemy: A deep dive into the OWASP API Top 10, dissecting critical vulnerabilities like BOLA (Broken Object Level Authorization) and Mass Assignment with real-world examples.The Defense: Master modern authentication using JWTs (JSON Web Tokens), OAuth 2.0, and OpenID Connect. Learn to implement Role-Based Access Control (RBAC) to ensure users stay in their lanes.The Fortress: Encrypt your data with TLS, sanitize your inputs to prevent Injection Attacks, and protect user privacy with Data Masking.The Offensive: Learn to hack your own API before the bad guys do. We cover SAST, DAST, and how to conduct a manual Penetration Test using tools like Postman and OWASP ZAP.The Lifecycle: Strategies for Secure Logging, Real-Time Monitoring, and how to safely kill "Zombie APIs" before they kill your business.Who It's Meant ForJunior to Mid-Level Developers who can build an API but aren't sure if it's safe to deploy.DevOps Engineers looking to integrate security scanning into their CI/CD pipelines.Product Managers who need to understand the technical risks involved in their feature requests.Anyone who wants to move beyond "copy-pasting code" and understand the "why" behind application security.Security is not a feature you add at the end; it is a mindset you build from the start. Do not wait for a data breach to teach you these lessons the hard way. Take control of your infrastructure today.Grab your copy now and start building APIs that can survive the hostile internet. This item is printed on demand. Shipping may be from our UK warehouse or from our Australian or US warehouses, depending on stock availability.…
N° de ref. del artículo 9798278451662
- Título
- API Security for Beginners (Paperback)
- Autor
- Ronald J. Randall
- Editorial
- Independently Published
- Año de publicación
- 2025
- Estado
- new
- Encuadernación
- Paperback
- Idioma
- inglés
- ISBN 13
- 9798278451662
Imagine it is 3:00 AM. Your phone buzzes on the nightstand. It’s a generic alert from your server. You groggily check the screen and freeze—your application’s entire user database is being downloaded by an unknown IP address halfway across the world. Your heart races. You panic. Do you shut down the server? Do you unplug the database? Do you even know how they got in?
Now, imagine a different reality. The alert buzzes, but you don't panic. You calmly glance at your phone and smile. You know exactly what is happening because you built the monitoring system. You know the attack has already failed because you implemented Rate Limiting and strict Authentication weeks ago. You verify the logs, see the satisfying wall of "403 Forbidden" blocks, and go right back to sleep.
This book is the difference between those two realities. It transforms security from a terrifying unknown into a manageable engineering problem that you can solve.
What's InsideThis guide takes you through the entire lifecycle of API security, from the first line of code to the final deployment.
- The Attack Surface: Understand the structural differences between REST, GraphQL, and gRPC and why they break traditional firewalls.
- The Enemy: A deep dive into the OWASP API Top 10, dissecting critical vulnerabilities like BOLA (Broken Object Level Authorization) and Mass Assignment with real-world examples.
- The Defense: Master modern authentication using JWTs (JSON Web Tokens), OAuth 2.0, and OpenID Connect. Learn to implement Role-Based Access Control (RBAC) to ensure users stay in their lanes.
- The Fortress: Encrypt your data with TLS, sanitize your inputs to prevent Injection Attacks, and protect user privacy with Data Masking.
- The Offensive: Learn to hack your own API before the bad guys do. We cover SAST, DAST, and how to conduct a manual Penetration Test using tools like Postman and OWASP ZAP.
- The Lifecycle: Strategies for Secure Logging, Real-Time Monitoring, and how to safely kill "Zombie APIs" before they kill your business.
- Junior to Mid-Level Developers who can build an API but aren't sure if it's safe to deploy.
- DevOps Engineers looking to integrate security scanning into their CI/CD pipelines.
- Product Managers who need to understand the technical risks involved in their feature requests.
- Anyone who wants to move beyond "copy-pasting code" and understand the "why" behind application security.
Security is not a feature you add at the end; it is a mindset you build from the start. Do not wait for a data breach to teach you these lessons the hard way. Take control of your infrastructure today.
Grab your copy now and start building APIs that can survive the hostile internet.
“Sinopsis” puede pertenecer a otra edición de este título.
CitiRetail
Stevenage, Reino Unido
Vendedor de IberLibro desde 29 de junio de 2022
Tarifas de envío de Reino Unido a Estados Unidos de America
| Artículo | De 7 a 14 días hábiles | De 7 a 60 días hábiles |
|---|---|---|
| Primer artículo | EUR 43,54 | EUR 43,54 |
Métodos de pago
Descripción de la tienda
Online business
Información empresarial del vendedor
ABC BOOKS LIMITED
10 John Street
London, Reino Unido WC1N 2EB
Condiciones de venta
Orders can be returned within 30 days of receipt.
Derecho al desistimiento
Si es un consumidor, puede rescindir el contrato de acuerdo con lo siguiente. Por consumidor se entiende cualquier persona física que actúe con fines ajenos a su actividad comercial, empresarial, oficio o profesión.
Información sobre el derecho de desistimiento
Derecho legal de desistimiento
Tiene derecho a rescindir este contrato en un plazo de 14 días sin dar ningún motivo.
El periodo de desistimiento vencerá a los 14 días desde que usted, o un tercero que no sea el transportista e indicado por usted, adquiera la posesión física del último bien o del último lote o pieza.
Para ejercer el derecho de desistimiento, complete de forma electrónica y envíe una declaración clara en nuestro sitio web, desde "Mis compras" en "Mi cuenta". Le enviaremos sin demora un acuse de recibo de dicho desistimiento a través de un soporte duradero (por ejemplo, por correo electrónico).
Para cumplir con el plazo de desistimiento, basta con que envíe su comunicación relativa al ejercicio del derecho de desistimiento antes de que venza el periodo de desistimiento.
Efectos del desistimiento
Si rescinde este contrato, le reembolsaremos todos los pagos que hayamos recibido de usted, incluidos los gastos de envío (excepto los gastos adicionales que surjan si elige un tipo de envío que no sea el tipo de envío estándar más económico que ofrecemos).
Podemos hacer una deducción del reembolso por la pérdida de valor de cualquier bien suministrado, si la pérdida es el resultado de una manipulación innecesaria por su parte.
Efectuaremos el reembolso sin demoras indebidas y, a más tardar, 14 días después de que se nos informe de su decisión de rescindir este contrato.
Efectuaremos el reembolso utilizando el mismo medio de pago que utilizó para la transacción inicial, a menos que haya acordado expresamente lo contrario; en cualquier caso, no incurrirá en ningún cargo como resultado de dicho reembolso.
Podremos retener el reembolso hasta que hayamos recibido los bienes o hasta que nos haya presentado una prueba de que los ha devuelto, lo que ocurra primero.
Deberá devolver los bienes o entregarlos a CitiRetail, Stevenage, United Kingdom, sin demoras indebidas y, en cualquier caso, en un plazo máximo de 14 días a partir del día en que nos comunique su desistimiento del presente contrato. El plazo se cumple si devuelve la mercancía antes de que venza el periodo de 14 días. Tendrá que asumir los gastos directos de devolución de los bienes. Usted solo es responsable de la disminución del valor de los bienes como resultado de una manipulación distinta a la necesaria para establecer la naturaleza, las características y el funcionamiento de los bienes.
Excepciones al derecho de desistimiento
El derecho de desistimiento no se aplica a lo siguiente:
- La entrega de periódicos, diarios o revistas, con la excepción de los contratos de suscripción; y
- El suministro de contenido digital que no se proporcione en un soporte tangible (por ejemplo, en un CD o DVD) si, al hacer el pedido, aceptó que podíamos empezar a entregarlo y que no podría desistir una vez iniciada la entrega.
Condiciones de envío
Please note that titles are dispatched from our US, Canadian or Australian warehouses. Delivery times specified in shipping terms. Orders ship within 2 business days. Delivery to your door then takes 7-14 days.