PingIntelligence 5.0 (June 2021) - PingIntelligence for APIs - 5.1

PingIntelligence

bundle
pingintelligence-51
ft:publication_title
PingIntelligence
Product_Version_ce
PingIntelligence for APIs 5.1
category
APISecurity
AdvancedAPICybersecurity
Capability
Environment
OS
Product
apisecurity
capability
linux
pi-51
pingintelligence
private
ContentType_ce

PingIntelligence 5.0 provides the following enhancements:

All PingIntelligence components now support a single unified license

New
PingIntelligence now supports up to 10 subpath levels for API base paths when API Security Enforcer (ASE) is deployed in sideband mode. Subpath depth is the number of sub-paths for a unique API definition. For more information, see Discovery Subpaths.

Dashboard Enhancements

New
The PingIntelligence Dashboard is enhanced to provide improved user experience for the following functionalities:
  • The updated Attack management page gives a comprehensive view of Indicators of Attacks (IoAs) on a per client basis. A separate Enable / Disable Attacks page helps the administrators in efficient attack management. For more information, see Attack management.
  • The Training Status page now allows you to view the training status for an API by selecting the API from a drop-down list. The page also has a new capability to download per API and across API attack thresholds in a JSON formatted text file. For more information, see AI engine training.

ASE Updates

New
ASE has the following new additions:
  • External Load Balancer support for ASE to ABS AI Engine traffic -ASE can be optionally configured to utilize external load balancers to distribute traffic across ABS AI Engine nodes. This provides the flexibility to support auto-scale of ABS AI Engine nodes and more high availability configurations.
  • REST API for sideband token management -The Token API helps to create, import, and delete ASE sideband tokens. You can also retrieve the list of tokens issued by ASE.
  • REST API for sideband authentication - The Authentication API helps to enable and disable ASE sideband authentication. You can also retrieve the authentication status. For more information, see REST APIs for sideband token and authentication.

New in sideband integration policies

Improved
  • NGINX plus policy - The updated PingIntelligence sideband policy can seamlessly integrate with NGINX Plus R22 or R23 systems. This enhanced policy supports NGINX nodes with PingAccess agents installed and can capture user information from the PingAccess token introspection. For more information, see NGINX Plus for RHEL 7.6.
  • Apigee policy - The updated PingIntelligence sideband policy adds optional asynchronous communication between Apigee and ASE for improved performance when deployed in environments that do not require automated client blocking. For more information, see Apigee integration.
  • Kong policy - The PingIntelligence sideband policy is enhanced to support extraction of user information from JWTs when OpenID Connect (OIDC) plugin is installed in a Kong gateway. For more information, see Kong API gateway integration.

New in deployment tools

Improved
The following PingIntelligence deployment tools have been modified to support integration with PingOne: