See your APIs like an attacker does.  Get a free API Attack Surface Assessment

Archive | Dawla Nasheed Internet

If you want, I can expand this into a full-length paper (with academic-style sections, citations, and references), create a policy brief, or draft an IRB-compliant protocol for collecting such materials. Which would you prefer?