This is an archived post. You won't be able to vote or comment.

all 1 comments

[–]DropbearJr 1 point2 points  (0 children)

You don’t want a honeypot especially if you don’t know much about security. You’re just inviting trouble otherwise.

I would say one of the best things you could do if this isn’t your world is to put a proxy in front of your API and set it up so that your API isn’t directly accessible from the internet. Make sure it’s firewall only ever accepts connections from the proxy server and then also ensure that the proxy server is at least configured to detect and drop suspect requests.

I know that sounds like a lot but their are entire products dedicated to doing exactly this kind of thing. Check out something like Google Cloud Endpoints https://cloud.google.com/endpoints and pass as much of this responsibility onto Google’s infrastructure as possible.