Return this item by mail or in store within 90 days for a full refund.
Eligible for registries and wish lists
About this item
Highlights
Proactively identify and mitigate API security risks using practical testing techniques in an ASP.NET Core development workflow.
About the Author: Roman Canlas is an accomplished application security engineer who built and runs the global application security program for a Fortune 500 company.
345 Pages
Computers, Programming
Description
Book Synopsis
Proactively identify and mitigate API security risks using practical testing techniques in an ASP.NET Core development workflow. With APIs becoming the backbone of modern applications and digital transformation, they have also become prime targets for cyberattacks. This book empowers you to take control of your API security by integrating security testing directly into your development process.
Through hands-on C# code examples using WebApplicationFactory and real-world scenarios from a vulnerable Banking API, you will learn to write security tests that verify your defenses against each of the OWASP Top 10 API Security risks. From broken authorization and authentication flaws to server-side request forgery and security misconfiguration, each chapter provides concrete testing strategies that catch vulnerabilities before they reach production.
By following the testing patterns and practices presented in this book, you will build APIs that are not just functional but comprehensively secure.
What You Will Learn
Write security-focused integration tests using WebApplicationFactory and C# that integrate seamlessly into your development workflow
Test and defend your APIs against all OWASP Top 10 API Security risks, including broken authorization, authentication bypass, and injection vulnerabilities
Integrate API security testing as a natural part of the ASP.NET Core API development process
Build a security mindset that treats security as a fundamental quality attribute of your APIs
Who This Book is For
This book is for ASP.NET Core developers, QA engineers, and DevOps professionals who want to take ownership of API security testing. Whether you are building new APIs or securing existing ones, you will benefit from the practical testing techniques presented here. Familiarity with C# and basic ASP.NET Core development is assumed, but no prior security expertise is required. This is an evergreen book that is not specific to any particular version of ASP.NET Core.
From the Back Cover
Proactively identify and mitigate API security risks using practical testing techniques in an ASP.NET Core development workflow. With APIs becoming the backbone of
modern applications and digital transformation, they have also become prime targets for cyberattacks. This book empowers you to take control of your API security by integrating security testing directly into your development process.
Through hands-on C# code examples using WebApplicationFactory and real-world scenarios from a vulnerable Banking API, you will learn to write security tests that verify your defenses against each of the OWASP Top 10 API Security risks. From broken authorization and authentication flaws to server-side request forgery and security misconfiguration, each chapter provides concrete testing strategies that catch vulnerabilities before they reach production.
By following the testing patterns and practices presented in this book, you will build APIs that are not just functional but comprehensively secure.
What You Will Learn
Write security-focused integration tests using WebApplicationFactory and C# that integrate seamlessly into your development workflow
Test and defend your APIs against all OWASP Top 10 API Security risks, including broken authorization, authentication bypass, and injection vulnerabilities
Integrate API security testing as a natural part of the ASP.NET Core API development process
Build a security mindset that treats security as a fundamental quality attribute of your APIs
About the Author
Roman Canlas is an accomplished application security engineer who built and runs the global application security program for a Fortune 500 company. His background in C# and ASP.NET development gives him a developer's eye for identifying code-level vulnerabilities and conducting web security testing. He holds GIAC GWAPT, ISC2 CSSLP, and EC-Council CASE.NET certifications, along with a Master's in Information Systems and a Bachelor's in Computer Science degree.
He wrote this book to share practical approaches that developers and security teams can actually implement. This book distils his experience into security tests you can write and run today.
Dimensions (Overall): 9.97 Inches (H) x 7.03 Inches (W) x .75 Inches (D)
Weight: 1.48 Pounds
Suggested Age: 22 Years and Up
Number of Pages: 345
Genre: Computers
Sub-Genre: Programming
Publisher: Apress
Theme: Microsoft
Format: Paperback
Author: Roman Canlas
Language: English
Street Date: May 5, 2026
TCIN: 1012980037
UPC: 9798868823909
Item Number (DPCI): 247-59-0675
Origin: Made in the USA or Imported
If the item details aren’t accurate or complete, we want to know about it.
Shipping details
Estimated ship dimensions: 0.75 inches length x 7.03 inches width x 9.97 inches height
Estimated ship weight: 1.48 pounds
We regret that this item cannot be shipped to PO Boxes.
This item cannot be shipped to the following locations: American Samoa (see also separate entry under AS), Guam (see also separate entry under GU), Northern Mariana Islands, Puerto Rico (see also separate entry under PR), United States Minor Outlying Islands, Virgin Islands, U.S., APO/FPO, Alaska, Hawaii
Return details
This item can be returned to any Target store or Target.com.
This item must be returned within 90 days of the date it was purchased in store, delivered to the guest, delivered by a Shipt shopper, or picked up by the guest.