STIGQter STIGQter: STIG Summary: Application Programming Interface (API) Security Requirements Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

The API must monitor the usage of API keys to detect any anomalies.

DISA Rule

SV-274523r1143516_rule

Vulnerability Number

V-274523

Group Title

SRG-APP-000095

Rule Version

SRG-APP-000095-API-001740

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Build or configure the API to monitor API key usage and flag anomalies:

Enable Logging: Log all API key usage, including timestamps, IP addresses, endpoints accessed, and request rates.

Define Normal Behavior: Establish a baseline for expected usage patterns (e.g., typical request rate, endpoints used, geographic regions).

Set Thresholds: Configure thresholds for detecting anomalies such as excessive requests, access to unusual resources, or use from unexpected locations.

Integrate Monitoring Tools: Use API management or SIEM tools to analyze logs and trigger alerts on anomalous activity.

Automate Alerts: Set up real-time notifications or automated actions (e.g., temporary blocking) when anomalies are detected.

Check Contents

Verify the platform provides features to monitor API key usage, including tracking requests made with each key and flagging anomalies such as unexpected request patterns, usage from unusual geographic locations, abnormal request rates, or access to unauthorized endpoints.

If API key usage is not being monitored for anomalies, this is a finding.

Vulnerability Number

V-274523

Documentable

False

Rule Version

SRG-APP-000095-API-001740

Severity Override Guidance

Verify the platform provides features to monitor API key usage, including tracking requests made with each key and flagging anomalies such as unexpected request patterns, usage from unusual geographic locations, abnormal request rates, or access to unauthorized endpoints.

If API key usage is not being monitored for anomalies, this is a finding.

Check Content Reference

M

Target Key

5703