What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The title describes a first-person account, but it does not identify the API, the four tests, or the fixes. Those details cannot be responsibly reconstructed from general AWS guidance. The useful way to read—or document—such a security walkthrough is to connect each verified test to its access-control assumption, observed evidence, remediation, and retest.
What a useful four-test account needs to show
For each test, report the attacker’s identity or capability, the endpoint and input involved, the access boundary that should have held, the observed response or side effect, the potential data or action at risk, and the exact fix with evidence that it worked. Without those facts, a reader cannot tell whether a test found an exploitable flaw or merely produced an unexpected response.
Keep the scope explicit: say whether testing was authorized, which environment was used, and whether real user data or production systems were in scope. Do not imply that any particular attack, endpoint, or AWS service was involved unless the account establishes it.
Classify only the attacks the account actually verifies
OWASP’s 2023 API Security Top 10 is a way to name risks, not a record of what happened in this account. Its relevant categories distinguish several different failure modes:
#1 Best Overall
- API1:2023, Broken Object Level Authorization: a caller can access another user’s object, for example by changing an identifier, when the application does not enforce ownership or another access rule.
- API2:2023, Broken Authentication: identity verification or token handling fails in a way that permits impersonation or otherwise undermines who the caller is.
- API3:2023, Broken Object Property Level Authorization: a caller can read or modify object fields they should not control.
- API4:2023, Unrestricted Resource Consumption: requests or costly operations can be abused in a way that threatens resources or availability.
- API5:2023, Broken Function Level Authorization: a caller can invoke a function reserved for a more privileged role.
Authentication answers who is making a request; authorization answers what that identity may do. An accepted login or valid token therefore does not prove that access to a particular object, field, or function is authorized. OWASP advises: “Object level authorization checks should be considered in every function that accesses a data source using an ID from the user.” OWASP API Security Top 10 – 2023.
Separate AWS account permissions from API authorization
If the system uses Amazon API Gateway, AWS recommends least-privilege IAM permissions for API Gateway management, request logging through CloudWatch Logs or Amazon Data Firehose, CloudWatch alarms, and CloudTrail records of API Gateway actions. These controls concern different parts of the system: management-plane IAM governs who can administer AWS resources, while the API’s client authentication and application authorization govern what a request may do.
Rank #2
AWS describes its recommendations as general guidance, not a complete security solution: “These best practices are general guidelines and don’t represent a complete security solution.” See Security best practices in Amazon API Gateway. If the API does not use API Gateway, do not present these service-specific recommendations as facts about its architecture.
Use logs to detect and reconstruct tests
Logs can help establish what a request did and whether the system detected it, but their presence alone does not establish that an attack succeeded or failed. OWASP’s logging guidance recommends recording failed authentication, denied access, and input-validation errors; using structured detail sufficient to identify suspicious activity; protecting log integrity; and monitoring continuously. A meaningful account should distinguish what the logs show from what they cannot show—for example, whether a request was denied, whether an alert fired, and whether any downstream side effect occurred.
See OWASP API10:2019, Insufficient Logging & Monitoring.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Where AWS WAF can help—and where it cannot
If the architecture uses API Gateway with AWS WAF, WAF rules can allow or block requests by IP address or country and inspect components such as query strings, request bodies, and HTTP methods. That can add a filtering layer, but it does not prove that an authenticated caller is entitled to another user’s object or a privileged function. Those decisions still need to be enforced by the application’s authorization logic. AWS describes WAF capabilities in its Security Overview of Amazon API Gateway; OWASP’s risk categories explain why filtering and authorization address different problems.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

