Vulnerabilities / Threats

12/10/2013
02:42 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

'Imposter' Bots On The Rise

A whopping 61.5 percent of all website traffic is attributed to bots of all types, new report finds

Both good and bad bots are frequenting websites, but, overall, the traffic they generate makes up more than half of all site traffic.

A new study by Incapsula based on 1.45 billion bot visits to some 20,000 websites worldwide in a 90-day period found that these code-based visitors account for 61.5 percent of all website traffic, an increase of 21 percent over 2012.

The good news is that most of that growth comes from good bots -- search engine crawlers, SEO services crawlers, and other types of legitimate software agents, for instance. And spam bots are down from 2 percent in 2012 to 0.5 percent this year. Much of that is due to Google's efforts to discourage comment-spamming SEO methods as well as link-spamming.

"We've noticed a 75 percent reduction in comment spammers, and that's really significant," says Marc Gaffan, co-founder of Incapsula.

The bad news is that 31 percent of bots are malicious. There was an 8 percent increase in unclassified bots with hostile intentions, according to Incapsula. Those are bots posing as legit agents, such as search-engine or browser user agents. The aim of these "impersonators" is to bypass the website's security, and they are typically built for specific malicious activity, such as automated DDoS agents or Trojan-activated browsers.

"The increase in impersonation is obviously a bad sign ... and it's also a bad symptom of increased malicious activities," Gaffan says. These automated bots also can be used to scan websites for holes or to impersonate a Google bot, he says.

"Sixteen percent of all websites had some type of good impersonation going on," he says.

The key to combating unwanted impersonator bots is to benchmark legitimate ones, and to get the proper visibility into their presence and activity, he says. "You want to make sure you don't block some of the good bots. Blocking Google bots by mistake can be hazardous" to your SEO investment, for example, Gaffan says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writer,  2/14/2019
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
Making the Case for a Cybersecurity Moon Shot
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  2/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-8980
PUBLISHED: 2019-02-21
A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
CVE-2019-8979
PUBLISHED: 2019-02-21
Koseven through 3.3.9, and Kohana through 3.3.6, has SQL Injection when the order_by() parameter can be controlled.
CVE-2013-7469
PUBLISHED: 2019-02-21
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.
CVE-2018-20146
PUBLISHED: 2019-02-21
An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could obtain administrator rights, as demonstrated by use of PowerShell.
CVE-2019-5727
PUBLISHED: 2019-02-21
Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS, aka SPL-138827.