The API Assessment Primer Introduction: Why API security matters, assessment considerations, common API vulnerabilities, takeaways,. | The API Assessment Primer Jason Haddix & Greg Patton OWASP AppSecEU | May 21, 2015 Agenda • • • • • Introduction Why API security matters Assessment considerations Common API vulnerabilities Takeaways 2 About me Greg Patton SAST Manager, HP Fortify on Demand • Manage the static analysis testing team for HP FoD • Nearly ten years of DAST experience with web & mobile apps • Attended my 1st OWASP meeting on June 7, 2007 (Houston, TX) hacker@ 3 Why API Security Matters APIs are everywhere • Mobile apps • Internet of Things (IoT) • Service Oriented Architecture (soa) • Enterprise .