Abstract With the mass application of virtualization, micro-services, and cloud-native technologies, interaction between service entities through APIs has become a norm. Many platforms are still maintaining large number old due to business needs. At same time, many new gradually going online. Both these statuses put forward higher requirements for API security. Focusing on APIs’ security protec...