The recently published “OWASP API security top 10” report analyzes the anti-patterns that lead to vulnerabilities and security risks in APIs. In this 10 part series, we introduce these API anti-patterns. Every API professional should know about these anti-patterns.

Lack of Resources & Rate Limiting from the OWASP API security paper

API security anti-pattern for Lack of Resources & Rate Limiting

Sometimes APIs are published without enforcing limitations on the rate of access per user or per client/app. Such APIs may have poor performance and are susceptible to Denial of Service (DoS) attacks and brute-force attacks on the authentication.

