API Security

Wallarm’s Open Source API Firewall debuts at Blackhat Asia 2024 – Introduces Key New Features & Functionalities

Wallarm introduced its ongoing Open Source API Firewall project to the world at the recently concluded Blackhat Asia 2024 conference in Singapore.

The open-source API Firewall by Wallarm is a free, lightweight API Firewall designed to protect REST and GraphQL API endpoints across cloud-native environments using API schema validation. By relying on a positive security model, our API Firewall only allows calls that match a predefined API specification while rejecting everything else.

At the event, our in-house expert Nikolay Tkachenko (Research Engineer @ Wallarm) showcased the latest developments and improvements made to the open-source project and what it means for the developer community looking to build more robust cybersecurity solutions.

Key Features of the API Firewall that were introduced

1. Secure REST and GraphQL API endpoints by blocking non-compliant requests/responses:

The API Firewall ensures the security of REST and GraphQL API endpoints by actively monitoring and blocking requests and responses that do not comply with predefined security standards. This includes preventing unauthorized access, malicious injections, and other security threats.

2. Stop API data breaches by blocking malformed API responses:

Malformed API responses can be a gateway for data breaches. The Firewall identifies and blocks any attempts to send or receive data in a format that deviates from the expected structure, preventing potential breaches and ensuring data integrity.

3. Discover Shadow API endpoints:

Shadow API endpoints, often unnoticed and unsecured, can pose significant security risks. The Firewall actively discovers these endpoints, enabling organizations to secure them and prevent potential vulnerabilities and unauthorized access.

4. Block attempts to use request/response parameters not specified in an OpenAPI specification:

By adhering strictly to the OpenAPI specification, the Firewall blocks any attempts to use request or response parameters that are not explicitly defined. This ensures that only permitted data and parameters are exchanged, minimizing the risk of injection attacks and unauthorized access.

5. Validate JWT access tokens:

JSON Web Tokens (JWTs) are commonly used for authentication and authorization in APIs. The Firewall validates JWT access tokens to ensure their authenticity and integrity, preventing unauthorized access and ensuring secure communication between clients and servers.

6. Validate other OAuth 2.0 tokens using introspection endpoints:

In addition to JWT tokens, the Firewall validates other OAuth 2.0 tokens using introspection endpoints. This process verifies the validity and permissions associated with OAuth tokens, enhancing overall security and access control.

7. Denylist compromised API tokens, keys, and Cookies:

Compromised API tokens, keys, and cookies pose significant security risks. The Firewall maintains a denylist of known compromised tokens, keys, and cookies, blocking any attempts to use them for access. This proactive approach helps mitigate the risks associated with compromised credentials and enhances overall security posture.

If you'd like to try the Wallarm API Firewall for yourself, check out our official GitHub account.

Recent Posts

AI Agent Security Readiness: The Federal Standard You Should Get Ahead Of

Here's the uncomfortable part first: in August 2026, researchers found AI agents connected to Hugging…

2 weeks ago

Dissecting Attacks Is Only Valuable If It Informs Controls: What the Unit 42 agentic AI investigation should change in your control set, stage by stage.

The volume of published incident research involving agentic AI is increasing, and the analysis that…

4 weeks ago

Lessons from the OpenAI and Hugging Face Incident: When Safety Filters Disarm the Defender

In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face's…

2 months ago

AI Control Platform vs. AI Firewall vs. AI Gateway: Clearing Up The Terminology

Editor's note: This article was originally published by Tim Erlin on LinkedIn. It has been…

3 months ago

Introducing the Wallarm AI Control Platform: One closed loop for AI security and API security.

TL;DR- AI deployment has outpaced AI governance. Most enterprises running AI on AWS cannot answer…

4 months ago

What Your Board Gets Wrong About AI Security

Editor's note: This article was originally published by Craig Riddell on LinkedIn. It has been…

4 months ago