Get a Demo
Under Attack?
Illustration of a cargo dock with stacks of blue and pink shipping containers, some bearing the logo Upwind. The scene includes overhead structures and rows of containers along a dock under bright lighting.

Automatically Discover API Sensitive Data Flows

Joshua Burgin October 22, 2024

Automatically Discover API Sensitive Data Flows

We are excited to announce a significant new addition to Upwind’s API Security capability – the automatic discovery and classification of sensitive data flows.

Upwind automatically tracks sensitive data routes and classifies sensitive data as PCI, PII, and PHI by analyzing API samples recognized by the Upwind sensor, making it easy to identify where you are at elevated risk.

Screenshot-2024-08-30-at-9.50.26%E2%80%AFAM-1024x656

Examples of sensitive data that Upwind identifies include:

  • PHI data: patient information, medical records & insurance information
  • PII data: SSNs, IDs and emails
  • PCI data: credit cards and billing information
Screenshot-2024-08-30-at-9.50.02%E2%80%AFAM-1024x732

How Upwind Identifies Sensitive Data Flows

In order to identify sensitive data flows, Upwind searches for patterns at the packet level and then masks any data found, ensuring it remains secure and is never sent outside of your environment. When an API request for sensitive data  is detected, Upwind labels it with a sensitive data tag and classifies it by its type and category, such as PCI for a MasterCard number. We are continuing to extend this capability, and customers will soon be able to create their own custom regular expression (regex) to classify sensitive data.

Screenshot-2024-09-04-at-6.13.58%E2%80%AFAM-1024x483

Use Upwind’s automated sensitive data flow tracking to easily understand API data security risks, prioritize remediation efforts for APIs with sensitive data flows, and ensure a proactive approach to data security. 

Learn More

To learn more about Upwind API Security, visit the Upwind Documentation Center (login required), or schedule a demo.

Contents

Further Reading

Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Custom-Reporting-Hero

Security Reporting Built Around Your Program

We've all been there: it's 3:00 PM on a Friday, and you get that "quick" request for a specific security status report. Suddenly, your afternoon is gone as you juggle filters, export CSVs, and try to explain to someone outside the security team why these numbers actually matter. Reporting shouldn't feel like a fire drill…
Blue-agent-blog

Introducing the Upwind Blue Agent: Autonomous Threat Investigation for the SOC

We’re excited to announce that the Upwind Blue Agent is now available in Beta. Blue is an AI-powered SOC investigator that autonomously investigates Upwind Threat Stories end to end. It gathers and correlates security context across the customer environment, evaluates the available evidence, and delivers one of three clear verdicts: Each verdict includes supporting reasoning…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS