StackHawk and Shift-Left API Security with Scott Gerlach
Mar 6, 2025
auto_awesome
Scott Gerlach, Co-Founder and Chief Security Officer at StackHawk, shares insights on the critical role of APIs in modern software and their exposure to security threats. He discusses the importance of proactive security measures in software development, particularly around API vulnerabilities. The conversation touches on the evolving landscape of API security influenced by generative AI and automation. Gerlach also highlights the unique challenges faced by the financial sector regarding compliance and security, making a compelling case for integrating security throughout the development process.
API security is critical as the openness of APIs makes them vulnerable to threats, necessitating proactive vulnerability identification before deployment.
StackHawk's innovative testing solutions combine dynamic application security with source code context to enhance API vulnerability management and increase developer awareness.
Deep dives
The Importance of API Security
APIs play a crucial role in modern software systems, facilitating communication between various services and applications. However, their inherent openness also renders them susceptible to security threats, making API security a top priority for software development teams. Organizations need to be proactive about identifying and addressing vulnerabilities before they reach production, as reactive approaches can lead to significant risks and incidents. The conversation emphasizes the importance of integrating security practices into the development lifecycle to mitigate these risks effectively.
StackHawk's Unique Approach to API Testing
StackHawk combines Dynamic Application Security Testing (DAST) with contextual awareness of source code, providing a comprehensive solution for identifying vulnerabilities in APIs. By connecting to a code repository, StackHawk can discover APIs and assign priority based on their discoverability and exploitability. This proactive approach allows developers to address vulnerabilities swiftly, reducing the likelihood of security issues arising post-deployment. The emphasis on real-time testing within a development environment marks a significant shift from traditional security testing methods.
Navigating API Sprawl and Complexity
The rise of automated coding tools and the rapid development of APIs have led to a phenomenon known as API sprawl, complicating security efforts. As APIs become increasingly prevalent, organizations must manage the complexity of numerous endpoints, many of which may be unused or under-monitored. StackHawk aims to simplify API discovery and management by enabling organizations to test code at its smallest functional levels, promoting a better understanding of potential vulnerabilities. This method helps teams keep pace with the exponential growth of APIs while maintaining a focus on security.
The Future of Security in Software Development
The integration of AI and machine learning into development practices is reshaping how security is approached within software engineering. As LLMs assist with code generation, there is a risk that developers may overlook vulnerabilities introduced by automated tools. StackHawk recognizes the need for continuous testing in a rapidly evolving development landscape, offering capabilities to simulate real-world attacks while ensuring business logic is respected. The dialogue reflects on the potential for LLMs to enhance security practices as they evolve, while highlighting the ongoing necessity for robust testing mechanisms.
APIs are a fundamental part of modern software systems and enable communication between services, applications, and third-party integrations. However, their openness and accessibility also make them a prime target for security threats, and this makes APIs a growing focus on software teams.
StackHawk is a company that scans and monitors source code to obtain the full scope of an organization’s APIs and applications, and runs tests to identify vulnerabilities and address them pre-production.
Scott Gerlach is the Co-Founder and Chief Security Officer at StackHawk and previously worked at SendGrid and GoDaddy. He has an extensive background running security operations and engineering and, in this episode, he joins the show to talk about the challenges around API security and leading-edge strategies to address them.
Full Disclosure: This episode is sponsored by 10kMedia (StackHawk).
Gregor Vand is a security-focused technologist, and is the founder and CTO of Mailpass. Previously, Gregor was a CTO across cybersecurity, cyber insurance and general software engineering companies. He has been based in Asia Pacific for almost a decade and can be found via his profile at vand.hk.