Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

11/17/2017
01:00 PM
0%
100%

Businesses Can't Tell Good Bots from Bad Bots: Report

Bots make up more than 75% of total traffic for some businesses, but one in three can't distinguish legitimate bots from malicious ones.

One in three organizations can't differentiate good or legitimate bots from bad bots - a shortcoming that can affect application security.

Bots make up more than 75% of total traffic for some businesses, according to a Radware study on Web application security. The study found nearly half (45%) of businesses had been hit with a data breach in the past year, and 68% are not confident they can keep corporate information safe.

Malicious bots are a serious risk, as Web-scraping attacks can affect retailers by stealing intellectual property, undercutting prices, and holding mass inventory in limbo, the report states. In retail, 40% of businesses can't tell good bots from bad ones. The healthcare industry is also struggling: 42% of traffic comes from bots, but 20% of IT security execs can tell if they're nefarious.

Researchers found gaps in DevOps security, which likely stem from the pressure to consistently deliver application services. Half (49%) of respondents use the continuous delivery of application services and 21% plan to adopt it in the next 1-2 years. More than half (62%) believe this increases the attack surface and about half report they don't integrate security into continuous application delivery.

Read more details here.

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/28/2017 | 9:42:38 PM
Re: Good or bad bots?
@Dr. T: Not really. There are security software solutions and analytics that detect what kind of bot a bot is -- and whether it is a bad bot or a so-called "good" bot.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/28/2017 | 9:41:43 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
@Dr. T: Maybe you and I have different ideas of what kinds of bots we want to allow. I have no intention of letting marketers' bots in.

Whitelisting, in any case, goes to specific bots/APIs/etc. -- as opposed to general types.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:52:56 PM
DevOPs Security?
 

"they don't integrate security into continuous application delivery?"

I do not know what they do then, are they delivering and deploying over the top?

 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:50:16 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
I agree, the question is how we applied that analogy to bots technologies.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:47:59 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
Are you a good bot or a bad bot?

This is a good idea, all the bots have to prove that they are good bots first.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:46:16 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
"Whitelist"

Whitelist  would be a god option to keep. It may be a useful new bot such as delivering you the best cyber Monday deal. You want to allow that.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:43:55 PM
Good or bad bots?
 

Good or bad bots? You would not know that until but executed so it is a little bit of a luck.
DonHarper
50%
50%
DonHarper,
User Rank: Apprentice
11/23/2017 | 4:41:54 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
Brilliant one ! 
agenpokeronline
50%
50%
agenpokeronline,
User Rank: Apprentice
11/22/2017 | 4:53:18 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
Nice one !
AutoEcole18
50%
50%
AutoEcole18,
User Rank: Apprentice
11/21/2017 | 5:48:58 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
Nice one !
Page 1 / 2   >   >>
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-3154
PUBLISHED: 2020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
CVE-2019-17190
PUBLISHED: 2020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the...
CVE-2014-8161
PUBLISHED: 2020-01-27
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2014-9481
PUBLISHED: 2020-01-27
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
CVE-2015-0241
PUBLISHED: 2020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric ...