All integrations

Akamai Integration with DefectDojo

Akamai API Security Integration with DefectDojo

Akamai API Security is Akamai's API protection product, built on its 2024 acquisition of Noname Security. It discovers the APIs running across an organization's environment, including ones that were never documented, assesses their security posture, and detects attacks and misuse against them at runtime. Findings are organized around the applications and hosts that expose those APIs, and are available through the Akamai API, which is what the DefectDojo Pro connector reads.

Akamai API Security Integration with DefectDojo

We run Akamai API Security because our API inventory grows faster than anyone can document it, and we connect it to DefectDojo because API findings need the same follow-through as everything else. The DefectDojo Pro Akamai connector reads findings straight from the Akamai API and maps each Akamai application and host to a DefectDojo Asset. From there an API posture issue gets an owner, an SLA, and a history, and it sits on the same Asset as the code and dependency findings for the service behind that API.

Why Akamai API Security Matters

APIs are the front door for most modern applications, and they are often where inventory and reality disagree.

  • Discovery finds APIs that teams didn't register, which are the ones least likely to have been tested.
  • API posture issues, such as weak authentication or sensitive data in responses, are often design problems that code scanners may not see.
  • Runtime visibility shows how APIs are actually being called, not only how they were designed.
  • API findings on their own sit in a separate console. Without a central platform it is hard to tell whether an API issue on a service is more urgent than that service's open dependency CVEs.

Advantages of This Integration

What we gained by connecting Akamai API Security to DefectDojo Pro:

  • No exports to manage. The connector authenticates with an Akamai API key and pulls findings on a schedule, so nobody downloads reports by hand.
  • Akamai structure preserved. Each Akamai Application and each Host becomes its own Record, which keeps the mapping to DefectDojo Assets clear and lets you send each one to the team that owns it.
  • Automatic lifecycle. Each Sync runs as a reimport. New findings are added, and findings no longer reported by Akamai are marked inactive, so the Asset reflects the current API exposure.
  • Shared triage and SLAs. API findings use the same severity SLAs, assignment, risk acceptance, and Jira push as every other Finding in DefectDojo.
  • Health alerts. The Connector Health Warning notification tells you when Syncs start failing or Akamai stops returning the Records it used to, instead of the integration going quiet.

How This Integration Works

Akamai API Security is integrated through a DefectDojo Pro connector (an Upstream Connector). DefectDojo does not ship a file parser for Akamai API Security reports, so the connector is the documented path for getting Akamai findings in.

1. Create an Akamai API key. You need an API key with access to the Akamai API. A dedicated service account for DefectDojo keeps automated activity separate from the actions of people on your team.

2. Add the connector in DefectDojo Pro. Under Connect > Upstream, find Akamai and add a configuration:

  1. Enter your Akamai API base URL in the Location field. This URL is specific to your Akamai instance.
  2. Enter the API key in the Secret field.

3. Discover. DefectDojo runs a Discover operation (daily, or on demand) to learn your Akamai environment. Each Akamai Application appears as a Record named {name} (application) and each Host as {name} (host).

4. Map Records to Assets. With Auto-Map enabled, DefectDojo creates or matches an Asset for each Record automatically. Without it, Records wait in the Unmapped list until you assign each one to a new or existing Asset. You might map several hosts to the Asset for one service, for example.

5. Sync. Every mapped Record is synced daily, and you can trigger a Sync manually from the Manage Records and Operations page. Findings are stored under an Engagement called Global Connectors on the mapped Asset, with a Test for the connector.

Data Granularity: What Gets Imported

The DefectDojo connector documentation describes how Akamai objects map into DefectDojo. It does not list field-level mappings for Akamai findings, so check a synced Finding to see exactly how title, description, and severity are populated for your account.

DefectDojo Object Source in Akamai Notes
Record Akamai Application Named {name} (application)
Record Akamai Host Named {name} (host)
Asset Mapped Record Assigned by Auto-Map or by hand; remapping by hand always wins
Engagement Created by DefectDojo Named Global Connectors, under the mapped Asset
Test The Akamai connector One Test per connector on the Asset
Findings Akamai API security findings Imported on each Sync
Status changes Sync comparison Findings absent from the latest Sync are marked inactive
Field adjustments Connector Field Mappings Rearrange, combine, or normalize fields the connector already sends

Connector Field Mappings apply per scan type. They can move or combine values the connector already sends, but they can't surface a value the connector doesn't send.

Use Cases

API inventory to remediation: A platform security team connects Akamai and lets Auto-Map create an Asset for each application. Product teams see the API findings for their services next to their SAST and SCA results and work them under the same SLAs.

Mapping hosts to services: Akamai reports by host as well as by application. A team that runs one service behind several hostnames maps all of those host Records to one DefectDojo Asset, so the service's API exposure is reported once.

Audit and compliance evidence: Because each Sync is a reimport, DefectDojo keeps when each API finding was first seen and when it stopped being reported. That answers how long an exposed or misconfigured API stayed that way.

Executive reporting: API risk appears in the same metrics and reports as the rest of the program, so leadership doesn't need a separate view of API security to compare it with everything else.

Operational Tips

  • Use a dedicated Akamai service account for the API key, and note when the key needs rotating so Syncs don't fail unexpectedly.
  • Decide on your Record mapping strategy before enabling Auto-Map. Applications and hosts both create Records, and mapping both to separate Assets can split one service's findings.
  • Turn on the Connector Health Warning notification and route it to email or Slack, so a broken credential is noticed the day it breaks.
  • Run Discover manually after onboarding new applications in Akamai rather than waiting for the daily run.
  • Review the first Sync's Findings for severity and title quality, and use Connector Field Mappings if a field needs normalizing before deduplication depends on it.
  • Set SLAs for the Assets that receive Akamai findings, and use tags to separate internet-facing APIs from internal ones in reports.