Website Security & Threat Management
Protecting your APIs from abuse and data exfiltration

Protecting your APIs from abuse and data exfiltration

3/24/2021 · Daniele Molteni

What this post added

This post introduces and expands upon Cloudflare's API Shield product, adding four key features to enhance API security and prevent data exfiltration: Schema Validation (now generally available for Enterprise customers), Data Loss Prevention (DLP) in beta, a managed 'Cloudflare Open Proxies' IP List, and enhanced client certificate lifecycle management for revocation. Schema Validation uses OpenAPI v3 schemas to enforce a positive security model, logging or blocking non-compliant requests. DLP identifies sensitive data in egress traffic, with initial logging capabilities and plans for obfuscation and blocking. The managed IP List leverages Cloudflare's threat intelligence to block traffic from open proxies. Enhanced certificate management provides a code-free solution for revoking and restoring client certificates.

Read the original post ↗