SV-274523r1143516_rule
V-274523
SRG-APP-000095
SRG-APP-000095-API-001740
CAT II
10
Build or configure the API to monitor API key usage and flag anomalies:
Enable Logging: Log all API key usage, including timestamps, IP addresses, endpoints accessed, and request rates.
Define Normal Behavior: Establish a baseline for expected usage patterns (e.g., typical request rate, endpoints used, geographic regions).
Set Thresholds: Configure thresholds for detecting anomalies such as excessive requests, access to unusual resources, or use from unexpected locations.
Integrate Monitoring Tools: Use API management or SIEM tools to analyze logs and trigger alerts on anomalous activity.
Automate Alerts: Set up real-time notifications or automated actions (e.g., temporary blocking) when anomalies are detected.
Verify the platform provides features to monitor API key usage, including tracking requests made with each key and flagging anomalies such as unexpected request patterns, usage from unusual geographic locations, abnormal request rates, or access to unauthorized endpoints.
If API key usage is not being monitored for anomalies, this is a finding.
V-274523
False
SRG-APP-000095-API-001740
Verify the platform provides features to monitor API key usage, including tracking requests made with each key and flagging anomalies such as unexpected request patterns, usage from unusual geographic locations, abnormal request rates, or access to unauthorized endpoints.
If API key usage is not being monitored for anomalies, this is a finding.
M
5703