Skip to content

Unlocking the Power of Virtual Desktops on Google Cloud with Thinfinity Workspace

Introduction

The way we work is evolving, with remote and hybrid setups becoming the norm. As businesses adapt, the demand for secure, scalable, and efficient Virtual Desktop Infrastructure (VDI) solutions is skyrocketing. Enter Google Cloud Platform (GCP) and Thinfinity Workspace—a dynamic duo designed to revolutionize how virtual desktops and applications are deployed and managed.
This guide dives into why GCP is a prime choice for virtual desktops and how Thinfinity Workspace amplifies its potential. From automation to security and scalability, discover how this integration transforms your digital workspace.

 

 

Why Choose GCP for Virtual Desktops?

Google Cloud Platform is built for businesses looking to enhance performance, availability, and security. Here’s why it stands out:

  • Global Infrastructure: Access low-latency services through GCP’s extensive data center network.
  • Scalability on Demand: Dynamically adjust virtual resources to meet business needs.
  • Top-Tier Security: Benefit from GCP’s identity and access management (IAM), encryption, and network protection.
  • Cost Optimization: Pay-as-you-go pricing ensures cost-efficiency for any scale.

When paired with Thinfinity Workspace, GCP transforms into a robust VDI solution, delivering seamless experiences for businesses and users alike.

 

Thinfinity Cloud Manager: Simplified GCP VDI Management

At the heart of Thinfinity Workspace is Thinfinity Cloud Manager, an intuitive platform designed to streamline VDI operations on GCP. Its features ensure efficient management and deployment, reducing complexity and boosting productivity.

Key Features of Thinfinity Cloud Manager

 1. Automated Provisioning

Accelerate virtual desktop deployment with pre-configured templates. Thinfinity Cloud Manager enables:

  • Automated virtual machine creation on GCP.
  • Reusable templates for standardized setups.
  • Significant reductions in setup time.
What-is-a-virtual-desktop-manager

Thinfinity Cloud Manager: Optimize Virtual Desktops Across Azure, AWS, GCP, and More

Dive deeper into this topic →

 2. Infrastructure as Code (IaC)

Take control of your infrastructure with code-based configurations:
  • Seamlessly integrate with tools like Terraform and Ansible.
  • Maintain consistency with version-controlled settings.
  • Rapidly scale resources to meet changing demands.

Thinfinity Cloud Manager: Automating Infrastructure as Code for Cloud Computing

Dive deeper into this topic →

3. Real-Time Monitoring and Alerts

Gain visibility into resource usage, performance, and user activity:
  • Monitor metrics in real-time.
  • Receive automated alerts to address issues proactively.

4. Self-Service Portals

Empower users with self-service functionality:
  • Allow users to manage their virtual desktops independently.
  • Minimize reliance on IT, boosting operational efficiency.
 
Automate provisioning, use Infrastructure as Code, monitor in real-time, and enable self-service portals
 

 

Security: The Zero Trust Advantage

With cyber threats on the rise, Zero Trust security is no longer optional. Thinfinity Workspace implements Zero Trust principles, ensuring each access request is rigorously authenticated and encrypted. Key security benefits include:

  • Unified Identity Management: Integrate seamlessly with Active Directory and other identity providers.
  • Granular Access Controls: Define precise roles and permissions with Role-Based Access Control (RBAC).
  • End-to-End Encryption: Safeguard communications between users and virtual desktops.
  • Regulatory Compliance: Ensure adherence to standards with Thinfinity’s audit-ready capabilities.
Thinfinity Workspace: Zero Trust security with unified identity management, RBAC, end-to-end encryption, and regulatory compliance
 

Scalability Meets Automation: The GCP and Thinfinity Advantage

Scalability

Thinfinity Workspace, combined with GCP, delivers unparalleled flexibility:

  • Elastic Resources: Scale up or down automatically to meet user demands.
  • Hybrid and Cloud-Native Options: Extend on-premises resources or fully embrace the cloud.
  • Global Reach: Tap into GCP’s worldwide infrastructure for seamless connectivity.
 

Automation

Automation is a game-changer for managing virtual desktops. Thinfinity Workspace offers:

  • Policy-Based Management: Dynamically assign resources based on predefined rules.
  • Streamlined Maintenance: Automate updates and patches for uninterrupted service.
  • API-Driven Integration: Enable custom workflows with third-party tools and DevOps pipelines.

Prepare your GCP VM to Run Thinfinity Workspace

If you’re exploring Virtual Desktop Infrastructure (VDI) on Google Cloud Platform, don’t miss our detailed guide: Host Your Desktop Applications in Google Cloud Platform.

This article complements the current tutorial by providing a step-by-step overview of preparing your Google Cloud VM for hosting desktop applications. It’s an essential resource for ensuring your virtual machine is properly configured before deploying Thinfinity Workspace or other applications.

Leverage both guides to maximize your efficiency and streamline your cloud-based application deployment.

 
Thinfinity Cloud Manager: Automating Infrastructure as Code for Cloud Computing

Dive deeper into this topic →

 

Benefits of Adopting VDI on GCP with Thinfinity Workspace

  • Cost Efficiency: Optimize budgets with GCP’s flexible pricing and Thinfinity’s resource management.
  • Enhanced Security: Adopt enterprise-grade protection through Zero Trust architecture.
  • Seamless Accessibility: Deliver an exceptional user experience with browser-based access.
  • Operational Excellence: Simplify processes with Thinfinity’s automation and self-service features.
  • Future-Ready Solutions: Leverage Thinfinity and GCP’s innovation to stay ahead of business challenges.
Thinfinity Workspace on GCP: Cost-efficient, secure, browser-accessible, automated, and future-ready virtual desktop solutions
 

Conclusion

GCP and Thinfinity Workspace create a powerful partnership for organizations aiming to modernize their IT infrastructure. By combining GCP’s robust cloud platform with Thinfinity’s advanced management and automation features, businesses can unlock the true potential of VDI.
Whether it’s enhanced security, seamless scalability, or unmatched flexibility, Thinfinity Workspace ensures your business is ready for the future. Start transforming your virtual desktop strategy today—because the future of work is already here.

FAQ

Thinfinity Workspace is a platform for managing virtual desktops and applications with browser-based access, focusing on scalability, security, and efficiency.

GCP’s global infrastructure, built-in security, and cost-effective pricing make it an ideal platform for deploying virtual desktops.

Thinfinity Cloud Manager streamlines provisioning, automates infrastructure management through IaC, and enhances efficiency with real-time monitoring and self-service features.

Yes, Thinfinity Workspace supports GPU-enabled instances on GCP, making it perfect for demanding applications like CAD and 3D modeling.

IaC allows infrastructure management through code, enabling consistent, automated resource provisioning and scalability.

About Cybele Software Inc.
We help organizations extend the life and value of their software. Whether they are looking to improve and empower remote work or turn their business-critical legacy apps into modern SaaS, our software enables customers to focus on what’s most important: expanding and evolving their business.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Everything you need to know about Retrieval-Augmented Generation (RAG)

The role of AI in IT Service Management

Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), and Knowledge Graphs (KGs) are reshaping how we manage and utilize vast amounts of data.

 

Understanding each of these technologies and how they interact can provide a deeper insight into their potential to transform ITSM. LLMs are advanced AI models trained on vast amounts of data to generate human-like text based on the input they receive. It is noteworthy to mention that the large language model itself does not have a memory or access to real time information. Moreover, LLMs can lose focus and hallucinate especially when given a large input.

To address some limitations of LLMs, Retrieval-Augmented Generation (RAG) can play an important role. RAG is a technique that enhances the capabilities of LLMs by dynamically retrieving external information from a knowledge base at the time of the query. This allows LLMs to access up-to-date information about the query and generate more accurate and relevant responses.

While RAG significantly enhances LLMs by providing them with access to external data, Knowledge Graphs (KGs) offer another layer of sophistication.

KGs are structured databases that store data in an interconnected network of entities and their relationships. They provide a structured way to represent knowledge in various domains, including ITSM. KGs can be used to further enhance the performance of LLMs where RAG might still fall short, especially in complex, multi-step problem-solving scenarios common in ITSM. By utilizing KGs, systems can navigate through connected data points to extract and utilize information that is contextually relevant to the user’s specific needs.

Together, LLMs, RAG, and KGs form a strong combination for IT Service Management use cases. By leveraging LLMs for their powerful language understanding and generation capabilities, augmenting them with RAG for dynamic information retrieval, and incorporating KGs to provide deep, structured contextual insights, ITSM platforms can achieve unprecedented levels of automation, accuracy, and efficiency.

This blog aims to explore the benefits these technologies bring to ITSM.


Advanced AI in ITSM: how does it all work?
 

This image provides a simplified, hypothetical example of how Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), and Knowledge Graphs (KGs) can work together to enhance IT Service Management (ITSM)

The system extracts key information from a knowledge base and maps it onto a Knowledge Graph, which illustrates how various elements like the server, application, and related devices are interconnected.

This structured representation is stored in a database, and then converted into embeddings so it can be searched later on. An embedding model also helps to convert any other data from the knowledge base as well as the query into embedding format.

This format allows the system to search the Knowledge Graph and related databases for relevant context. The LLM then uses this context to generate a coherent and precise response.

This approach demonstrates how these technologies can complement each other: the Knowledge Graph provides structured context, RAG dynamically retrieves up-to-date data, and the LLM synthesizes this information into a useful, actionable insight.


Leveraging Retrieval Augmented Generation, LLMs and Knowledge Graphs in ITSM

The integration of advanced technologies such as Large Language Models (LLMs), Retrieval-Augmented Generation (RAG), and Knowledge Graphs (KGs) could potentially transform the IT landscape. These technologies can collectively enhance IT Operations Management, IT Service Management, and Artificial Intelligence for IT Operations (AIOps).

By implementing LLMs within ITSM frameworks, it is possible to provide instantaneous, context-aware responses to customer inquiries, which may help in reducing resolution times and improving customer satisfaction. For instance, LLMs can assist in automating ticket generation, categorization, and sentiment analysis, potentially prioritizing issues based on urgency to meet Service Level Agreement targets more consistently. Moreover, LLMs might serve as virtual assistants or chatbots, summarizing interactions which could enhance operational efficiency within ITSM frameworks.

Complementing these, RAG could improve the retrieval of pertinent information from expansive knowledge bases, thus enabling support teams to possibly identify and apply the most relevant solutions more effectively. Knowledge Graphs can also augment decision-making processes by providing structured visualizations of relationships among IT assets, incidents, and solutions. This clarity could help teams navigate complex scenarios and make more informed decisions, potentially simplifying the identification of recurring incidents.

Beyond customer support, LLMs, RAG, and KGs can also enhance other essential IT functions. They could refine recommender systems by delivering precise, context-sensitive suggestions based on both historical and real-time data analysis.

In the domain of AIOps, these technologies might play a role in failure management by analyzing logs, pinpointing root causes, and automating corrective actions, which could minimize downtime and improve system reliability. These potential benefits suggest a promising integration of AI technologies in ITSM.

The Future of LLMs in ITSM: Domain-Specific and Task-Specific Models

While general-purpose Large Language Models (LLMs) have proven effective in a wide range of applications, they can be limited and fall short in specialized domains like IT Service Management (ITSM). These models are typically trained on vast, diverse datasets, which may not include the deep, specific knowledge needed to navigate the unique challenges of ITSM effectively. This can result in less accurate responses, technical misinterpretations, or incomplete understanding of IT operations and protocols.

In contrast, domain-specific and task-specific LLMs can offer a significant advantage in ITSM applications. These models can be fine-tuned on datasets that are rich in ITSM-specific language and scenarios, enabling them to better understand and respond to the needs of the domain. For instance, a model trained specifically for ITSM is likely to better handle tasks like incident categorization and problem resolution.

Integrating these models with technologies like Retrieval-Augmented Generation (RAG) and Knowledge Graphs (KGs) can further enhance their effectiveness. Which can help in managing complex, multi-hop question-and- answer scenarios, where an answer requires combining information from multiple sources effectively.

Additionally, semantic search using embeddings which are used to match user queries to the most relevant information can sometimes miss the user’s true intent. As an example, if a user submits a ticket asking for help with a “server outage” but specifies “not related to network issues,” troubleshooting steps that focus on network-related problems might still be returned. A gap that perhaps domain-specific models with the help of knowledge graphs can be particularly well-suited to fill in the future.

These tailored LLMs, especially when enhanced with KGs and domain-specific embedding models, represent a promising future for AI in ITSM. At our AI lab, we are committed to pushing the boundaries of what’s possible in IT Service Management through advanced AI solutions.

We are currently focused on fine-tuning LLMs that offer robust multilingual capabilities specifically adapted to ITSM use cases. This ensures our models can handle diverse linguistic requirements while being deeply integrated into ITSM processes.

Additionally, we are developing multilingual embedding models fine-tuned for ITSM, which can be seamlessly incorporated into Retrieval-Augmented Generation (RAG), search functionalities, and the embedding of Knowledge Graphs.

By combining the strengths of LLMs with cutting-edge RAG techniques and the increasingly popular Knowledge Graphs, we are enhancing the knowledge base and response accuracy of our AI solutions. Looking ahead, we see great potential in multimodal RAG and RAG-optimized LLMs, which will further enhance AI’s ability to understand and generate meaningful responses in IT environments.

We invite you to explore our ongoing research and innovations, and to see firsthand how our tailored AI solutions can revolutionize your IT operations.

About EasyVista  
EasyVista is a leading IT software provider delivering comprehensive IT solutions, including service management, remote support, IT monitoring, and self-healing technologies. We empower companies to embrace a customer-focused, proactive, and predictive approach to IT service, support, and operations. EasyVista is dedicated to understanding and exceeding customer expectations, ensuring seamless and superior IT experiences. Today, EasyVista supports over 3,000 companies worldwide in accelerating digital transformation, enhancing employee productivity, reducing operating costs, and boosting satisfaction for both employees and customers across various industries, including financial services, healthcare, education, and manufacturing.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Cloudbric Managed Rules for IP Reputation Management

In establishing security through solutions such as firewalls, IP Reputation is a crucial metric for identifying and blocking malicious traffic. It assesses the risk of an IP using factors such as traffic volume, traffic type, presence of malware, and whether the IP has been involved in illegal activities like hacking or phishing. Managing IP Reputation is an important aspect of web security as traffic can be allowed or blocked based on the credibility of IPs, which is determined by their history.

Cloudbric Managed Rules for IP Reputation Management

Penta Security provides a solution for managing IP Reputation through “Cloudbric Managed Rules.”

🛡️ Malicious IP Protection

Cloudbric Managed Rules for AWS WAF – Malicious IP Protection was created to protect the websites and web applications against the traffic originating from various threat IPs. It utilizes the Threat DB of Cloudbric Labs, which collects and analyzes the threat intelligence from 700,000 websites in 148 countries to create a Malicious IP Reputation list and respond to the Malicious IP traffic.

🛡️ Anonymous IP Protection

Cloudbric Managed Rules for AWS WAF – Anonymous IP Protection provides integrated security against Anonymous IPs originating from various sources including VPNs, Data Centers, DNS Proxies, Tor Networks, Relays, and P2P Networks. It utilizes the Anonymous IP list, managed and updated by Cloudbric Labs, to detect and respond to Anonymous IPs that can easily be exploited for malicious purposes and prevent threats such as geo-location based fraud, DDoS, or license and copyright infringements.

 

Cloudbric Managed Rules for AWS WAF

Cloudbric Managed Rules for AWS WAF is created based on the security technologies and expertise of WAPPLES which has protected the web services for enterprises since 2005. Cloudbric Managed Rules have recently proven its performance by displaying a detection rate of 97.31% against other Managed Rules, which has been validated through a report (Penta Security Cloudbric Managed Rules – Comparative Effectiveness of the API Security-Related Managed Rule Groups for AWS WAF) published by an independent third-party IT testing, validation, and analysis organization, The Tolly Group.

✅ Expertise in Security

Cloudbric Managed Rules for AWS WAF utilizes the latest threat intelligence collected and analyzed by Penta Security’s own Cyber Threat Intelligence (CTI) to respond to web threats against web applications and APIs.

✅ Continuous Security Management

Cloudbric Managed Rules respond to the latest threats and maintain a stable level of security through continuous updates and management by security experts with over 20 years of experience in the field.

✅ Official Partner of AWS

Penta Security is an official launch partner for AWS WAF Ready, provider partner of AWS Activate, and AWS Public Sector Partner, and all Cloudbric products provided in AWS Marketplace by Penta Security have been validated by AWS through the Foundational Technical Review.

 

If you are looking to establish a safe web security environment without the need of security expertise, subscribe to Cloudbric Managed Rules for AWS WAF today!

👉 For more information
👉 To subscribe to Cloudbric Managed Rules

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Anonymous IP: Why You Should Block It and How.

AnonymousIP(1)

In February 2016, the global content streaming service, Netflix, officially announced that it would block all VPNs and proxy use on its platform. This decision came as a response to the abuse of Anonymous IPs, which had been a persistent issue for the service. Although many users would employ Anonymous IPs for privacy and security reasons, some exploited them for illegal purposes. One example was Netflix users using VPNs to bypass the geo-restrictions on contents that are not available in their region. The geo-restrictions were put in place due to licensing agreements, but users soon discovered that accessing the platform through an IP from another country allowed them to stream the geo-restricted content. As a result, Netflix was forced to address the issues related to license and copyright infringement.

 

Anonymous IP utilizes methods such as VPNs, Tor Nodes, Proxies, and Data Centers to mask the IPs and the geolocation to protect the privacy of the user and provide a secure access to the web. However, it is also a double-edged sword that can very well be used for illegal activities such as:

  • Manipulation of public opinion or reviews.
  • Distribution of malware while concealing the distributor’s identity.
  • Bypassing geo-pricing, which violates company policy.
  • License and copyright infringement.
    As such, detecting and blocking Anonymous IPs can be a smart move for companies and organizations of all industries to reduce the risk of cyber threats.
    Many companies and organizations already make use of various solutions to respond to Anonymous IPs. Like Netflix, a significant number of content streaming services and other companies in the media & entertainment industry have adopted Anonymous IP-related solutions to protect their media contents. Some companies use Anonymous IP-related solutions to prevent DDoS attacks carried out by zombie PCs infected via Data Centers. Online game companies block illegal access to geo-blocked servers, and finance companies, including cryptocurrency platforms, prevent fraud by blocking attempts to bypass the geolocation restrictions.
    Such solutions are largely categorized into two types: IP Reputation Database (often referred to as “IP Reputation Checkers”) and IP Reputation Filters. There are pros and cons to both types of solutions, and the choice between them depends on the available resources and the needs of the user.
    IP Reputation Database IP Reputation Filters
    • Focuses on providing detailed information about the IPs.
    • Such information includes the method of creating Anonymous IPs, geolocation data, and domain information.
    • The IP Reputation Database is constantly updated.
    • The user is given more flexibility as the user can utilize the information to configure the security settings as fit.
    • However, a deep understanding of security is required for the user to configure a robust security.
    • Because the IP Reputation Database is constantly updated, the user has to subscribe to the database service, and in many cases, the user may be charged per query.
    • Focuses on providing a proactive security solution by detecting and blocking the traffic based on the Anonymous IP list.
    • IP Reputation Filters are often included in a Web Application Firewall (WAF) solution, and do not provide as much flexibility as the users configuring the security settings themselves.
    • The performance of the IP Reputation Filter may depend on the source of the Anonymous IP list, update cycle, and the performance of WAF.
    • However, users do not need expert-level security knowledge.
    • Security measures can be quickly implemented.
    • Resources required in configuring the security settings are greatly reduced.
    •  
      • Penta Security’s direction in responding to Anonymous IPs is IP Reputation Filters. Penta Security currently provides a managed rule group, Cloudbric Managed Rules for AWS WAF – Anonymous IP Protection, in the AWS Marketplace.
    •  

    AnonymousIP(2)

    •  
      • Taking advantage of the characteristics of managed rule groups for AWS WAF, which enables the user to quickly adopt the security rules predefined by security vendors simply through subscribing to the product, Penta Security provides a quick and easy solution for AWS WAF users to detect and block any threats that can be caused by Anonymous IPs. Penta Security’s Cloudbric Managed Rules for AWS WAF – Anonymous IP Protection is defined based on the Anonymous IP List, which is continuously updated with the latest IP Reputation data, collected and analyzed by Penta Security’s own Cyber Threat Intelligence (CTI). With a cost efficient, pay-as-you-go pricing, users are able to implement a robust security solution against Anonymous IPs without the need for security expertise by subscribing to the product.
    •  
      • Cloudbric Managed Rules for AWS WAF – Anonymous IP Protection is available at

    👉link.

     

     

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

APIs are Everywhere. Are You Protected from API Attacks?

 

API security has become a major focus in cybersecurity in recent years. The global research firm, Gartner recognized the importance of API security and proposed a new model of web application security, which they named Web Application and API Security (WAAP). API, which stands for Application Programming Interface, is a mechanism that enables two software components to communicate with each other using a set of definitions and protocols. APIs are generally used to provide access to data and services, allowing the developers to build new applications and tools by leveraging existing data and functionality.

For instance, if a new food delivery app requires a map to display local restaurants, it would be inefficient for the developers to create a new map and gather all the restaurant data themselves. Instead, they could use an existing map API, such as Google Maps, to retrieve the necessary data for their app.

APIs are becoming indispensable in modern software development because of its;

  • Interoperability
    • APIs facilitate interoperability between software systems, and by using APIs, applications and services developed by different developers would work together, share data, and provide integrated solutions
  • Modular Development
    • APIs allow complex systems to be divided into smaller and more manageable components, making software development, testing, and maintenance easier. Developers can focus on building and updating specific functionalities.
  • Cross-Platform Integration
    • APIs enable cross-platform integration, allowing applications to work across different devices and environments.
  • Data Access and Sharing
    • APIs define a structured way for data to be exchanged between applications, usually formatted in JavaScript Object Notation (JSON) or Extensible Markup Language (XML). This standardization ensures that both the requesting application and the providing system can easily interpret and process the data.

Despite their benefits, not all APIs are built with security measures, and an increasing number of organizations have reported attacks targeting APIs, resulting in significant damage to their services. Such was the case with Duolingo. Duolingo is a company that services a vastly popular language learning application. It is estimated that by the end of Q1 2022, Duolingo’s monthly active users reached 49.2 million. Naturally, due to its massive volume of user data, Duolingo’s user database became a target for hackers. In January 2023, scraped data of 2.6 million Duolingo users appeared on the dark web hacking forum called “Breached.” The scraped data included email addresses, personal names, usernames, and other user profile information.

screenshot courtesy of FalconFeedsio

It is believed that the hacker acquired the user data by infiltrating Duolingo’s API vulnerability. Duolingo’s API provided access to user information based solely on email or username without asking for any other forms of verification. The API did not take any security measures to ensure that the requests were coming from legitimate users, thus the access to user data was not restricted. This incident would be categorized under two vulnerabilities of OWASP Top 10 API Security Risks: 

  • API2:2023 – Broken Authentication
  • API3:2023 – Broken Object Property Level Authorization (BOLA) 

As API has become a target for hackers, establishing API security became an important task for any organizations or businesses providing services that include APIs. There are already numerous solutions for API security in the market, but the important question to ask is: which of the solutions best fit my environment?

As there are a myriad of APIs for different purposes, solutions for API security can also take many different directions and approaches. For instance, some may focus on specific vulnerabilities of APIs, such as Injection attacks or Broken Authentication, while some may focus more on API Discovery. Some may even choose to focus more towards API Gateway. There is no definitive answer to what type of solution is best. Therefore, it is important that organizations and businesses carefully assess their environment and needs before adopting a solution.

Penta Security’s direction in establishing API security was to build a solution that focuses on the actual API attacks and vulnerabilities. Penta Security has recently launched a managed rule group for AWS WAF, Cloudbric Managed Rules for AWS WAF – API Protection (API Protection). Taking advantage of the characteristics of managed rule groups for AWS WAF, which enables the user to quickly adopt the security rules predefined by security vendors simply through subscribing to the product, Penta Security provides a quick and easy solution for AWS WAF users to detect and block API attacks. API Protection was created to provide security against the threats of OWASP API Security Top 10 Risk. To respond to the attacks and vulnerabilities of API, API Protection utilizes the API attack data gathered and analyzed by Penta Security’s own cyber threat intelligence (CTI) and establishes security against known API attacks. Furthermore, API Protection provides validation and protection for XML, JSON, and YAML data. API Protection was recently validated to have the highest detection rate among API Security managed rule groups currently provided in AWS Marketplace through a comparative test conducted by a third-party IT testing, validation and analysis company, The Tolly Group.

The Tolly Group – 3rd-party IT Testing, Validation, & Analysis

With a cost efficient, pay-as-you-go pricing, users are able to implement a robust API security without the need for security expertise, just by subscribing to the product.

Cloudbric Managed Rules for AWS WAF – API Protection is available at 👉link.

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.