THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Thursday, April 21, 2022
Corsha is an API Identity and Access Management technology that protects machine-to-machine communication and adds automated multi-factor authentication (MFA) to APIs. Corsha's patented technology creates dynamic identities for trusted machines and securely authenticates API calls using one-time-use MFA credentials for better security, visibility, and control.
FREMONT, CA: API security is a broad phrase that refers to procedures and technologies that protect application program interfaces from malicious attacks or misuse (API). Unfortunately, APIs have become a target for hackers since they are essential for designing web-based interactions. As a result, basic authentication, which only required user names and passwords, has been phased out in favor of other security tokens, such as those used in multifactor authentication (MFA).
To introduce one-time-use, multi-factor authentication (MFA) credentials to the world of APIs, the API security business creates automated and dynamic machine identities. Corsha, a Washington, DC-based API security business that offers a unique solution to safeguarding API communication between trusted machines, has raised $12 million in a Series A fundraising round. The round was co-led by Ten Eleven Ventures and Razor's Edge Ventures, participating from 1843 Capital.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Corsha delivers a first-of-its-kind platform for secure communication in both on-prem and cloud environments, thanks to partners like Dell Technologies. “By taking an identity-first approach to API security, Corsha provides a much-needed security layer to the way organizations should manage service-to-service communication. Corsha provides all the goodness of MFA to secure the communication between APIs, as well as the machines that are accessing them,” said Chris “CT” Thomas, a Technical Strategist in the Office of the CTO at Dell.
Security teams can use Corsha's unique technology to cryptographically assign dynamic identities to a set of trusted machines and restrict API access to those devices. Corsha addresses security risks in machine-to-machine communication by using an innovative approach to machine identification and MFA for APIs, providing a zero-trust API security posture in cloud-native environments for north-south or east-west APIs.
Chris Simkins and Anusha Iyer, co-founders of Corsha, have extensive expertise supporting national security projects and have witnessed firsthand the security risks that unsecure APIs represent to businesses.
“API secrets are being used as proxies for machine identities – each machine ideally needs its own secret. But these secrets are routinely being shared between machines, and leaked in code repositories or CI pipelines at an alarming rate. They’re rarely rotated and often set to never expire,” explained Iyer. “The greater we automate our application development and deployment processes, the more the risk shifts from human to machine. It’s more important than ever to have clear visibility into the machines that are accessing APIs and be able to seamlessly control access,” added Simkins.
The machines that fuel API-first environments are the ones that drive them—securing API communication between services, whether Kubernetes pods, containers, virtual machines, physical servers, IoT devices, or other form factors, is often an afterthought. ACCORDING TO GARTNER, 'API security concerns have surfaced as a top worry for most software engineering leaders because unmanaged and insecure APIs generate vulnerabilities that might expedite multimillion-dollar security events. According to Verified Market Research, the API Management market is estimated to be valued at $13.6 billion by 2028, with a compound annual growth rate (CAGR) of 29 percent from 2021 to 2028. According to current predictions, the cost of data breaches will exceed $10.5 trillion per year by 2025.
“The Corsha team has a unique perspective and clear vision on how the API Security and machine identity markets are growing and evolving, and their technology is going to revolutionize how enterprises think about API traffic management and machine authentication,” said Mark Hatfield, Founder and General Partner at Ten Eleven Ventures. “We are extremely excited to invest in Corsha to accelerate their growth and continued product development.”
A key authentication factor such as a PKI certificate, JSON Web Token, or OAuth token is commonly used when an application or service wishes to perform an API call. Corsha fortified the API request with a one-time-use MFA certificate based on the machine's dynamic identity and verified it against a cryptographically verifiable distributed ledger network (DLN). The API request will only be accepted if the MFA credential and the machines identified on the DLN match. A security operations center (SOC) might easily utilize Corsha to revoke API access for a specific machine or group of machines without affecting other workloads if a log management system identifies a potential security event.
Corsha recently launched an API Security Scorecard, which uses a set of simple questions to assess an organization's API security posture. In addition, Corsha intends to spend extensively on API discovery and observability, API ecosystem integrations, and open-source technologies to enable application security teams to stay ahead of the API attack surface with the new funding.
More in News