What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The title describes a first-person account, but it does not identify the API, the four tests, or the fixes. Those details cannot be responsibly reconstructed from general AWS guidance. The useful way to read—or document—such a security walkthrough is to connect each verified test to its access-control assumption, observed evidence, remediation, and retest.

What a useful four-test account needs to show

For each test, report the attacker’s identity or capability, the endpoint and input involved, the access boundary that should have held, the observed response or side effect, the potential data or action at risk, and the exact fix with evidence that it worked. Without those facts, a reader cannot tell whether a test found an exploitable flaw or merely produced an unexpected response.

Keep the scope explicit: say whether testing was authorized, which environment was used, and whether real user data or production systems were in scope. Do not imply that any particular attack, endpoint, or AWS service was involved unless the account establishes it.

Classify only the attacks the account actually verifies

OWASP’s 2023 API Security Top 10 is a way to name risks, not a record of what happened in this account. Its relevant categories distinguish several different failure modes:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
  • API1:2023, Broken Object Level Authorization: a caller can access another user’s object, for example by changing an identifier, when the application does not enforce ownership or another access rule.
  • API2:2023, Broken Authentication: identity verification or token handling fails in a way that permits impersonation or otherwise undermines who the caller is.
  • API3:2023, Broken Object Property Level Authorization: a caller can read or modify object fields they should not control.
  • API4:2023, Unrestricted Resource Consumption: requests or costly operations can be abused in a way that threatens resources or availability.
  • API5:2023, Broken Function Level Authorization: a caller can invoke a function reserved for a more privileged role.

Authentication answers who is making a request; authorization answers what that identity may do. An accepted login or valid token therefore does not prove that access to a particular object, field, or function is authorized. OWASP advises: “Object level authorization checks should be considered in every function that accesses a data source using an ID from the user.” OWASP API Security Top 10 – 2023.

Separate AWS account permissions from API authorization

If the system uses Amazon API Gateway, AWS recommends least-privilege IAM permissions for API Gateway management, request logging through CloudWatch Logs or Amazon Data Firehose, CloudWatch alarms, and CloudTrail records of API Gateway actions. These controls concern different parts of the system: management-plane IAM governs who can administer AWS resources, while the API’s client authentication and application authorization govern what a request may do.

AWS describes its recommendations as general guidance, not a complete security solution: “These best practices are general guidelines and don’t represent a complete security solution.” See Security best practices in Amazon API Gateway. If the API does not use API Gateway, do not present these service-specific recommendations as facts about its architecture.

Use logs to detect and reconstruct tests

Logs can help establish what a request did and whether the system detected it, but their presence alone does not establish that an attack succeeded or failed. OWASP’s logging guidance recommends recording failed authentication, denied access, and input-validation errors; using structured detail sufficient to identify suspicious activity; protecting log integrity; and monitoring continuously. A meaningful account should distinguish what the logs show from what they cannot show—for example, whether a request was denied, whether an alert fired, and whether any downstream side effect occurred.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

See OWASP API10:2019, Insufficient Logging & Monitoring.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Where AWS WAF can help—and where it cannot

If the architecture uses API Gateway with AWS WAF, WAF rules can allow or block requests by IP address or country and inspect components such as query strings, request bodies, and HTTP methods. That can add a filtering layer, but it does not prove that an authenticated caller is entitled to another user’s object or a privileged function. Those decisions still need to be enforced by the application’s authorization logic. AWS describes WAF capabilities in its Security Overview of Amazon API Gateway; OWASP’s risk categories explain why filtering and authorization address different problems.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.