RESTGuardian: a system for controlling personal and sensitive data in REST API responses

Vol 56, 2024 - 308931
Complete Articles (CA)
Favorite this paper
How to cite this paper?
Abstract

Nowadays is essential to protect personal and sensitive data to ensure compliance with regulations such as the LGPD (Brazilian General Data Protection Law Number 13.709/2018) and the GDPR (General Data Protection Regulation Number 2016/679 EU). This paper presents the development of RESTGuardian, a controller for personal and sensitive data in responses from REST (Representational State Transfer) APIs (Application Programming Interfaces). RESTGuardian acts as a security middleware between the frontend and backend of a web or mobile application. It aims to alert developers so they do not create insecure APIs and can mitigate the risk of Excessive Data Exposure, as reported by the OWASP (Open Web Application Security Project). Additionally, it serves as a tool for Data Protection Officers (DPOs), offering a view of REST APIs in the development environment, focusing on LGPD compliance to prevent the deployment of insecure APIs in production. 

Share your ideas or questions with the authors!

Did you know that the greatest stimulus in scientific and cultural development is curiosity? Leave your questions or suggestions to the author!

Sign in to interact

Have a question or suggestion? Share your feedback with the authors!

Institutions
  • 1 UNIFEI
  • 2 UFMS
  • 3 Universidade Federal da Bahia
  • 4 Universidade Federal de Itajubá (UNIFEI)
Track
  • 6. D&SP – OR in Defense and Public Security
Keywords
Privacy
Data Protection Officers
Middleware