This article addresses the pressing issue of securing application programming interfaces (APIs) in cloud environments within the broader context of software supply chain protection. Given the widespread adoption of microservice architectures and open REST/GraphQL APIs, the need to defend APIs against attacks has become critically important. The paper presents a formalization of the software supply chain model, which serves as the basis for analyzing potential attack vectors at each stage of the chain — from the compromise of repositories, dependencies, and CI/CD servers to artifact storage and deployment environments. Special attention is given to two key security mechanisms: the Web Application Firewall (WAF) and the API Gateway. A comparative analysis is provided covering their functionality, request handling approaches, security levels, logging methods, and integration into cloud infrastructures. The study identifies that WAFs detect and block HTTP-level attacks — such as SQL injections, XSS, and CSRF — based on signatures or behavioral rules, while API Gateways act as intermediaries managing request routing, authentication, authorization, access policies, and API call control.
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً