Taliferro Group

Google's Apigee Finally Treats API Abuse as a Pattern, Not a Pile of Alerts

Most API security tools flag one suspicious request at a time, which misses the coordinated attacks that only look dangerous in aggregate. Taliferro's take on Google's new Apigee models: this is the right fix, and worth understanding even if you're not on Apigee.

Published: 2 May 2023 · Updated: 11 Aug 2026

By Tyrone Showers

Co-Founder Taliferro

Article

Apigee

Google has added machine learning models to its Apigee API management platform, purpose-built to catch business logic attacks — abuse that looks legitimate request-by-request but forms a clear pattern in aggregate. The models are available now to all Apigee Advanced API security customers, trained on Google's own internal traffic.

Google's Take

Shelly Hershkovitz, a product manager at Google Cloud, explained the origin directly: "The machine learning models that power API abuse detection have been trained and used by Google's internal teams to protect our public-facing APIs. The models rely on years of learning and best practices." In other words, this isn't a model built from a generic dataset — it's the same detection logic Google uses to protect its own APIs, now offered to Apigee customers.

Google's Apigee: Machine Learning for API Security (depiction 1)
Google's Apigee: Machine Learning for API Security (depiction 2)

Dashboards

Alongside the models, Apigee ships dashboards that summarize the shape of an attack — source, request frequency, and duration — instead of leaving a security team to piece it together from a stream of individual alerts.

That's the actual shift worth paying attention to. Traditional tooling flags one suspicious request at a time, which means a coordinated attack spread across thousands of individually-plausible requests can slip through entirely. Looking at the pattern across requests, not each one in isolation, is what catches it.

Why Patterns Matter More Than Individual Alerts

Business logic attacks are built to look legitimate one request at a time — that's what makes them hard to catch with rule-based systems. Machine learning is suited to exactly this problem: finding a pattern across a large volume of data that no single data point reveals on its own.

Training on Google's own internal traffic matters here too. It means the models have seen a genuinely large and diverse set of real attack patterns, not a synthetic or narrow dataset — and per Hershkovitz, that training keeps evolving as new attack patterns show up.

Getting Started, If You're Already on Apigee

  • Turn on the Advanced API security tier — the ML models are bundled with it, not a separate product to integrate.
  • Give it real traffic history before trusting the alerts — like any ML system, accuracy improves once it has your actual usage patterns to compare against, not just Google's.
  • Route alerts somewhere a human actually checks — a dashboard nobody looks at is the same as no dashboard.
  • Feed false positives back in — flag them so the model tightens over time instead of staying static.

Conclusion

The real news here isn't "Google added AI to a security product" — that's table stakes now. It's that Apigee moved from alert-by-alert review to pattern detection across the whole traffic stream, which is the only approach that actually catches business logic attacks built specifically to look innocent one request at a time.

Tyrone Showers
Need stronger model confidence?

Use this article as a starting point, then move into predictive analytics services, connect it to the Momentum System, or book a consult.

Want this fixed on your site?

Tell us your URL and what feels slow. We’ll point to the first thing to fix.

Explore Taliferro's free tools: Ask TODD · Find · Email Signature Builder · SayIt · Lead Vault · Meet Maya — or become an affiliate.