Advanced API Security 会持续监控您的 API,以保护它们免受安全威胁(包括来自恶意客户端和滥用行为的攻击)。Advanced API Security 会分析 API 流量以识别可疑的 API 请求,并提供相关工具来屏蔽或标记这些请求(如果您决定这样做)。此外,Advanced API Security 还会评估您的 API 配置以确保其符合安全标准,并在需要时提供改进建议。
配置混淆后,系统会在混淆前应用 Advanced API Security 检查(例如,在滥用行为检测和安全操作中)。例如,即使 IP 地址经过了混淆处理,也有可能检测到来自特定 IP 地址的滥用行为。不过,用户无法在 Advanced API Security 界面或 API 中以明文(未经哈希处理)形式查看经过混淆处理的值(例如客户端 IP 地址)。系统会显示哈希值。
在某些情况下,您需要获取未经过混淆处理的数据值,以便与 Advanced API Security 搭配使用。例如,您可能需要使用客户端 IP 地址来配置安全操作。如果值已经过混淆处理,则无法检索明文 IP 地址。在安全操作配置中使用经过混淆处理(哈希处理)的值不起作用,因为数据混淆使用的是单向哈希,而 Advanced API Security 无法将哈希值转换回明文值。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-26。"],[[["\u003cp\u003eAdvanced API Security is a paid add-on for Apigee and Apigee hybrid that protects APIs from security threats by monitoring traffic, identifying suspicious requests, and evaluating API configurations.\u003c/p\u003e\n"],["\u003cp\u003eTo utilize Advanced API Security, users must first provision Apigee and then enable the feature, which is available for Apigee Subscription, Pay-as-you-go, and hybrid Subscription organizations, as well as non-hybrid organizations with data residency enabled.\u003c/p\u003e\n"],["\u003cp\u003eAdvanced API Security presents its analysis of API traffic in the Apigee UI through Abuse detection, Security reports, and Risk assessment, allowing users to review and take actions.\u003c/p\u003e\n"],["\u003cp\u003eUsers can define how Apigee handles detected threats through Security actions, like blocking requests, and can set up Security alerts to receive notifications about security-related events.\u003c/p\u003e\n"],["\u003cp\u003eAdvanced API Security uses detection rules based on machine-learning algorithms to detect patterns of malicious activity, allowing for counter-measures to be put in place.\u003c/p\u003e\n"]]],[],null,["*This page\napplies to **Apigee** and **Apigee hybrid**.*\n\n\n*View [Apigee Edge](https://docs.apigee.com/api-platform/get-started/what-apigee-edge) documentation.*\n\n| **Note:** To use Advanced API Security you must first [provision Apigee](/apigee/docs/api-platform/get-started/provisioning-intro). When Apigee is successfully provisioned, you can [set up and enable Advanced API Security](./enable-security).\n\nAdvanced API Security continually monitors your APIs to protect them from security threats,\nincluding attacks from malicious clients and abuse. Advanced API Security analyzes your API traffic to\nidentify suspicious API requests, and provides tools to block or flag those requests\nif you decide to do so. In addition, Advanced API Security evaluates your API configurations to\nensure they meet security standards, and gives you recommendations for improving them if\nneeded.\n\nAdvanced API Security does not affect runtime traffic.\n\nThe diagram below illustrates how Advanced API Security works.\n\nAdvanced API Security uses the following process to protect your APIs:\n\n1. Advanced API Security collects data for recent traffic passing through your APIs.\n2. Advanced API Security analyzes the data to detect unusual traffic patterns that indicate a threat to your APIs.\n3. Advanced API Security presents the results of the analysis in following pages in the Apigee UI:\n - [Abuse detection](#abuse-detection)\n - [Security reports](#security-reports)\n - [Risk assessment](#risk-assessment)\n4. After reviewing the analysis, you can choose to block or flag requests from specific IP addresses using the [security actions](#security-actions) page. You can also create [security alerts](#security-alerts), which notify you of events related to Advanced API Security.\n\nNote that Advanced API Security does not support APIs running under\n[Apigee Adapter for Envoy](/apigee/docs/api-platform/envoy-adapter).\n\nUse Advanced API Security\n\nAdvanced API Security is available as a paid add-on for the following organization types:\n\n- Apigee Subscription and Pay-as-you-go organizations\n- Apigee hybrid organizations\n- Apigee organizations with [data residency enabled.](/apigee/docs/api-platform/get-started/drz-concepts) See [Data residency and Apigee hybrid](/apigee/docs/api-platform/get-started/drz-concepts#data-residency-and-apigee-hybrid) for information on use with DRZ-enabled hybrid organizations.\n\nTo use Advanced API Security, you must first enable it, as described in the following sections:\n\n- [Manage Advanced API Security for Pay-as-you-go organizations](/apigee/docs/api-security/enable-security#manage-advanced-api-security-for-pay-as-you-go-organizations)\n- [Manage Advanced API Security for Subscription organizations](/apigee/docs/api-security/enable-security#manage-advanced-api-security-for-subscription-organizations)\n\nYou can try Advanced API Security for free in any trial organization. Contact [Apigee Sales](https://pages.apigee.com/contact-sales-reg.html) to learn more.\n\nAdvanced API Security features\n\nThe following sections briefly describe the features of Advanced API Security.\n\nAbuse detection\n\n[Abuse\ndetection](/apigee/docs/api-security/abuse-detection) shows you security incidents involving your APIs. A security incident is a group\nof detected security events that are related to each other. Advanced API Security uses\n[detection rules](/apigee/docs/api-security/detection-rules), based on\nGoogle's machine-learning algorithms, to identify patterns that are signs of malicious activity,\nincluding API scraping and anomalies. You can then take measures to counter those threats\nusing [security actions](#security-actions).\n\nSecurity reports\n\n[Security reports](/apigee/docs/api-security/security-report-jobs) give you more in-depth analysis of security threats to your APIs.\nFor example, you can create reports for the number of malicious requests\nby various dimensions, such as the country of origin of the request. You can view these\nreports in the Apigee UI or via the API.\n\nRisk assessment\n\n[Risk assessment](/apigee/docs/api-security/security-scores) helps you identify APIs\nthat don't conform to security standards. Risk assessment regularly evaluates your API configurations\nand calculates scores to rate their security level. When a low score indicates a configuration\nissue, Advanced API Security provides recommendations to resolve the problem.\n\nSecurity actions\n\n[Security actions](/apigee/docs/api-security/security-actions) let you\ndefine how Apigee handles detected traffic, based on information from the Abuse detection page.\nFor example, you can create a security action to deny requests from an IP address that has been\nidentified as a source of abuse.\n\nSecurity alerts\n\nYou can configure [security alerts](/apigee/docs/api-security/security-alerts)\nto send you notifications when Advanced API Security detects\nevents related to Advanced API Security, such as changes to your security scores or security incidents.\n\nData obfuscation with Advanced API Security\n\nAdvanced API Security works with data that is obfuscated to replace sensitive data with a hashed value. See\n[Obfuscate user data for Apigee API Analytics](/apigee/docs/api-platform/analytics/obfuscate-user-data-for-analytics)\nfor information on the data obfuscation functionality.\n\n\nWhen obfuscation is configured, Advanced API Security checks such as in [Abuse detection](#abuse-detection)\nand [Security actions](#security-actions) are applied before the obfuscation. For example,\nit's possible to detect abuse from a specific IP address even if the IP address is obfuscated. However,\nobfuscated values (such as client IP address) are not viewable to users in clear (unhashed) text within the\nAdvanced API Security UIs or APIs. The hashed values are shown.\n\n\nIn some cases you need to obtain an unobfuscated data value to use with Advanced API Security. For example,\nyou might need a client IP address to configure a Security action. If the value is already obfuscated, you\ncan't retrieve the clear text IP address. Using the obfuscated (hashed) value in the Security action\nconfiguration doesn't work since data obfuscation uses a one-way hash and Advanced API Security cannot\nconvert the hashed value back to the clear text value."]]