teejlab / API-Risk-Assessment-Framework

A framework for quantifying API risks.
https://teejlab.github.io/API-Risk-Assessment-Framework/intro.html
MIT License
5 stars 8 forks source link

Use of NRI for proxy of 'server_location' #52

Open Jacq4nn opened 2 years ago

Jacq4nn commented 2 years ago

Hi team. I am doing a little more research about some features in our dataset. I have a question about geopolitics and API security/risk, more specifically if there is a long-term association between host_country and API security? I suppose my basic intuition is that if a country is undergoing some civil strife, there would be some impact on some APIs (more attempts in injection for example in the business API) from other states who want to cause disruption to that specific country. However, this is temporal and is constantly changing. Are there perhaps other long-term variables with regard to a country that can allow us to quantify (i.e. Canada is more secure than South Korea, but is less secure than Singapore). With that, are there any papers that you can suggest to allow us to understand how geopolitics/governance/federal laws or other factors can lead to a compromise in API security?

Jacq4nn commented 2 years ago

For example,

However, these all seem rather state-centric and I’m a little wary about how this translates into corporations. With this said, countries such as Poland are trying to establish their own public cloud service, which leads me to think that I cannot look at this feature “host_country” in silo, and would potentially need to look at the city in which the data centre is located in and potentially the server name to. For some context, this is the article that I read: (https://ruj.uj.edu.pl/xmlui/bitstream/handle/item/262562/roguski_the_geopolitics_of_cloud_computing_2020.pdf?sequence=1&isAllowed=y) This is somewhat of a policy memo to discuss which direction Central European states should head towards with regard to digital sovereignty, in light of the encroachment of the US and China into their digital data.