Penetration testing of application programming interface endpoints using security agents
Systems, methods, and devices that relate to penetration testing using security agents are disclosed. In one example aspect, a system is caused to receive information of an API endpoint to be tested, select tools for testing the API endpoint, determine an order of execution of the tools, identify task agents suitable for testing the API endpoint, route the information of the API endpoint to the task agents, coordinate an execution time of the tools according to the order of execution, perform testing, using the task agents, of the API endpoint based on the coordination, validate testing results from the task agents, and provide a report for testing of the API endpoint.
1 . A security system comprising one or more processors and a memory to implement a hierarchy of security agents, wherein the hierarchy of security agents comprises:
a routing agent configured to:
receive, from a user device, information of an application programming interface (API) endpoint to be tested,
wherein the information of the API endpoint comprises a type of the API endpoint and historical vulnerabilities of the API endpoint;
select, based on at least the type of the API endpoint and the historical vulnerabilities of the API endpoint, one or more tools for testing the API endpoint;
determine an order of execution of the one or more tools based on the information of the API endpoint,
wherein the order specifies whether a subset of the one or more tools is to be executed in parallel;
identify, based on the information of the API endpoint and the selected one or more tools, one or more task agents from the hierarchy of security agents suitable for testing the API endpoint,
wherein each of the one or more task agents is trained to test endpoints using at least one of the selected one or more tools; and
route the information of the API endpoints to the one or more task agents;
a plurality of task agents comprising the one or more task agents,
wherein the plurality of task agents is configured to:
coordinate an execution time of the one or more tools according to the determined order of execution; and
perform testing of the API endpoint based on the coordination; and
a supervisor agent configured to:
validate testing results from the one or more task agents; and
provide, based on the validated testing results, a report for testing of the API endpoint for the user device.
2 . The security system of claim 1 , wherein the report indicates at least one update required for the API endpoint based on the testing of the API endpoint.
3 . The security system of claim 1 , wherein the routing agent is configured to route the information of the API endpoints to the one or more task agents based on load balancing the testing of the API endpoints across the one or more task agents.
4 . The security system of claim 1 , wherein the supervisor agent is further configured to:
generate one or more confidence scores associated with the validated testing results,
wherein the one or more confidence scores indicate a likelihood that the validated testing results are accurate; and
provide the one or more confidence scores with the report for the testing of the API endpoint.
5 . The security system of claim 1 , wherein the routing agent is further configured to determine one or more triggers for performing the testing of the API endpoint, and wherein the one or more task agents are further configured to perform the testing of the API endpoint further based on the one or more triggers.
6 . The security system of claim 1 , wherein the report indicates one or more vulnerabilities of the API endpoint discovered through the testing and at least one tool, of the one or more tools, used to discover the one or more vulnerabilities.
7 . A computer implemented method using one or more processors and a memory, the method comprising:
receiving, from a user device, information of an application programming interface (API) endpoint to be tested,
wherein the information of the API endpoint comprises a type of the API endpoint and historical vulnerabilities of the API endpoint;
selecting, based on at least the type of the API endpoint and the historical vulnerabilities of the API endpoint, one or more tools for testing the API endpoint;
determining an order of execution of the one or more tools based on the information of the API endpoint;
identifying, based on the information of the API endpoint and the selected one or more tools, one or more task agents from a hierarchy of security agents suitable for testing the API endpoint,
wherein each of the one or more task agents is trained to test endpoints using at least one of the selected one or more tools;
routing the information of the API endpoints to the one or more task agents,
coordinating an execution time of the one or more tools according to the determined order of execution,
wherein a subset of the one or more tools is to be executed in parallel;
performing testing of the API endpoint, using the one or more task agents, based on the coordination;
validating testing results from the one or more task agents;
providing, based on the validated testing results, a report for testing of the API endpoint for the user device, wherein the report indicates at least one update required for the API endpoint based on the testing of the API endpoint; and
causing the API endpoint to implement the at least one update based on the testing of the API endpoint.
8 . The method of claim 7 , further comprising routing the information of the API endpoints to the one or more task agents by load balancing the testing of the API endpoints across the one or more task agents.
9 . The method of claim 7 , further comprising:
generating one or more confidence scores associated with the validated testing results,
wherein the one or more confidence scores indicate a likelihood that the validated testing results are accurate; and
providing the one or more confidence scores with the report for the testing of the API endpoint.
10 . The method of claim 7 , further comprising determining one or more triggers for performing the testing of the API endpoint, wherein the one or more task agents are further configured to perform the testing of the API endpoint further based on the one or more triggers.
11 . The method of claim 7 , wherein the report comprises data regarding one or more vulnerabilities of the API endpoint discovered through the testing and at least one tool, of the one or more tools, used to discover the one or more vulnerabilities.
12 . The method of claim 11 , wherein the at least one update comprises a change to the API endpoint that addresses the one or more vulnerabilities of the API endpoint discovered through the testing.
13 . One or more non-transitory, computer-readable media storing instructions that, when executed by one or more processors, cause operations comprising:
receiving, from a user device, information of an application programming interface (API) endpoint to be tested,
wherein the information of the API endpoint comprises a type of the API endpoint and historical vulnerabilities of the API endpoint;
selecting, based on at least the type of the API endpoint and the historical vulnerabilities of the API endpoint, one or more tools for testing the API endpoint;
determining an order of execution of the one or more tools based on the information of the API endpoint,
wherein the order specifies whether a subset of the one or more tools is to be executed in parallel;
identifying, based on the information of the API endpoint and the selected one or more tools, one or more task agents from a hierarchy of security agents suitable for testing the API endpoint,
wherein each of the one or more task agents is trained to test endpoints using at least one of the selected one or more tools;
routing the information of the API endpoints to the one or more task agents,
coordinating an execution time of the one or more tools according to the determined order of execution,
wherein a subset of the one or more tools is to be executed in parallel;
performing testing of the API endpoint, using the one or more task agents, based on the coordination;
validating testing results from the one or more task agents;
providing, based on the validated testing results, a report for testing of the API endpoint for the user device, wherein the report indicates at least one update required for the API endpoint based on the testing of the API endpoint; and
causing the API endpoint to implement the at least one update based on the testing of the API endpoint.
14 . The one or more non-transitory, computer-readable media of claim 13 , wherein the report comprises data regarding one or more vulnerabilities of the API endpoint discovered through the testing and at least one tool, of the one or more tools, used to discover the one or more vulnerabilities.
15 . The one or more non-transitory, computer-readable media of claim 13 , wherein the instructions further cause operations comprising routing the information of the API endpoints to the one or more task agents by load balancing the testing of the API endpoints across the one or more task agents.
16 . The one or more non-transitory, computer-readable media of claim 13 , wherein the instructions further cause operations comprising:
generating one or more confidence scores associated with the validated testing results,
wherein the one or more confidence scores indicate a likelihood that the validated testing results are accurate; and
providing the one or more confidence scores with the report for the testing of the API endpoint.
17 . The one or more non-transitory, computer-readable media of claim 13 , wherein the instructions further cause operations comprising determining one or more triggers for performing the testing of the API endpoint, wherein the one or more task agents are further configured to perform the testing of the API endpoint further based on the one or more triggers.