Blockchain-based WAAP / API level management security system and method

The blockchain-based WAAP system addresses the challenge of comprehensive API protection by managing API lifecycles and WAAP reliability, ensuring secure and dynamic management, thereby enhancing user trust and web environment security.

JP2026049638APending Publication Date: 2026-03-18PENTA SECURITY SYST INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025094236
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-09-06
Filing Date
2025-06-05
Publication Date
2026-03-18

AI Technical Summary

Technical Problem

Existing integrated web security solutions struggle to comprehensively protect APIs against various attacks, such as hacking and data theft, and lack a robust management system for ensuring API reliability and trust in the security ecosystem.

Method used

A blockchain-based security system that integrates WAAP (Web Application and API Protection) with blockchain technology to manage API lifecycles, ensuring API and WAAP reliability through distributed synchronization and integrity assurance, enabling dynamic management policies and continuous updating.

Benefits of technology

The system provides reliable API management, WAAP management, and authenticated API usage by leveraging blockchain technology for secure and dynamic policy assignment, enhancing user confidence and overall web environment protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026049638000001_ABST
    Figure 2026049638000001_ABST
Patent Text Reader

Abstract

This provides a blockchain-based security system and method that can defend against a variety of attacks on public and private networks by assigning a lifecycle to APIs and managing WAAP / API levels using a cloud-based integrated web security solution (WAAP). [Solution] The security method includes a step S550 in which WAAP receives an API security rating confirmation request from the blockchain while a session is established between the user and the blockchain, a step S560 in which the API security rating is confirmed, and a step S580 in which the blockchain transmits confirmation information regarding the API security rating to the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0002] , ,

[0005] ,

[0004] , , , , ,

[0003]

[0001] The present disclosure relates to a blockchain-based security system and method that can defend against various attacks on public or private networks by assigning a life cycle to an API (application programming interface) in an integrated web security solution such as WAAP (web application and API protection) on a cloud platform and managing the WAAP / API level.

Background Art

[0002] Recently, social activities and economic activities through online channels such as the Internet have been active. Therefore, the importance of security for APIs (application programming interfaces), which are widely used for communication between online terminals, has been increasing.

[0003] An API is a set of definitions and protocols for constructing and integrating application software. By using an API, it is possible to assist products and services of terminals to communicate with each other without the need for terminals such as clients and servers to build a connection infrastructure. For example, in API communication, a client transmits a key value for connecting to data to a server, and if the key values match, the server can transmit the data to the client.

[0004] On the other hand, as the use of APIs expands, hacking and security incidents against personal data such as credit information data, personal information such as login information, and open data such as weather, bus information, and medical information are also increasing. For example, security incidents due to API attacks such as damaging user authentication or keys to obtain information, intentionally allocating a large amount of system resources, or stealing response data midway are increasing.

[0005] To prevent such security incidents, individuals and businesses must implement security solutions for their networks connected to the internet and other networks. However, implementing such single-function solutions can be burdensome. Therefore, considering cost issues and other factors, there is a growing demand for integrated web security solutions that can comprehensively protect the web environment.

[0006] In particular, recent integrated web security solutions have evolved to include not only existing web firewall functions but also API protection, bot mitigation, and DDoS (Digital Dosith) protection. In this context, there is a growing demand for integrated web security solutions that meet OWASP's Top 10 API security requirements. [Overview of the project] [Problems that the invention aims to solve]

[0007] This disclosure was derived to meet the requirements of the aforementioned prior art, and its purpose is to provide an integrated web security solution that combines existing web firewall functionality with API (application programming interface) security functionality.

[0008] In other words, the purpose of this disclosure is to provide an API reliability assurance security system and method that utilizes blockchain distributed synchronization technology to generate an API lifecycle and constitutes a WAAP (web application and API protection) ecosystem, along with blockchain integrity assurance technology.

[0009] Another objective of this disclosure is to provide a security system and method that, by grafting blockchain technology into an integrated web security solution, can establish a management ecosystem not only for the APIs being secured but also for the integrated web security solution WAAP itself, thereby ensuring trust in the security solution.

[0010] In other words, another purpose of this disclosure is to provide a security system and method based on WAAP target verification and management technology that leverages the distributed synchronization technology inherent to blockchain. [Means for solving the problem]

[0011] A security method relating to one aspect of this disclosure for solving the aforementioned technical problems is a blockchain-based security method that is executed by an integrated web security solution (web application and API protection, WAAP) and utilizes WAAP and API (application programming interface) level management, and includes the steps of: receiving an API security level confirmation request from the blockchain to a Level 1 WAAP under the establishment of a session between WAAP and the blockchain; confirming the API security level; and transmitting information regarding the API security level to the blockchain.

[0012] The step of verifying the API security rating includes verifying the security rating of the API itself in relation to the vulnerability of the API within the WAAP management API data, which is the most stable level (e.g., Level 1).

[0013] The WAAP may have the highest security rating (e.g., Level 1) indicating the most secure WAAP. The blockchain may store the WAAP identification information of the WAAP and a list of APIs with the highest security rating (e.g., Security Level 1) registered with the WAAP. This may mean that the blockchain completes synchronization between the WAAP and the blockchain, targeting the API list with the highest security level (e.g., Security Level 1).

[0014] The security method may further include the step of receiving API sample code for WAAP vulnerability testing from the blockchain. The API sample code is malicious sample code.

[0015] The security method may further include a step of calculating a security rating for the WAAP vulnerability testing API sample code.

[0016] The security method may further include the step of transmitting information regarding the API security rating status, including the calculated security rating, to the blockchain.

[0017] Based on the information regarding the API security rating status, the blockchain can classify a WAAP that has been assigned the highest level of security rating to the WAAP vulnerability test API sample code as a vulnerable WAAP and downgrade its level.

[0018] Based on the information regarding the API security rating status, the blockchain can classify a WAAP that has been assigned the lowest level of security rating to the WAAP vulnerability test API sample code as a stable WAAP and upgrade its level.

[0019] The security method may further include the steps of requesting the blockchain to test the WAAP, receiving a request from the blockchain to verify the API sample code security rating, and transmitting API security rating status information, including verification information for the API security rating, to the blockchain.

[0020] A security method relating to another aspect of this disclosure for solving the aforementioned technical problems is a blockchain-based security method that is executed by an integrated web security solution (web application and API protection, WAAP) and utilizes WAAP and API (application programming interface) level management, and includes the steps of: requesting a WAAP test from the blockchain through a session established between the blockchain and WAAP; receiving a request from the blockchain for confirmation of the API sample code security rating; performing a proprietary vulnerability test on the API sample code received from the blockchain; calculating the API security rating after performing the vulnerability test; and transmitting API security rating status information, including confirmation information for the API security rating, to the blockchain.

[0021] The aforementioned API security rating status information includes the results of WAAP performing its own vulnerability tests on the API sample code received from the blockchain and calculating the security rating.

[0022] The security method may further include a step of automatically, autonomously, or independently upgrading the functionality of the WAAP with administrator privileges of the WAAP before requesting testing of the WAAP.

[0023] Based on the information regarding the API security rating status, the blockchain can classify a WAAP that has been calculated to have the highest security rating for the WAAP vulnerability test API sample code as a vulnerable WAAP and downgrade its level. Conversely, based on the information regarding the API security rating status, the blockchain can classify a WAAP that has been calculated to have the lowest security rating for the WAAP vulnerability test API sample code as a stable WAAP and upgrade its level.

[0024] The security method may further include a step of re-requesting the blockchain for a WAAP level test to upgrade the WAAP level in order to restore the downgraded WAAP level of the WAAP administrator privileges, after going through a WAAP level adjustment step based on the results of the WAAP test.

[0025] Based on the API security rating calculation results of WAAP obtained by re-requesting the WAAP level test, the blockchain can classify WAAPs whose API sample code for WAAP vulnerability testing has been calculated to the highest level as vulnerable WAAPs and downgrade their level, and based on the information regarding the API security rating status, the blockchain can classify WAAPs whose API sample code for WAAP vulnerability testing has been calculated to the lowest level as stable WAAPs and upgrade their level.

[0026] A security system according to still another aspect of the present disclosure for solving the above technical problems is a blockchain-based security system that utilizes an integrated web security solution (web application and API protection, WAAP) and API (application programming interface) level management, and includes a memory and at least one processor that executes a program including at least one instruction connected to the memory. By the at least one instruction, the processor, under the establishment of a session with the blockchain, causes the WAAP to receive a request for API security level confirmation from the blockchain, confirm the API security level, and transmit confirmation information regarding the API security level to the blockchain.

[0027] The WAAP can have a level 1 rating indicating the most secure WAAP in terms of security. The blockchain can store the WAAP identification information of the WAAP and a list of APIs with security level 1 registered in the WAAP. Thereby, the blockchain can complete synchronization between the corresponding WAAP and the blockchain for the list of APIs with the highest security level of security.

[0028] The processor can further execute receiving API sample code for WAAP vulnerability testing from the blockchain, calculating a security level for the API sample code for WAAP vulnerability testing, and transmitting information regarding an API security level state including the calculated security level to the blockchain.

[0029] The blockchain can classify the WAAP into a WAAP vulnerable to security by calculating the security level of the API sample code for WAAP vulnerability testing to the highest level based on the information on the API security level status, and can downgrade its level. Also, the blockchain can classify the WAAP with the security level of the API sample code for WAAP vulnerability testing calculated to the lowest level into a stable WAAP based on the information on the API security level status, and can upgrade its level.

[0030] The processor can further request the blockchain to test the WAAP, receive a request for confirmation of the API sample code security level from the blockchain, and transmit API security level status information including confirmation information for the API security level to the blockchain.

[0031] After the WAAP level adjustment stage based on the WAAP test result, before requesting a WAAP level test for level repair, the processor can further perform a unique update of the WAAP with the administrator authority of the WAAP.

[0032] Before requesting the blockchain to test the WAAP, or before requesting a retest for correcting the WAAP level due to a downgrade adjustment of the WAAP level based on the previous test result, the processor can further perform a unique upgrade of the WAAP function using the administrator authority of the WAAP.

Advantages of the Invention

[0033] According to the present disclosure, it is possible to have features in API security through the construction of an API management system based on the "decentralized synchronization" technology, which is a unique characteristic technology of the blockchain, and a management system of WAAP, which is an integrated web security solution. It is possible to solve the technical problem of providing users with the use of a safe API through ensuring API reliability based on the "integrity guarantee" technology, which is another unique characteristic technology of the blockchain.

[0034] Furthermore, according to this disclosure, the blockchain-based WAAP / API level management integrated security system can be broadly divided into three parts: "API management effect," "WAAP management effect," and "authenticated API usage effect," all of which utilize blockchain technology.

[0035] Specifically, "API management" utilizing blockchain technology refers to a technique in which WAAP calculates API levels from the most secure level 1 to the most vulnerable level 3 for each API, and then stores and manages the corresponding security level and other API information on the blockchain. With this blockchain-based "API management" technique, the security level and information of an API can be shared among all nodes in the blockchain network, thus enabling the management effect of information sharing based on blockchain's distributed storage technology. Furthermore, because the security level and other information of the corresponding API registered on the blockchain cannot be altered, it is possible to achieve reliable API management effects based on blockchain's data integrity assurance technology.

[0036] Furthermore, "WAAP management" utilizing blockchain technology refers to a technique that involves conducting WAAP function tests on all WAAPs linked to the blockchain network, calculating WAAP levels from the most stable level 1 to the most unsafe level 3, and then recording and managing the WAAP ID and WAAP level of the tested WAAPs on the blockchain. This technique utilizes the blockchain's inherent characteristic of "distributed synchronization" technology, and can be carried out by recording a WAAP function test sample code on the blockchain, propagating the code to all interconnected WAAPs, and then checking the response values. According to this blockchain-based "WAAP management" technique, it is possible to derive the management effect of continuously updating and improving WAAP, which is an API verification solution, and ultimately improve user confidence, thereby leading to a WAAP management effect that increases user satisfaction.

[0037] As mentioned above, according to this disclosure, by leveraging the distinctive blockchain technologies of "distributed data synchronization" and "ensuring data integrity to prevent forgery and alteration," the integrated security solution systematically performs the functions of "API management" and "WAAP management," ultimately guaranteeing users the use of secure and authenticated APIs. In other words, according to this disclosure, it is possible to provide the "effect of authenticated API usage."

[0038] Furthermore, the unique and distinctive feature of the security technology disclosed in this disclosure lies in its dynamic rather than static establishment of API and WAAP management policies. This involves not statically establishing API and WAAP management policies for each individual piece of equipment, but rather using blockchain to configure a network of integrated web security solutions and assigning a "life cycle" to API and WAAP management. This configuration allows for the provision of an integrated web security solution with the ability to protect the overall web environment. In other words, it provides WAAP (web application and API protection) with additional functions such as API protection, bot mitigation, and DDoS protection, in addition to web security. Furthermore, according to this disclosure, WAAP can be used to effectively manage not only API security but also the overall infrastructure and web services. [Brief explanation of the drawing]

[0039] [Figure 1] This is an illustrative diagram illustrating API (application programming interface) communication that can be used in a method according to one embodiment of the present invention. [Figure 2] This is a schematic conceptual diagram of a WAAP-based security system for client API security according to one embodiment of the present invention. [Figure 3]Figure 2 is an illustrative diagram illustrating the main features of WAAP. [Figure 4] This is an illustrative diagram illustrating an API lifecycle that can be used in a security method according to one embodiment of the present invention. [Figure 5] This is a flowchart illustrating the API blockchain registration verification and registration process that can be adopted in one embodiment of the security method described herein. [Figure 6] This is a flowchart illustrating the WAAP vulnerability discovery and updating process that can be adopted in one embodiment of the security method described herein. [Figure 7] This is a flowchart illustrating the level repair and re-rating request process after a WAAP update, which can be used in a security method according to one embodiment of the present invention. [Figure 8] This is a schematic block diagram of the configuration of a security system according to yet another embodiment of the present invention. [Figure 9] Figure 8 is a schematic block diagram of the main components of WAAP that can be used in the security system. [Figure 10] Figure 8 is a schematic block diagram of the main configuration of WAAP in administrator mode that can be used in the security system. [Figure 11] This is a block diagram illustrating a software module that can be used in a security system according to yet another embodiment of the present disclosure. [Modes for carrying out the invention]

[0040] While the present invention can be modified in various ways and has a variety of embodiments, specific embodiments will be illustrated in detail in the drawings. However, this should not be understood as limiting the present invention to specific embodiments, but rather as including all modifications, equivalents, or substitutes that fall within the spirit and technical scope of the present invention.

[0041] The terms "first," "second," etc., may be used to describe a variety of components, but the components should not be limited by such terms. The terms are used solely for the purpose of distinguishing one component from another. For example, without departing from the scope of the invention, the first component may be named the second component, and similarly, the second component may be named the first component. The terms "and / or" include a combination of multiple related listed items or any of the multiple related listed items.

[0042] In the embodiments of this application, "at least one of A and B" may mean "at least one of A or B" or "at least one of one or more combinations of A and B". Also, in the embodiments of this application, "one or more of A and B" may mean "one or more of A or B" or "one or more of one or more combinations of A and B".

[0043] When it is stated that one component is "connected" or "linked" to another component, it should be understood that it may be directly connected to or linked to the other component, but that other components may exist in between. Conversely, when it is stated that one component is "directly connected" or "directly linked" to another component, it should be understood that there are no other components in between.

[0044] The terms used in this application are used solely to describe specific embodiments and are not intended to limit the invention. Singular expressions include plural expressions unless the context clearly indicates otherwise. In this application, terms such as “includes” or “having” are intended to specify the existence of features, figures, stages, operations, components, parts, or combinations thereof described in the specification, and should be understood not to preemptively exclude the possibility of the existence or addition of one or more other features, figures, stages, operations, components, parts, or combinations thereof.

[0045] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as those generally understood by a person of ordinary skill in the art to which this invention pertains. Terms as defined in commonly used dictionaries should be interpreted as having the meaning consistent with their meaning in the context of the relevant art, and not as ideal or overly formal unless expressly defined herein.

[0046] The following describes preferred embodiments of the present invention in more detail with reference to the attached drawings. In describing the present invention, the same reference numerals are used for identical components in the drawings to facilitate overall understanding, and redundant descriptions of identical components are omitted.

[0047] Figure 1 is an illustrative diagram illustrating API (application programming interface) communication that can be used in a method according to one embodiment of the present invention.

[0048] Referring to Figure 1, in API communication, client 10 establishes a connection session with server 100 and transmits a key value to server 100 for connecting to specific data. If the key value matches, server 100 can transmit the data to client 10.

[0049] On the other hand, various attacks can occur through API communication as described above, carried out by malicious users such as hackers. A detailed examination of the main vulnerabilities in API communication reveals the following:

[0050] First, client 10 can transmit an API key that does not conform to the format to server 100. In this case, various problems can occur if server 100 does not go through the proper verification process. Specifically, vulnerabilities such as ignoring the API format and null character insertion attacks may occur. Here, "ignoring the API format" means a situation where, if the API key is specified to conform to a specific format such as a certain length and combination of characters, server 100 does not properly verify this and arbitrary data is registered as the API key. Also, "null character insertion attack" means a situation where server 100 is unable to properly handle null characters in the API verification process, and an attacker transmits a key containing null characters to bypass the key verification logic.

[0051] Furthermore, client 10 may possess a hardcoded API key. Hardcoded encryption keys have a security weakness: the encryption key is directly stored within the source code and may be exposed along with the source code if the source code is leaked, and key changes that need to be adapted to the environment are not easy to perform. In other words, using an encryption key hardcoded within the source code makes it vulnerable to indiscriminate assignment (brute-force) attacks, and it becomes possible to reverse-calculate some hash functions that are hardcoded in the form of constants, potentially leading to the leakage of encrypted information.

[0052] Furthermore, there is a vulnerability that could include a flaw in the API format on server 100. The API format can include the API message format, and the API message format can use UTF-8 encoding with the JSON (JavaScript Object Notation) method. JSON can mean an open standard message format that represents data objects in attribute and value format, i.e., key-value format, for sending and receiving messages of small size. UTF-8 is a standard encoding method that extends ASCII code to represent all character codes worldwide. If server 100 cannot properly process the UTF-8 encoding during the API communication process, a security vulnerability may occur caused by garbled characters. The "garbled character vulnerability" refers to a vulnerability where, if client 10 transmits data through an incorrect UTF-8 encoding and server 100 is unable to process the data correctly, resulting in data corruption, the garbled characters can disrupt the system and potentially lead to a buffer overflow attack.

[0053] Additionally, during the API call process in which client 10 transmits an API key value to server 100 to receive data from server 100, traffic hijacking may occur through a man-in-the-middle attack (MITM), address resolution protocol (ARP) spoofing, or DNS (domain name system) spoofing from a spoofed server or client. In other words, traffic can be hijacked during the API call process in which the client transmits an API key value to the server to receive data from the server.

[0054] To defend against attacks occurring at the aforementioned major API vulnerability points, it is preferable to store encryption keys encrypted in an external space or file. Furthermore, it is preferable to manage encryption keys using encryption codes generated based on a seed and initialization vector extracted from a random function, for example. As a random function, a secure random function can be used, for example, one that can be obtained through the .NET RNGCryptoServiceProvider class, which generates any cryptographically secure number.

[0055] However, since the aforementioned API protection measures are implemented over API communication in a web environment, security vulnerabilities that occur in the web environment can occur in the same way as API vulnerabilities.

[0056] For example, the items in the OWASP Web Security Top 10 are listed in Table 1 below.

[0057] [Table 1]

[0058] Furthermore, the OWASP API Security Top 10 items and their explanations are shown in Table 2 below.

[0059] [Table 2] JPEG2026049638000004.jpg83162

[0060] To give an example of how security vulnerabilities occurring in a web environment can occur in the same way as API vulnerabilities, items A03, A05, and A09 in the OWASP Web Security Top 10 shown in Table 1 are the same as items A07, A08, and A10 in the OWASP API Security Top 10 shown in Table 2, and items A01, A07, and A08 in the OWASP Web Security Top 10 are similar to items A02, A05, and A09 in the OWASP API Security Top 10.

[0061] Figure 2 is a schematic conceptual diagram of a WAAP-based security system for client API security according to one embodiment of the present invention.

[0062] Referring to Figure 2, the WAAP infrastructure security system (hereinafter simply referred to as the "security system") includes the WAAP300, API server 510, and API DB530.

[0063] WAAP300 is a type of integrated web security solution configured to perform web application security and API security. WAAP300 can include a service provider and hash verification tools. Furthermore, WAAP300 can be configured to include web firewall (WAF), API security, bot mitigation, and DDoS protection functions. Such a detailed explanation of WAAP300 is provided in the detailed description below, referring to Figure 3, etc., so a detailed explanation is omitted here to avoid redundancy.

[0064] API server 510 may refer to a server in API communication that responds to API requests. Such an API server 510 may refer to a service API server on a client private network or internal network.

[0065] API DB530 can refer to an off-chain database (DB) that stores and manages APIs. Such an API DB530 may refer to an internal API management database within a client's internal network.

[0066] The aforementioned security system includes WAAP300, a cloud-based platform specifically for service APIs, and can be configured to provide a life cycle to APIs using WAAP300.

[0067] Additionally, the security system can migrate API information from the API server 510 to the API DB 530 for client internal network security and security rating calculation for APIs. The security system can also migrate API information from the API server 510 to the WAAP 300. Furthermore, the security system can tag at least one API received from the API server 510 with an API ID in the WAAP 300 and then store the API hash value. The security system can also perform security verification of an API received from the service server (i.e., API server) of a service provider client (i.e., the service provider) if the service user outside the client requests such verification from the WAAP 300.

[0068] Thus, the security system according to this embodiment can design a WAAP ecosystem that can defend against various attacks by assigning a lifecycle to the API. Furthermore, the security system can perform client internal network security through API registration and hash value verification processes for client API security. Moreover, the security system can calculate a security rating for the API based on the verification results of the API registration and hash value verification processes, and by periodically applying this rating, it can maintain client internal network security in an even more reliable manner.

[0069] Figure 3 is an illustrative diagram illustrating the main features of WAAP shown in Figure 2.

[0070] Referring to Figure 3, WAAP300 can be described as an evolved web application firewall (WAF), representing a security solution that includes additional web security features in addition to the basic web application firewall function 310. In other words, WAAP300 can possess four core functions: WAF310, API protection320, bot mitigation330, and DDoS protection340.

[0071] To explain each function in more detail, the WAF function can include detecting and blocking web attacks such as SQL (structured query language) injection and cross-site scripting (XSS). The WAF function can monitor all HTTP / HTTPS protocol traffic transmitted to the web server and inspect the URL of the user of the request packet to prevent unintended content from being transmitted to the web application. In addition, the WAF function can apply the principle of a proxy server to monitor the content of HTTP reply packets passing through the web server to prevent the leakage of specific information.

[0072] API protection can mean protecting APIs from misuse, malicious bot attacks, and other cybersecurity threats. In particular, API protection can be extended by the evolution of API security. Specifically, as APIs expand with the advent of microservices architectures leveraging the Internet of Things (IoT) and cloud-native technologies, smoother communication and call routing become possible between applications and across the entire DevOps environment. High-quality APIs such as Representational State Transfer (REST) ​​and Simple Object Access Protocol (SOAP) coordinate application integrations, specify data formats, and dictate call types, procedures, and rules. Furthermore, web APIs such as GraphQL, REST APIs, and SOAP APIs are transforming the environment by extending their capabilities to include a wide range of integration functions across a vast and complex network. However, because these modern APIs heavily rely on API endpoints to embody their functionality, enterprises and security teams must adopt robust security measures to protect data and web services and ultimately maximize the use of IT resources. Therefore, this embodiment provides a method for adding a lifecycle to an API, which can be adopted as one of the robust security measures.

[0073] Bot mitigation functionality may include blocking a bot request from an external client (where the client is a bot) by having the integrated web security system transmit a confirmation message for the request, and then verifying that an abnormal response to the confirmation message is received from the client or that the response is received from an abnormal IP address.

[0074] Distributed Denial of Service (DDoS) protection features may include the integrated web security system detecting and blocking denial-of-service (DoS) attacks at the application layer, such as a large number of unfulfilled messages, when the number of unfulfilled messages exceeds a certain limit within a unit of time.

[0075] The aforementioned security system can also be configured to automatically recognize problems that occur during system operation through its self-checking function and transmit real-time alarms to the administrator. To this end, the security system can be configured to self-diagnose resource status, network status, and hardware status, recognize dangerous situations such as security hazards, transmit alarms to the administrator, and execute automatic recovery functions based on the self-diagnostic items and the resulting settings.

[0076] Figure 4 is an illustrative diagram illustrating an API lifecycle that can be adopted in a security method according to one embodiment of the present invention.

[0077] Referring to Figure 4, the API lifecycle can be configured to cycle through the processes of Design, Manage, Monitor, Deploy, and Assess.

[0078] Design refers to calculating the safety rating of an API and classifying and designing the API's level.

[0079] "Manage" means registering and managing API-related information and security ratings in an off-chain API database and on-chain blockchain. Here, "on-chain" refers to a method of recording all transaction details that occur on the blockchain (On), while "off-chain" refers to a method of recording transaction details that occur on the blockchain outside the blockchain network (Off). Monitoring refers to the process of verifying the integrity and visibility of data regarding API information and security ratings registered on the blockchain.

[0080] Deployment refers to the process of distributing and storing newly registered API information and security rating data on the blockchain network in an on-chain manner.

[0081] Assessment refers to the process by which clients within the interconnected network evaluate an API based on API information and security rating data posted on-chain on the blockchain.

[0082] Table 3 illustrates the API levels and their characteristics in terms of web security when using the aforementioned APIs.

[0083] [Table 3]

[0084] Furthermore, the levels and characteristics of WAAP (web application and API protection), a type of integrated web security solution for API protection and web application security functions mentioned above, are illustrated in Table 4 below.

[0085] [Table 4]

[0086] Thus, it is possible to implement API security using an integrated web security solution. In particular, the security system in this embodiment performs the basic functions of a web firewall (WAF) while also enabling bot detection and DDoS protection, and embodies technology that allows for dynamic management of APIs.

[0087] For example, in the case of bot detection and blocking, when a data request is received from an external client (where the client is a bot), the integrated web security system transmits a confirmation message in response to the request. The system can then confirm that the client has received an abnormal response to the confirmation message or a response from an abnormal IP address, allowing the client to block the request.

[0088] Furthermore, in the case of DDoS protection, when the number of incomplete messages exceeds a certain number within a unit of time, the integrated web security system may be configured to detect and block denial-of-service (DoS) attacks or distributed denial-of-service (DDoS) attacks at the application layer, such as attacks involving a large number of incomplete messages.

[0089] Furthermore, the integrated web security system of this embodiment can be configured to automatically recognize problems that occur during system operation using a self-checking function and to transmit information and alarms regarding the recognized problems in real time to the administrator and / or the linked blockchain network.

[0090] To this end, an integrated web security system can be configured to self-diagnose resource status, network status, and hardware status, recognize risk situations such as security vulnerabilities, transmit alarms to administrators and / or blockchain networks, and activate automatic recovery functions based on self-diagnostic items and the resulting settings.

[0091] Figure 5 is a flowchart illustrating the API blockchain registration verification and registration process that can be adopted in one embodiment of the security method of this disclosure.

[0092] Referring to Figure 5, the user can perform the TLS handshake procedure with respect to the blockchain and the transport layer security (TLS) protocol (S510). The TLS handshake can signify the establishment of a session for communication between the user and the blockchain.

[0093] Here, the user includes a user device connected to the internet, and the blockchain may include a blockchain network consisting of multiple nodes connected to the internet. Such a blockchain may be embodied to store and compare WAAP (web application and API protection) identification information, WAAP level information, and API level information. For example, the blockchain may be configured to store and compare data or information through smart contracts, etc. WAAP identification information may be represented by a WAAP ID, and API level information may include level information for API security.

[0094] As mentioned above, WAAP is a type of integrated web security solution that is an evolved form of web application firewall (WAF). Its core features include a web firewall function, which is a basic function for web security, and additional functions for web security, such as API protection, bot mitigation, and DDoS (Deadly DoS) protection.

[0095] Next, the user can check whether the API is registered on the blockchain (S520). In other words, the user can send a confirmation request message to the blockchain to check whether specific API information is registered on the blockchain.

[0096] Next, the blockchain can determine whether the API requested by a user is registered on the blockchain based on the user's API registration confirmation request (S530). For example, the blockchain can determine whether one of the following three conditions is met based on the user's API registration confirmation request. Specifically, the blockchain can determine if the API is not registered on the blockchain (non-registration), if the API information is registered on the blockchain but the registered API safety level is 3, or if the safety level of the API registered on the blockchain is 1 or 2, but the level of WAAP, an integrated web security solution that calculates the safety level of the API, is 3.

[0097] The conditions for requesting confirmation of whether or not blockchain APIs are registered for such API information are as follows:

[0098] [Conditions for requesting confirmation of API registration status]

number

[0099] In accordance with the above conditions, Level 1 WAAP and API security verification can be performed in the following cases: "If API information is not registered on the blockchain", "If WAAP information is registered on the blockchain, but the API security level is 3", or "If the security level of the API registered on the blockchain is 1 or 2, but the security level determination WAAP level is 3".

[0100] Next, for API security verification, the blockchain can first perform a Level 1 WAAP and TLS handshake procedure. That is, a Level 1 WAAP can perform a TLS handshake procedure with the blockchain (S540). Such a TLS handshake can signify the establishment of a session for communication between the blockchain and the Level 1 WAAP. A TLS handshake can be broadly referred to as a security handshake. And a Level 1 WAAP can signify a Level 1 security WAAP.

[0101] After a session is established between the blockchain and a Level 1 WAAP, the blockchain can request the WAAP to verify the API security level. In other words, the WAAP can receive a request from the blockchain for API security verification (S550).

[0102] Requests for API security verification may include information related to the user in question, such as user identification information, API identification information, API configuration information, API settings information, API inventory information, and API usage information.

[0103] Next, a Level 1 WAAP can perform API safety verification through pre-configured procedures or verification modules and models that execute such procedures, at the request of the blockchain, and transmit the verification results for the API safety status to the blockchain. In other words, the blockchain can receive the verification results for the API safety status from the WAAP (S560). The verification results for the API safety status may include information such as the API safety rating.

[0104] Next, the blockchain can store WAAP identification information (ID, e.g., α), WAAP level information (e.g., level 1), and API security rating information (e.g., rating 1) in block form in a chain-like linked-ring-based distributed data storage environment generated based on a P2P (peer-to-peer) scheme (S570). API security rating information is information stored on the blockchain and may include the ID of a WAAP with security level 1 and a list of APIs with security level 1 registered to the WAAP. The process of storing such information may mean the process of synchronizing the API list with the blockchain.

[0105] Next, the blockchain can communicate the API status and WAAP level obtained from the API security verification results to the user (S580). In other words, the blockchain can provide the user with API information and WAAP level.

[0106] According to this embodiment, the user can request API information from the blockchain and receive information on the API status and WAAP level from the blockchain.

[0107] The process of requesting API information from the blockchain, as described above, may be substantially identical to the process of requesting confirmation from the blockchain for an API authenticated by a Level 3 WAAP. Therefore, the aforementioned "process of requesting API information from the blockchain" can be used in the process of requesting information about an API authenticated by a Level 3 WAAP from a Level 1 WAAP. Figure 6 is a flowchart illustrating the WAAP vulnerability discovery and updating process that can be adopted in a security method according to one embodiment of this disclosure.

[0108] Referring to Figure 6, in order to perform the WAAP vulnerability discovery and updating process, an API Vulnerability Researcher can establish a session with the blockchain through the TLS handshake procedure (S610). An API Vulnerability Researcher may include a user or a user device used by the registrant to discover API vulnerabilities, and may be simply referred to as the registrant or user.

[0109] Once the TLS handshake procedure is complete, the registrant can register the discovered vulnerability and sample code for that vulnerability on the blockchain (S620). The sample code may include or be referred to as vulnerability test code.

[0110] Next, once a vulnerability and its sample code are registered, the blockchain can notify all WAAP(s) of the vulnerability and sample code (S630). The blockchain's notification of the vulnerability and sample code can be transmitted to all WAAP(s) belonging to the blockchain network via broadcast. In other words, the blockchain can propagate the WAAP vulnerability test API sample code to all WAAP(s). Such functionality may be considered one of the blockchain's original functions, such as the "distributed synchronization" function.

[0111] Next, at least one WAAP(s) that have received notification of the vulnerability test API sample code can transmit the API safety status for the aforementioned WAAP vulnerability test API sample code to the blockchain (S640). That is, after the WAAP calculates the safety rating for the WAAP vulnerability test API sample code, it can transmit the resulting response value back to the blockchain.

[0112] Next, the blockchain can determine the API status by determining whether the security rating of the API sample code transmitted as a response value by all WAAP(s) is level 1 or level 3 (S650). That is, if a WAAP calculates the security rating of the malicious API sample code for vulnerability testing to be 1, the blockchain can classify the WAAP as a vulnerable WAAP and adjust its level to 3. Also, if a WAAP calculates the security rating of the malicious API sample code for vulnerability testing to be 3, the blockchain can classify the WAAP as a stable WAAP and update its level to 1.

[0113] Next, if the security level of the transmitted API vulnerability sample code is 1, the blockchain can identify the transmitted WAAP as vulnerable, set its security level to 3, and save the corresponding WAAP ID.

[0114] On the other hand, if the security level of the transmitted API vulnerability sample code is 3, the blockchain can accurately classify the harmful API sample code as security level 3 for the transmitted WAAP, and therefore can set the security level for that WAAP to 1 and store the corresponding WAAP ID. Through this process, the blockchain can store updated information on the WAAP ID, WAAP level, and vulnerability (S660).

[0115] According to this embodiment, registrants store API vulnerabilities and corresponding sample code on the blockchain. The blockchain receives API security status from all WAAP(s) in the blockchain network based on the vulnerabilities and sample code. Based on the API security status received from each WAAP, the blockchain verifies the API status and can store the WAAP ID, WAAP level, and vulnerable WAAP information, or store the WAAP ID, WAAP level, and vulnerability update information based on the verified API status.

[0116] Figure 7 is a flowchart illustrating the level repair and re-grading request process after a WAAP update, which can be used in a security method according to one embodiment of the present invention.

[0117] Referring to Figure 7, a WAAP can perform its own update procedure in administrator mode for WAAP level repair and re-grading requests (S710). An administrator can perform an update to upgrade the security level of a WAAP with WAAP administrator privileges. A WAAP in administrator mode is an administrator and can refer to a WAAP that is being used by an administrator or operating in administrator mode, such as a WAAP being used by a user who has received user authentication. Next, WAAP in administrator mode can perform blockchain and TLS handshake procedures for WAAP level repair and re-grading requests (S720).

[0118] After establishing a session with the blockchain via the TLS handshake, the WAAP can re-request a WAAP test to restore the WAAP level, which has been adjusted based on the results of the blockchain propagation vulnerability API sample code test (S730). The identification information of the test WAAP may be represented, for example, by alpha (α). For example, in the case of a WAAP that was downgraded in a previous process, it can re-request a WAAP level test from the blockchain after updating to restore its level.

[0119] Next, the blockchain can request WAAP to perform API sample code security verification. That is, WAAP in administrator mode can receive requests for API sample code security verification from the blockchain (S740). API sample code security verification can be performed by the blockchain transmitting malicious API sample code for vulnerability testing to the WAAP in question and requesting verification of it. Such API sample code security verification is intended to allow administrators to confirm the stability of WAAP, an integrated web security solution, against pre-registered malicious API sample code for vulnerability testing.

[0120] Next, WAAP can transmit the API safety status confirmed at the administrator level to the blockchain (S750). That is, WAAP in administrator mode can define a safety rating for malicious API sample code used for WAAP testing and transmit the verification results, including the API safety status, to the blockchain.

[0121] Next, the blockchain checks the API status (S760) and can store the corresponding WAAP ID, WAAP level, and vulnerability information based on the security rating of the checked API, or it can store the WAAP ID, WAAP level, and vulnerability update information (S770). In other words, if the security rating of a specific WAAP transmission test malicious API is 1, the blockchain can classify the WAAP as a vulnerable WAAP and downgrade its level to level 3 before storing it. Also, if the security rating of a specific WAAP transmission test malicious API is 3, the blockchain can classify the WAAP as a stable WAAP and upgrade its level to level 1 before storing it. Figure 8 is a schematic block diagram of the configuration of a security system according to yet another embodiment of the present invention.

[0122] Referring to Figure 8, the security system 800 may include at least one processor (810), memory 820, and a transceiver (830) that is connected to a network and performs communication. The at least one processor 810 and the memory 820 may be composed of at least one controller. The transceiver 830 may include a sub-communication system that supports a wired network or a wireless communication module (WCM) that supports a wireless network.

[0123] Furthermore, the security system 800 may further include a storage device 840, an input interface device 850, an output interface device 860, and the like. Each component included in the security system 800 can be connected by a bus (870) to perform communication.

[0124] However, each component included in the security system 800 may not be connected via a common bus, but rather via individual interfaces or individual buses centered around the processor 810. For example, the processor 810 may be connected to at least one of the following via a dedicated interface: memory 820, transceiver 830, storage device 840, input interface device 850, and output interface device 860.

[0125] The processor 810 can execute program commands stored in at least one of the memory 820 and the storage device 840. The processor 810 may mean a central processing unit (CPU), a graphics processing unit (GPU), or a dedicated processor on which the security method according to an embodiment of the present invention is executed. The program commands may include at least one instruction for implementing the aforementioned security method.

[0126] The memory 820 and the storage device 840 may each consist of at least one of a volatile storage medium and a non-volatile storage medium. For example, the memory 820 may consist of at least one of a read-only memory (ROM) and a random access memory (RAM).

[0127] The aforementioned security system 800 can be embodied in desktop computers, servers, mobile terminals, laptop computers, personal mobile communication terminals, etc. The security system 800 may also refer to nodes, servers, management systems, service systems, etc., located on wired networks, short-range wireless networks, mobile communication networks, satellite networks, or combinations thereof.

[0128] Figure 9 is a schematic block diagram of the main components of WAAP that can be adopted in the security system shown in Figure 8.

[0129] Referring to Figure 9, WAAP900 is a Level 1 security system that may comprise a service provider 910 and a verification tool 950. The service provider 910 may comprise a handshake processing unit 920, an API security rating verification unit 930, and a notification processing unit 940, all of which are embodied by at least one software module.

[0130] In this embodiment, WAAP900 may be executed based on the blockchain's verification of the relevant API information in response to a user's request to confirm whether or not they have registered for the API.

[0131] To explain the components of WAAP900 in more detail, the service provider 910 can register an API with the verification tool 950. At this time, the verification tool 950 can store the API, the API identifier (ID), and the hash. The verification tool 950 can then transmit the ID and hash to the service provider 910. The verification tool 950 may also be configured to compare the hash value of the API with the hash value it has stored.

[0132] On the other hand, the handshake processing unit 920 installed in the service provider 910 can execute the TLS handshake procedure to establish a session with the blockchain. Accordingly, the handshake processing unit 920 can execute the security handshake procedure to establish a session between the service provider 910 and the verification tool 950.

[0133] The API security rating verification unit 930 can receive an API security rating verification request from the blockchain to a Level 1 WAAP. In this case, the API security rating verification unit 930 can transmit API security status information, including the API security rating verification result, to the blockchain. At this time, the blockchain can receive the identifier of the Level 1 WAAP and the list of security rating 1 APIs registered in the WAAP from each WAAP and store them on the blockchain. This corresponds to the blockchain completing blockchain synchronization for the secure API list.

[0134] On the other hand, API vulnerability registrants can register vulnerabilities and sample code on the blockchain. The sample code can include vulnerability test code. In this case, the blockchain can propagate the WAAP vulnerability test API sample code to all WAAP instances. This can be achieved through the blockchain's inherent "distributed synchronization" functionality.

[0135] The notification processing unit 940 can receive notifications propagated or broadcast from the blockchain. Notifications may include WAAP vulnerabilities and API sample code for WAAP vulnerability testing. That is, once the vulnerability and sample code are received through the notification processing unit 940, the API security rating verification unit 930 can calculate the API security rating based on the received API sample code and then transmit the API security status information, including the calculation result, back to the blockchain.

[0136] At this time, the blockchain can classify a WAAP that has been assigned a security rating of 1 for the malicious API sample code used for vulnerability testing as a vulnerable WAAP and adjust its level downwards. Conversely, the blockchain can classify a WAAP that has been assigned a security rating of 3 for the malicious API sample code used for vulnerability testing as a stable WAAP and update its level to a higher level. Figure 10 is a schematic block diagram of the main configuration of WAAP in administrator mode that can be used in the security system shown in Figure 8.

[0137] Referring to Figure 10, the WAAP1000 in administrator mode may be equipped with an update processing unit 1010, a handshake processing unit 1020, a sample code verification processing unit 1030, and an API safety rating processing unit 1040.

[0138] The update processing unit 1010 can perform WAAP-level repair updates with WAAP administrator privileges.

[0139] The handshake processing unit 1020 can perform a security handshake to establish a session with the blockchain. The security handshake can include a TLS handshake, but is not limited to this, and other security methods can be applied.

[0140] The sample code verification processing unit 1030 can request a WAAP level test from the blockchain. In the case of a downgraded WAAP, the sample code verification processing unit 1030 can request a WAAP level test from the blockchain after updating itself to restore the WAAP's level. Then, the sample code verification processing unit 1030 can perform verification of the malicious API sample code for vulnerability testing from the blockchain and calculate the API security rating.

[0141] The API security rating processing unit 1040 can transmit API security status information, including the API security rating calculation and the associated WAAP level adjustment results from the sample code verification processing unit 1030, to the blockchain.

[0142] According to the aforementioned security system, WAAP can provide a service API security rating calculation function that performs security rating calculations for service API-specific vulnerabilities for enterprise service API security. Furthermore, after generating service API-specific IDs and hash values ​​for enterprise service API security, WAAP can provide a service API management function that matches IDs and hash values ​​or matches hash values.

[0143] Furthermore, according to the aforementioned security system, WAAP can provide a service API security verification function that performs verification in response to user requests for security checks on service APIs for enterprise service API security. Prerequisites for the service API security verification function may include the fact that the service API is served as a standardized API to which consistent rules, patterns, and protocol standards are applied.

[0144] Furthermore, according to the aforementioned security system, for the security of external users, it is possible to provide a user-active reverse WAAP function that allows users to request security verification of the service API from the WAAP-linked blockchain of the service provider (corresponding to the service provider). In addition, for the security of external users, it is possible to provide a function to proactively block damage from API vulnerabilities, for example, by publicly announcing the hash value of the service API to the outside to prevent forgery or alteration of the service API. In addition, for the security of external users, it is possible to provide a function to provide a secure user service usage environment, for example, by providing a secure service API through a verification procedure for the service API.

[0145] Furthermore, according to the aforementioned security system, WAAP can provide web firewall functionality for corporate internal network security. Web firewall functionality can include DMZ Zone service server security, bot detection, DDoS blocking, and more.

[0146] Figure 11 is a block diagram illustrating a software module that can be used in a security system according to yet another embodiment of the present disclosure.

[0147] Referring to Figure 11, the security system's processor 1100 includes at least one software module, which may be configured to include a web firewall function unit 1110, an API security function unit 1120, a bot mitigation function unit 1130, a DDoS (Deadly DoS) protection function unit 1140, a self-check function unit 1150, and an alarm processing unit 1160.

[0148] The web firewall function unit 1110 is at least part of the WAAP's web firewall functionality and can be configured to respond to web attacks or to respond to primary attacks aimed at gathering information for secondary attacks. The web firewall function unit 1110 may have a web firewall engine based on multiple rules and custom rule functionality. The web firewall engine can detect and block HTTP / HTTPS-based web attacks through logic analysis of attacker and circumvention attacker signals and data, thereby maintaining client internal network security.

[0149] The API security function unit 1120 is at least part of the WAAP's web firewall function or enterprise service API security function, and can calculate the security level of an API and, through API validation, determine whether the API is secure or a tampered API and inform the user accordingly.

[0150] The bot mitigation unit 1130 is at least part of the WAAP's web firewall function or enterprise service API security function and may be configured to identify, detect, and block bot activity. The bot mitigation unit 1130 can identify bot activity and block attacks by utilizing unique information of the client (in this case, the attacker) through pre-configured Suspicious Access (SA) rules. Here, SA rules may be used to determine the characteristics of automated attack tools such as bots and block or restrict access to connections from clients that are not legitimate web browsers.

[0151] The DDoS (Deadly DoS) protection unit 1140 is at least part of the WAAP's web firewall functionality and may be configured to detect and block DDoS attacks at the application layer. The DDoS protection unit 1140 can, for example, detect and block attacks that overload a session by repeatedly sending incomplete requests.

[0152] The self-checking function unit 1150 may be configured to automatically recognize problems that may occur during the operation of the security device. The self-checking function unit 1150 may be configured to perform real-time self-diagnosis of its own status, recognize dangerous situations, and perform automatic recovery function operations through a pre-configured process. The automatic recovery function may be performed based on pre-configured self-diagnosis items and their corresponding settings.

[0153] If there are usage settings for an alarm, the alarm processing unit 1160 can communicate the alarm to the security device administrator or client based on the pre-set classification results of the degree of danger for self-diagnosis, danger situation recognition, etc., and / or the value settings for alarm generation.

[0154] At least one of the aforementioned software modules, or at least one of the web firewall function unit 1110, API security function unit 1120, bot mitigation function unit 1130, DDoS (Deadly DoS) protection function unit 1140, self-check function unit 1150, and alarm processing unit 1160, can constitute a program instruction.

[0155] Furthermore, a program instruction may include at least one instruction to implement a security method. For example, a program instruction may include instructions for handshake processing, API registration verification processing, API security rating processing, notification processing, update processing, and sample code verification processing.

[0156] On the other hand, the operation of the security method according to the embodiments of the present invention described above can be embodied in a computer-readable program or code on a computer-readable recording medium. A computer-readable recording medium includes all types of recording devices on which information readable by a computer system is stored. Furthermore, computer-readable programs or code can be stored and executed in a distributed manner on computer systems connected to a network.

[0157] Furthermore, computer-readable recording media can include hardware devices specially configured to store and execute program instructions, such as ROM, RAM, and flash memory. Program instructions can include not only machine code generated by a compiler, but also high-level language code that can be executed by a computer using an interpreter or the like.

[0158] Some aspects of the present invention have been described in the context of apparatus, but they can also be described in a corresponding way, where a block or apparatus corresponds to a method step or feature of a method step. Similarly, aspects described in the context of a method can also be described by a corresponding block or item or feature of a corresponding apparatus. Some or all of the method steps may be carried out by (or utilizing) a hardware device such as, for example, a microprocessor, a programmable computer, or an electronic circuit. In some embodiments, at least one or more of the most important method steps may be carried out by such a device.

[0159] In embodiments, a programmable logic device (e.g., a field-programmable gate array) may be used to perform some or all of the functions of the methods described herein. For example, a field-programmable gate array may operate in conjunction with a microprocessor to perform one of the methods described herein. Generally, it is preferable that the methods be performed by some hardware device.

[0160] As described above with reference to examples, those skilled in the art will understand that the present invention can be modified and altered in various ways without departing from the spirit and scope of the invention as described in the following claims.

Claims

1. A blockchain-based security method implemented by an integrated web security solution (web application and API protection, WAAP) and utilizing WAAP and API (application programming interface) level management, When a session with the blockchain is established, and the blockchain requests confirmation of the API security rating, The step of verifying the API safety rating - the verification step is to independently verify the safety rating for the vulnerability of the API in the management API data of the WAAP with the highest level of stability, and A blockchain-based security method comprising the step of transmitting information regarding the API security rating to the blockchain.

2. The blockchain-based security method according to claim 1, wherein the WAAP has a security level of 1, indicating the most secure WAAP, and the blockchain stores the WAAP identification information of the WAAP and a list of security level 1 APIs registered in the WAAP.

3. The blockchain-based security method according to claim 2, wherein the WAAP and blockchain synchronization are completed for the API list with security level 1, which is the most secure level of security.

4. The blockchain-based security method according to claim 1, further comprising the step of receiving API sample code for WAAP vulnerability testing from the blockchain, wherein the API sample code is a malicious sample code.

5. The blockchain-based security method according to claim 4, further comprising the step of calculating a security rating for the WAAP vulnerability testing API sample code.

6. The blockchain-based security method according to claim 5, further comprising the step of transmitting information regarding the API security rating status, including the calculated security rating, to the blockchain.

7. The blockchain-based security method according to claim 6, wherein the blockchain, based on information regarding the API security rating status, classifies a WAAP that has been calculated to have the highest level of security rating for the WAAP vulnerability test API sample code as a WAAP with a security vulnerability and downgrades its level.

8. The blockchain-based security method according to claim 6, wherein the blockchain, based on information regarding the API security rating status, classifies a WAAP that has been assigned the lowest level of security rating to the API sample code for WAAP vulnerability testing as a stable WAAP and upgrades its level.

9. The stage of requesting the aforementioned blockchain to test the aforementioned WAAP, The stage in which a request for confirmation of the security level of the API sample code is received from the aforementioned blockchain, and The blockchain-based security method according to claim 1, further comprising the step of transmitting API security status information, including confirmation information for the API security rating, to the blockchain.

10. A blockchain-based security method implemented by an integrated web security solution (web application and API protection, WAAP) and utilizing WAAP and API (application programming interface) level management, The stage where the blockchain is asked to test WAAP through an established session with the blockchain, At the stage where a request for confirmation of the security level of the API sample code is received from the aforementioned blockchain, The stage of performing a custom vulnerability test on the API sample code received from the aforementioned blockchain, After performing the aforementioned vulnerability tests, the stage of calculating the API safety rating, and A blockchain-based security method comprising the step of transmitting API security status information, including confirmation information for the API security rating, to the blockchain.

11. The blockchain-based security method according to claim 10, further comprising the step of independently upgrading the functionality of the WAAP with administrator privileges of the WAAP before requesting a test of the WAAP.

12. Based on the information regarding the API security rating status, the blockchain classifies the WAAP that has been assigned the highest level of security rating to the WAAP vulnerability test API sample code as a vulnerable WAAP and downgrades its level. The blockchain-based security method according to claim 10, wherein the blockchain, based on information regarding the API security rating status, classifies a WAAP that has been assigned the lowest level of security rating to the WAAP vulnerability test API sample code as a stable WAAP and upgrades its level.

13. A blockchain-based security system that utilizes an integrated web security solution (web application and API protection, WAAP) and API (application programming interface) level management, memory, and Includes at least one processor that is linked to the memory and executes a program that includes at least one instruction, By at least one of the instructions, the processor: A blockchain-based security system in which, under the presence of a session with the blockchain, the WAAP receives an API security rating confirmation request from the blockchain, confirms the API security rating, and transmits confirmation information regarding the API security rating to the blockchain.

14. The blockchain-based security system according to claim 13, wherein the WAAP has a security level of 1, indicating the most secure WAAP, the blockchain stores the WAAP identification information of the WAAP and a list of security level 1 APIs registered in the WAAP, and the blockchain completes blockchain synchronization with the corresponding WAAP for the API list of the highest security level.

15. The blockchain-based security system according to claim 13, further comprising the processor receiving WAAP vulnerability testing API sample code from the blockchain, calculating a security rating for the WAAP vulnerability testing API sample code, and transmitting information regarding the API security rating status, including the calculated security rating, to the blockchain.

16. The blockchain-based security system according to claim 15, wherein the blockchain, based on information regarding the API security rating status, classifies a WAAP that has been assigned the highest level of security rating to the WAAP vulnerability test API sample code as a vulnerable WAAP and downgrades its level.

17. The blockchain-based security system according to claim 15, wherein the blockchain, based on information regarding the API security rating status, classifies a WAAP that has been assigned the lowest level of security rating to the API sample code for WAAP vulnerability testing as a stable WAAP and upgrades its level.

18. The blockchain-based security system according to claim 13, further comprising the processor requesting the blockchain to test the WAAP, receiving a request for API sample code security rating verification from the blockchain, and transmitting API security rating status information, including verification information for the API security rating, to the blockchain.

19. The blockchain-based security system according to claim 18, wherein the processor further performs an independent upgrade of the functionality of the WAAP using the administrator privileges of the WAAP before requesting a test of the WAAP from the blockchain, or before requesting a retest for modification of the WAAP level by downgrading the WAAP level based on the results of the previous test.