惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
Jina AI
Jina AI
雷峰网
雷峰网
博客园_首页
WordPress大学
WordPress大学
博客园 - 司徒正美
爱范儿
爱范儿
博客园 - 聂微东
IT之家
IT之家
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Tailwind CSS Blog
博客园 - Franky
V
V2EX
GbyAI
GbyAI
阮一峰的网络日志
阮一峰的网络日志

A10 Networks

How to Secure AI Applications From Modern Threats? | A10 Networks How to Secure AI Applications From Modern Threats? | A10 Networks A10 Thunder 3360S ADC: 150 Gbps for AI & Enterprise | A10 Networks AI Security Is an Architecture Problem | A10 Networks What Is an AI Gateway? The AI Control Plane | A10 Networks AI in Financial Services: Why Leadership Is the Risk OWASP Now Has Two AI Top 10s: What Changed? OWASP Now Has Two AI Top 10s: What Changed? TrojAI by A10 Networks AI Security Platform TrojAI Defend for MCP by A10 Networks TrojAI Detect by A10 Networks TrojAI Defend by A10 Networks Secure, High-Performance Networking Solutions | A10 Battling Bots, Fraud & AI Threats Summit | Retail IT & Cybersecurity What Is Healthcare Data Compliance? | A10 Networks Interop Best of Show Runner's Up - People's Choice | A10 Networks Interop Best of Show Runner's Up - Security for AI | A10 Networks What Is FIX Protocol Trading? | A10 Networks A10 Joins OpenAI's Trusted Access for Cyber Flexible Licensing for Multiple Clouds | A10 Networks A10 Acquires TrojAI to Advance Enterprise AI Security HFT Infrastructure: High Frequency Trading Explained | A10 Networks A10 Networks Acquires TrojAI Inc., Expanding AI Roadmap | A10 Networks What Is Low-latency Trading? | A10 Networks Multi-Vector DDoS: 11 Amplification Vectors | A10 Healthcare Cloud Compliance: HIPAA & GDPR Guide | A10 LLM Unbounded Consumption & DoS Attacks | OWASP LLM10 LLM Hallucination & Misinformation | OWASP LLM09:2025 Healthcare Network Protection for Hospitals & Clinics RAG Security: Vector & Embedding Weaknesses | OWASP LLM08
A10’s 5 Key Takeaways on Application & API Security Trends
Gary Wang · 2026-05-14 · via A10 Networks

We’ve been making a FUS out of WAPP for the past few months, and it’s reassuring to see analysts – albeit with different acronyms – speaking the same language. A recent report on application and API security makes one thing clear about the application security space: it’s not about protecting against vectors of attacks. It’s about implementing an integrated, intelligent, and seamless approach to protecting applications against attacks and attackers.

  • APIs are now the primary attack surface, making API security central to modern application security strategies
  • Platform-based security is replacing siloed tools, consolidating WAF, API protection, bot defense, and L7 DDoS into unified solutions
  • Automation and AI-driven detection are reducing operational overhead while improving accuracy and response speed
  • Effective security platforms prioritize real-world, battle-tested machine learning over theoretical or opaque detection models
  • The future of application security is converging around deeper API controls and emerging AI application protection requirements

Best Practices for Application and API Security

Many of the capabilities analysts are prioritizing are already core to ThreatX’s approach. Here are the five biggest takeaways from recent reports on application and API security trends, and how they map to ThreatX.

  1. APIs are the New Crown Jewel

    Takeaway: APIs now account for over 80 percent of web traffic and have become attackers’ prime target.

    ThreatX Perspective: ThreatX was designed for this reality. Hacker Mind doesn’t differentiate between “web” and “API” traffic. It sits inline and analyzes attacks and attackers from a more holistic perspective – protecting the true target: the application ecosystem. ThreatX isn’t just a WAF with some API functionality. It’s a Web Application Protection Platform (WAPP), built from inside-out, protecting applications against attacks and attackers, including those that come from the API vector.

  2. This (Platform-based Security) is the Way

    Takeaway: Organizations are replacing siloed security tools with unified platforms that combine WAF functionality, API security, bot protection, and L7 DDoS defense.

    ThreatX Perspective: This trend plays directly into A10’s strategy. ThreatX is a Web Application Protection Platform. Its approach is to holistically protect applications against attacks and attackers, irrespective of the attack’s/attacker’s vector of choice.

  3. FSD (Fully Self-driving) Security

    Takeaway: FSD from Tesla is a hot topic right now. How about FSD security? Large enterprises around the world operate an average of 43 different security products. Leading solutions don’t just provide strong security, they minimize operational overhead through automation, consolidation, and ease of use/deployment.

    ThreatX Perspective: This is where ThreatX stands out.

    • Auto-blocking with near-zero false positives
    • Minimal tuning required
    • Dedicated SOC support included
    • One platform for application security needs
    • Many supported deployment models – we’ll fit YOUR environment, not the other way around
  4. ML and Automation Should be Real and Transformative, not Magic

    Takeaway: Modern platforms rely on magic (some form of context-based, ML-enhanced detection) and automation to detect sophisticated attacks while reducing manual intervention.

    ThreatX Perspective: We also have proprietary ML-enhanced detection, but our ML algorithms are battle-tested, meaning they aren’t just theoretical, they have been used in practice for years, and finely tuned for practical functionality. 

    Analysts highlight our ability to:

    • Correlate behavior across vectors
    • Identify coordinated attack campaigns
    • Operate with near-zero false positives

    This process is further enhanced by the ThreatX SOC, allowing us to deliver what many vendors are still building toward

  5. Future Expectations: API Depth

    Takeaway: The market is rapidly moving toward deeper API-specific controls and protection for AI-driven applications.

    ThreatX Perspective: AI doesn’t change the target. It is still the applications. What changes is how applications are used. AI systems rely heavily on APIs to function, which means ThreatX can be directly in the enforcement path. This means we’re not just protecting APIs. We’re also gaining visibility into what AI-based interactions are happening. Where our roadmap becomes critical is deeper AI-specific protection. An AI firewall can help complement this by extending protection into prompt/model-level threats.

    Analysts call out opportunities around:

    • Endpoint-specific rate limiting, preventing targeted API abuse
    • API-aware threat detection to be more like an API-specialized vendor
    • The creation of API schema definition in real time
    • Extending into AI/LLM protection 

Here’s the good news: Not only are these just extensions of our current capabilities, many of these are already available features, and others are on the roadmap – let’s chat! 

Final Thought: Aligned with the Market, and Positioned to Lead

We’re aligned with analysts in terms of where the market is heading. The growth points and future outlook presented are all excellent opportunities for us to extend ThreatX’s functionality, which is built on a strong foundation. As the industry is moving toward smarter, simpler, and more unified security platforms, it sounds like the market is catching on to the fuss about WAPP (Web Application Protection Platform), which is how ThreatX by A10 was built from day one.


FAQs

Web Application Protection Platform is an approach for web application and API security that focuses on protecting the application ecosystem from attacks and attackers.

APIs now make up a huge portion of application traffic, have access to sensitive data, and are particularly vulnerable to business logic exploits

This means protections such as WAF, API, bot, and L7 DDoS are provided by a single, unified solution. This approach simplifies operations, reduces technical debt, and increases overall effectiveness.

With L7 DDoS, attackers can cause significant disruption with relatively low-volume traffic by targeting application logic and resource-heavy functions. Because these attacks often mimic legitimate users and behavior, they are harder to detect and mitigate.

AI applications rely heavily on APIs to carry out its advanced functions.



Gary Wang