Talk to your security eng. in your org & they should have similar security products mentioned if not google.. In general you will need to rely on products which does the work for you with detection(atleast on-prem) but with in apigee when you build & expose api’s make sure you build api’s securely following best practices. If you think you need more information may be open a case with support(https://cloud.google.com/apigee/support) to learn & share..