Explore the evolving world of application delivery and security. Each episode will dive into technologies shaping the future of operations, analyze emerging trends, and discuss the impacts of innovations on the tech stack.
Lori MacVittie (00:14.993)
Welcome back to Pop Goes the Stack, where LLMs are fluent in every language except specific. And yet somehow they're running the demo. I am Lori MacVittie and I am running solo today, which is probably okay because we didn't actually have an article, so Joel's off the hook. Good luck, Joel, doing what you're doing. So I'm gonna run solo today for our topic, which is all about API security.
Well, AI API security because this is popping up as something new and a new market and there's new tools. And what we wanted to dig into is is that really necessary? Do we need a new domain just for AI API, or is it the same just with bigger threats? So to talk about that, I've got Vinnie Mazza with me. Welcome Vinnie.
Vinnie Mazza (01:13.494)
Hey, hi Lori, great to be here.
Lori MacVittie (01:15.065)
Alright. And our pre-conversation, you're gonna love this because Vinnie has some opinions, like I have opinions, and so we're gonna have a conversation. So let's start with that first question, because I think that's really the big one, is is AI API security actually a new domain, or is it just classic broken access control with a billion dollar valuation?
Vinnie Mazza (01:42.849)
I think that it's actually the collision of those two things. Right?
Lori MacVittie (01:47.855)
Oh, ooo.
Vinnie Mazza
And so what the, you know, if you would say that a volumetric change was change, we absolutely have an incredible difference in the amount of requests that are being seen.
Lori MacVittie
Yep.
Vinnie Mazza (02:01.478)
Right? And we also have a lot of organizational technical debt or you know deferred maintenance that they've done. They didn't adopt modern authentication standards. They didn't embrace zero trust. And now that agents are running around making API calls with identities or their own, not having those pieces becomes exacerbated. And now multiply it by one person can run hundreds or you know thousands of agents. And so now if your entire organization is doing that, it has completely changed the game.
Now, are we still inspecting requests? Are we still looking for known bad behaviors? You might call them mugshots, right, you know it's a known thing we've seen before. Yeah, all those things are true. And I think this is just, you know, bad hygiene catching up with some customers has created kind of a separate domain, right?
Lori MacVittie (02:56.882)
Yeah, and that's interesting when you talked about, you know, like so the APIs are, they're the same APIs. It's just that AI has kind of exposed a lot of bad habits, you know, poor practices, you know.
Vinnie Mazza (03:08.256)
We 're also seeing some new protocols on
Lori MacVittie (03:12.316)
Okay.
Vinnie Mazza
the existing API. So like MCP is a great example that's been rewritten now to be a streaming protocol, which is much more modern. I think initially it was built for local desktop work and now it's being put into every AI gateway because organizations have decided that that's the way they're gonna do it, the way they've always done it, is a centralized point of control.
Vinnie Mazza (03:34.575)
And so now you can no longer have sessions that aren't, you know, sticky or persistent is the way you'd say in NGINX land. And now you have things that need to be fully asynchronous in stream. And so that's changing it again, because now you can do more traditional, more kind of cloud native controls across the proxies. You don't have to centralize it as much because the agent sessions are no longer a one-to-one with the server whereas they were previously.
Lori MacVittie (04:03.41)
And that sounds like classic API security, right? There's one request, we're gonna check it, we're gonna do this thing, then a different request, and we're gonna... it's very one-to-one, it's very transactional. Whereas when you start streaming things, it kind of changes how you apply security because it's continuous, correct?
Vinnie Mazza (04:24.278)
It changes the amount of time you have to make a decision. Right. So
Lori MacVittie (04:28.114)
Okay.
Vinnie Mazza
if we think about our like RFCs for HTTP 1.1, right, and we we have this request and response and wait. When you switch to a stream, it's kind of bi directional. It's happening, you know, much more quickly. You have much less time to decide, right, because you're not waiting on handshakes and things like that. And so it kind of changes the math of how the clients interact and how long the security tools have to make a decision.
Vinnie Mazza (04:52.216)
So now amplify that with the number of new clients that are both malicious and you know valid internal users that are coming from inside and outside and everywhere, the volume is changing immensely. And you know, the streaming only makes that more. Right? And so now you have less time to make decisions on more traffic. So you have less sampling to decide what's good and bad. Right. And so that, so while it is the same controls that we're used to, it's gonna change the economics of how you enforce those controls.
Cause like, you know, I've seen, you know, F5 has an offering where they're using, you know, smarter agents to investigate those requests as well. And, you know, that's gonna have a better outcome because it's able to look at the request in aggregate the same way we'd historically done with teams of SOCs. Right, like entire, you know, multiple security operation centers working together to look at data and decide, you know, what's an anomaly and what's not, right?
And so the AI is kind of short circuiting that process and giving us a way to look at that sooner. So that is a little different than traditional. However, I think like the four fundamentals haven't changed, right? Like we're still looking at clients making requests, we're inspecting those requests, and we're making a decision. So...
Lori MacVittie (06:07.206)
Yeah, so from the perspective of, you know, I'm gonna implement, I need some API security because I'm doing AI stuff. So from my perspective, I still need the same kinds of tools. But behind the scenes what you're saying is that those tools have to change and be updated in order to handle streaming protocols, higher volumes, faster responses, right, more you know flexibility, I guess, you know, in terms of being able to rapidly deal with all of this coming in.
So it is deserving actually of a new category, as they might say in marketing land. Right? This is separate. They don't work the same way. That's what I'm hearing. So how, when you're doing API security now and just plain old API--just wrote it, you know, it's gonna be apps and it's clients, very transactional--so how does the API security work for that? Like behind the scenes that's kind of the baseline, right? You mentioned something in the pre-discussion
Vinnie Mazza (07:10.679)
So
Lori MacVittie
about sampling. Can you explain that?
Vinnie Mazza
Right. So, when you're configuring and some of the traditional like application firewall setups, you have two choices. You can either do a positive security model where you're saying "I know all the good things that should happen and that's the only traffic that's allowed to pass," or you do
Lori MacVittie (07:31.228)
Okay.
Vinnie Mazza
a negative security model where you're saying, "I know all the bad things and everything else is good and it can just pass."
Vinnie Mazza (07:37.783)
The problem is that no one ever knows all the bad things, but every organization I've ever worked with chooses the negative security model, which has been really interesting to watch. And then they go, "Well, I don't know why we didn't see that." I'm like, "Well, because you said everything else was good."
Lori MacVittie (07:51.915)
Ha ha ha.
Vinnie Mazza
And so AI is mutating that even further, because now you're gonna have, you know, more sophisticated attacks that are doing things humans didn't consider because AI thought about it for forty turns with an agent and came up with a solution that was novel, that does the same attack a different way.
Vinnie Mazza (08:07.436)
Right. So I think that's where, you know, traditional security was, you know, you pick one of those methods, you make some kind of policy that dictates these things, and you work with the application owner to keep that policy in sync with reality. Right? But you can't anticipate what users are going to do with their clients. You can only request. That's the whole point of HTTP, right? You're saying, "This is what we agreed to, we've negotiated this, and we're gonna speak this way." Just like TLS, just like the other tools we have, right? A lot of those haven't changed, all the fundamentals are there.
And so now, you know, what's happening is like just the sheer volume can't keep up with the rate of change because now applications are shipping faster. So how do you keep that policy in sync with reality? A lot of organizations I saw would turn it off. They would they do what they say fail open. Right, because you know, the reality is that sometimes making money is more important than being secure, which is a scary thought for an engineer like myself.
Lori MacVittie (09:03.251)
Mm-hmm.
Vinnie Mazza
So...
Lori MacVittie
Yeah. Yeah, yeah, the whole turn it off. But that's been true of security tools, especially at the application layer, forever. I mean, we've always heard from people that, well, I mean, so I remember with one of the first security, you know, regulations, right, that required a WAF, they had to go in and specify that the WAF had to be turned on because people are like, "Well, I put it in." I just,
Vinnie Mazza
Ha ha ha.
Lori MacVittie
"Oh, it has to be on and working, I see." Right? I mean, like compliance. They just went, "Yeah, we'll go around it." So
Vinnie Mazza (09:39.271)
Absolutely, we used
Lori MacVittie
people have been turning it off forever.
Vinnie Mazza
Yeah, we used to call that checkbox security. So they
Lori MacVittie (09:43.664)
Yeah. Yeah.
Vinnie Mazza
had the checkbox, they've got the thing. I had one where the customer just actually had them in a box and not even installed.
Lori MacVittie
Ha ha ha. Just...
Vinnie Mazza
So, and I was, "We have them. We're good." Yeah. So
Lori MacVittie (09:54.941)
Yeah, we bought them, we paid for them.
Vinnie Mazza
So, that was yeah,
Lori MacVittie
And it's crazy.
Vinnie Mazza
it was very surprising. Yeah.
Lori MacVittie
Yeah, it's crazy. And your description of the policies, right, and you have to, so you have to keep updating because they're static, right? I mean basically we're saying we're pattern matching. We know that what looks like this is bad, so let's watch for that. We know this is bad, so watch for that. And the problem with AI now is we don't know what's bad. Like you said, right, the AI
Vinnie Mazza (10:28.334)
Well
Lori MacVittie
could be like, Yeah, watch this, you know.
Vinnie Mazza
Well, think about it this way. So in F5 has a product called Application Security Manager, right, which F5 ASM and in ASM we used to have a thing that was called automatic policy builder. And this was AI,
Lori MacVittie (10:42.629)
Mm-hmm.
Vinnie Mazza
you know, 10, 15 years ago making changes to your policy based on traffic it had seen. But nobody would turn it on, nobody would use it because they didn't trust AI. Today that is completely flipped on its head. Everybody's like, Yes, let's do whatever the AI says because it's AI.
Vinnie Mazza (10:58.072)
So the supporting evidence that makes those decisions is still there. These boxes are still collecting that metric. That's part of the sampling that I was describing. And so, the mutability of the policy becomes really important as things are changing faster than a static world. So if I had to talk about this to a developer, I would talk about an API contract, like an
Lori MacVittie (11:21.586)
Mm-hmm.
Vinnie Mazza
open API spec or schema. And so think of ASM policy as something that you're enforcing, right?
Vinnie Mazza (11:28.306)
And so your enforcement needs to move with your application and a lot of organizations weren't doing that. So that's why we came up with tools like API Discovery. And so F5 has been trying to help customers adapt to this rate of change through various security tools in each of our data platforms. So I think it's interesting. We're trying to help reach them where they are, even for the ones who haven't done their, you know, maintenance. So
Lori MacVittie (11:53.681)
Haven't done their maintenance. I like that. That's so politic, they haven't...they've deferred maintenance. But that is, right, what Mythos kind of exposed, if you will, because a lot of
Vinnie Mazza (12:06.57)
Oh, that was
Lori MacVittie
what it's finding
Vinnie Mazza
absolutely linchpin. Beautiful, beautiful way to think about, like I think of like, you know, you look at the it was like a doomsday event if you think of everybody was counting down to the year two thousand again.
Lori MacVittie
Ha ha ha.
Vinnie Mazza
And we were running around updating our computers. Ha ha ha.
Lori MacVittie (12:23.11)
Yeah. Ha ha ha.
Vinnie Mazza
And so, you know, and then it passed and everybody was like, Whoa, well this did find a lot of really important bugs, but like this wasn't what we thought it was, right?
Vinnie Mazza (12:35.532)
And I think part of that is anytime you're selling something, you need to, you know, have a very important story to support it. So I think they did an amazing job. Both, you know, OpenAI and Anthropic have done an amazing job, you know, doing that. But it doesn't negate the real risk, because like we had novel math problems that were previously unsolved by humans that are now being solved by these things, right? And so the same thing is happening in security.
We have, like, the ability to put someone on the problem essentially 24/7 without tasking humans, which is changing the game of, you know, both how fast the API can change, which has now changed the bar of how fast you can secure it, and has now changed, you know, the way you think about the volume of requests you're gonna get, because it's not possible to look at everything today.
Lori MacVittie (13:27.986)
Why not? Why can't we? Ha ha ha.
Vinnie Mazza
Oh, I guess we could. We can have unlimited budgets.
Vinnie Mazza (13:32.984)
There are places with unlimited budgets. Like I think there's one really well known tech company that their like limiting factor is the amount of power that can go into a data center, not money. So I, you can,
Lori MacVittie (13:46.673)
Wow. Oh, to have that problem.
Vinnie Mazza
I'll let you think about who that is.
Lori MacVittie
Yeah, yeah. But I mean you're right. I mean that's, right, in the the old days of API security--so like just a couple of years ago--right, we did we sampled, right, requests in order to try and figure out is this anomalous, right, to do kind of behavioral based detections. And you would sample things and kind of decide based on that, but right now you've got so much coming in that sampling might miss these. I mean they did before, but not as frequently
Vinnie Mazza (14:22.242)
Yeah, I
Lori MacVittie
because the...right?
Vinnie Mazza (14:22.242)
Absolutely. I think that's the volumetric change that I'm referring to when I say that like, you know, so we'll do some like really bad, bad statistics real quick and like can I can hear my stats professor yelling at me
Lori MacVittie (14:36.06)
Ha ha ha.
Vinnie Mazza
right now. But let's say like we were previously again like we had a population of a million requests and we're only sampling ten thousand and now we're getting ten million requests in the same time frame and we only had resources to say sample twenty thousand.
Vinnie Mazza (14:51.788)
So how much are we missing now that we weren't before? And how much more do we need to expand what we have to catch these things? Or do we need to fundamentally change the way we're looking at the security posture? Right. And I think like, you know, I think like things like identity didn't change. Right? Like having modern authentication protocols really helps this problem because you can discard a lot of requests you don't have to then inspect. Right. And that's where things like firewalls became really useful was you're able to drop things ahead of time.
Lori MacVittie
Mmm.
Vinnie Mazza
What I saw interacting with a lot of cloud providers is they wait till Layer 7 to make decisions on some of these things. And they don't drop bad actors early. They wait until it's actually you're paying for it in your compute to make the security decisions. And that's something that I found interesting, having worked at F5 for so long, where we made the decisions as early as possible always, because we always want to drop the bad traffic outside. But the challenge is that a lot of the bad traffic could come from inside now. So that's really the shift. So...
Lori MacVittie (15:49.467)
Yeah, that's a good point. I mean, for years architecturally, leveraging security as a service made sense. Because requests are generally coming from outside. They're going to your thing. If you can stop them before they ever got to your data center or wherever you were hosting the actual app or API, well, that's brilliant. Right? That's saving you, that's saving everybody. It's lovely. But if it's coming from inside, well you're paying for it no matter what, so you better be able to detect it faster. But, you know, in all of this I'm not hearing an answer.
Vinnie Mazza (16:25.834)
Ha ha ha.
Lori MacVittie (16:26.16)
How do you do that? I mean you cannot. Like assume your statistics right number, like okay we've got you know a million requests a second how are you gonna inspect every single one of those? You can't. So how do we still manage to like up the security game and make sure that whether it's coming from inside or outside that the API is not being exploited somehow here?
Vinnie Mazza (16:50.734)
I think the traditional engineering approach to this would be to break down the problem. And so that's where the streaming and the stateless connections
Lori MacVittie
Mm-hmm, okay.
Vinnie Mazza
came in in MCP and that's why a lot of people have settled on that is the new transport over HTTP for this, which allows you to spread out the inspection across more devices. Right? It's not a centralized single proxy or gateway, it is a collection of them or a fleet of them doing this inspection, right? So...
Lori MacVittie (17:16.934)
I find it interesting that no one has proposed yet pushing the initial inspection all the way down to the client. Cause it's usually a browser and it's easy enough to, you know, basically distribute, right, force some sort of inspection beforehand, especially as all of these the "AI PCs" show up where they've got the power to be able to do that and so push it down.
Vinnie Mazza (17:39.342)
I, so one thing is you can't trust clients, you never could. That's
Lori MacVittie (17:44.984)
Oh, yeah.
Vinnie Mazza
part of being
Lori MacVittie
I forgot.
Vinnie Mazza
a web service.
Lori MacVittie
Yeah. Ha ha.
Vinnie Mazza
Number two, there are people looking into this
Lori MacVittie
Okay, all right.
Vinnie Mazza
that are building products around this.
Lori MacVittie
All right, okay.
Vinnie Mazza
I can maybe talk about that in another forum, but
Lori MacVittie
All right. Well we'll have you back in the future and we'll talk about that because that is, right, that is a logical step. It, and I understand you can't trust the browser, you can't trust the client, right, you never could. You should never trust the user. That's part of good API security, right, is never trust the user. Right? Sanitize everything because who knows what's coming in.
But being able to distribute even further the security into even if you chop it up and say, "Okay, you're gonna do this piece of the check and you're gonna do this piece of the check," is going to help make it more efficient and maybe even affordable to be able to do the kind of volumes that we need to do to keep these things secure.
Vinnie Mazza (18:41.314)
Yeah, traditionally when I refer to this, I talk about defense in depth or layers of the onion, right? And so we
Lori MacVittie (18:46.705)
Yeah.
Vinnie Mazza
we think about like what can I drop at what stage and,
Lori MacVittie (18:50.128)
Right.
Vinnie Mazza
you know, where the stage is coming in has changed with this again for insight. And that's really what's kind of made the math different. 'Cause before we were like, Okay, we have an answer for how this layered thing happens coming in and now organizations are going, "Oh no, we don't want to stop this because we're personifying agents here. So Bob's agents are
Vinnie Mazza (19:09.55)
flying out and they're looking at all this internal data and we want to make sure Bob's agents aren't sending that to an external model provider." Right? And that's a real concern because in this world where code is getting cheaper to produce, your IP becomes more important. And a lot of people are just giving it away.
Lori MacVittie (19:25.458)
Yeah, true. Very, very true. That's, so
Vinnie Mazza (19:32.463)
So I guess that's a
Lori MacVittie
basically. Yeah.
Vinnie Mazza (19:32.463)
good thing. We've landed on something interesting though, because like now
Lori MacVittie (19:48.028)
Yeah.
Vinnie Mazza
I just realized, like yes, IP and DLP were part of traditional API security but it's become paramount now, whereas before it was just an afterthought, I think, because a lot of people said,
Lori MacVittie (20:00.007)
Yeah.
Vinnie Mazza
"We'll deal with DLP later, we're just gonna stop bad requests." But now it's like the forefront of this. So it's kind of flipped traditional API security towards, you know, IP and DLP--data loss prevention, sorry.
Lori MacVittie
Yeah, yeah, yeah. We've seen a lot of that, right? The notion of data security being something that people outside of, you know, the traditional data analysts and right, you know, the data people worry about. Right, it's now coming into operations, into the network, into the security teams. They have to actually worry about data security, as it were, a lot more because of this. So and maybe that's a good thing, right?
Data is kind of like that is your gold mine and so losing it is actually a lot more costly than we might think. So,
Vinnie Mazza (20:39.714)
Yeah. Accidentally giving away your moat is a dangerous prospect, right?
Lori MacVittie (20:43.29)
Yeah. Yes. Absolutely. So if you were gonna leave the the listeners with, you know, one or two like takeaways, what should they take away from, you know, the idea that there is a need for something called AI API security? Like what do they need to know then? Going, Okay, it exists, now what?
Vinnie Mazza (21:08.396)
That's a good one. So I think
Lori MacVittie (21:09.328)
It was a gotcha.
Vinnie Mazza
Yeah, I mean that's important. We're rolling so we had to have one, right? So the
Lori MacVittie (21:15.216)
Yeah, yeah.
Vinnie Mazza (21:18.37)
I think my key takeaway is that you don't need to be afraid. It's the same tools you already know. And some of the like the patterns and the scale have changed, right? And so we have the things to stop this, we have the things to make this right, it's just have to be vigilant, the same as always. And I think never before have we had such amazing resources to help us do that.
I'm seeing code bases have documentation that historically never did in open source and other things because it's just so easy to produce now. And so what that's changing is like your ability to research and plan to address this and how to operate the tools is at a level that was never there before. Previously you had to engage specialists in consulting and this data wasn't available. It was very difficult to do these protections.
Now you can leverage the same thing that's fighting you to protect against it and which is somewhat confusing, but at the same time, don't be afraid to try some of these things. And it's important to have a safe, you know, place to test. So you definitely wanna, you know, be playing with offline models, be playing with the, you know, the local AI, because I think we're gonna see a resurgence of that as you know more focused local models get better.
And then so, you know, all these guardrails and security things that the you know frontier labs are putting out are gonna become less relevant as customers are starting to build their own. And so you're gonna have your own flavor of how to protect it, I think is what's gonna come out of that. And we're gonna need tools or application of the existing tools to address that. Does that help?
Lori MacVittie (22:56.59)
Yes. No, that was that's a great takeaway. I mean, I and the notion that organizations will be able to build or customize at least right their own tool set to protect their own unique environment is kinda exciting. It is a little scary,
Vinnie Mazza (23:12.768)
I
Lori MacVittie
like you said, but
Vinnie Mazza
I believe it's the new gold rush and that's
Lori MacVittie
Interesting. Yeah.
Vinnie Mazza
one of the reasons that my role exists at F5 now is we're investing in programmability with WebAssembly.
Lori MacVittie (23:24.37)
Mm.
Vinnie Mazza
And so you might know Joel and have some
Lori MacVittie (23:28.046)
I might. Yeah.
Vinnie Mazza
feelings about that.
Lori MacVittie
Mm-hmm. Yes.
Vinnie Mazza
So that's allowing us to address that rate of change at a rate that's never been seen before at F5. So we're able to push out this programmable logic and gates at a rate that is not months, it may be hours now.
Vinnie Mazza (23:41.602)
So it's gonna let us keep up with the change, right? And give you the ability to have incredibly complex logic in a shippable, safe, portable way. So
Lori MacVittie (23:51.741)
That is cool. And I'm glad you mentioned that 'cause that does seem to be a great takeaway that yeah, it's different. AI API security has to be a different thing because the volume, the rate of change is different, even what we're looking at in some cases, but the tools are adapting so that organizations can adapt. So you're right, don't be afraid, try things out and don't worry. It's all gonna be okay. Maybe. Well
Vinnie Mazza (24:20.716)
Yeah, take a breath. You didn't deprecate your toolbox. You just
Lori MacVittie
that's right.
Vinnie Mazza
have some new things to put in it, right?
Lori MacVittie (24:25.808)
That's right. Awesome. I love it. We'll put new things in the toolbox. That is sadly all the time we have for this episode. So you know, hey, please hit subscribe because prompt harder is not an operational strategy. It's not.