Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

11/17/2017
01:00 PM
0%
100%

Businesses Can't Tell Good Bots from Bad Bots: Report

Bots make up more than 75% of total traffic for some businesses, but one in three can't distinguish legitimate bots from malicious ones.

One in three organizations can't differentiate good or legitimate bots from bad bots - a shortcoming that can affect application security.

Bots make up more than 75% of total traffic for some businesses, according to a Radware study on Web application security. The study found nearly half (45%) of businesses had been hit with a data breach in the past year, and 68% are not confident they can keep corporate information safe.

Malicious bots are a serious risk, as Web-scraping attacks can affect retailers by stealing intellectual property, undercutting prices, and holding mass inventory in limbo, the report states. In retail, 40% of businesses can't tell good bots from bad ones. The healthcare industry is also struggling: 42% of traffic comes from bots, but 20% of IT security execs can tell if they're nefarious.

Researchers found gaps in DevOps security, which likely stem from the pressure to consistently deliver application services. Half (49%) of respondents use the continuous delivery of application services and 21% plan to adopt it in the next 1-2 years. More than half (62%) believe this increases the attack surface and about half report they don't integrate security into continuous application delivery.

Read more details here.

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Joe Stanganelli
100%
0%
Joe Stanganelli,
User Rank: Ninja
11/19/2017 | 5:16:44 PM
White Bot, Black Bot, Good Bot, Bad Bot
There are vendor tools that can help accomplish this.

That said, does this really matter in the grand scheme of things? Whitelist what you know, explicitly trust, and actively want in your network. Otherwise, if you find out it's a bot, why not kick it out?
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
11/20/2017 | 10:16:38 AM
Re: White Bot, Black Bot, Good Bot, Bad Bot
I am so sorry for this one, but when I read the headline title ---- the first image came to mind was Glinda asking Dorothy - 'Are you a good bot or a bad bot?" 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/21/2017 | 7:38:19 AM
Re: White Bot, Black Bot, Good Bot, Bad Bot
@REISEN: Brilliant! I'd love to borrow this analogy/imagery for a future article or blog.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:50:16 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
I agree, the question is how we applied that analogy to bots technologies.
AutoEcole18
50%
50%
AutoEcole18,
User Rank: Apprentice
11/21/2017 | 5:48:58 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
Nice one !
DonHarper
50%
50%
DonHarper,
User Rank: Apprentice
11/23/2017 | 4:41:54 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
Brilliant one ! 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:47:59 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
Are you a good bot or a bad bot?

This is a good idea, all the bots have to prove that they are good bots first.
agenpokeronline
50%
50%
agenpokeronline,
User Rank: Apprentice
11/22/2017 | 4:53:18 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
Nice one !
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:46:16 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
"Whitelist"

Whitelist  would be a god option to keep. It may be a useful new bot such as delivering you the best cyber Monday deal. You want to allow that.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/28/2017 | 9:41:43 PM
Re: White Bot, Black Bot, Good Bot, Bad Bot
@Dr. T: Maybe you and I have different ideas of what kinds of bots we want to allow. I have no intention of letting marketers' bots in.

Whitelisting, in any case, goes to specific bots/APIs/etc. -- as opposed to general types.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:43:55 PM
Good or bad bots?
 

Good or bad bots? You would not know that until but executed so it is a little bit of a luck.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/28/2017 | 9:42:38 PM
Re: Good or bad bots?
@Dr. T: Not really. There are security software solutions and analytics that detect what kind of bot a bot is -- and whether it is a bad bot or a so-called "good" bot.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2017 | 12:52:56 PM
DevOPs Security?
 

"they don't integrate security into continuous application delivery?"

I do not know what they do then, are they delivering and deploying over the top?

 
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/10/2019
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Jim, stop pretending you're drowning in tickets."
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13623
PUBLISHED: 2019-07-17
In NSA Ghidra through 9.0.4, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis r...
CVE-2019-13624
PUBLISHED: 2019-07-17
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.
CVE-2019-13625
PUBLISHED: 2019-07-17
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.
CVE-2019-3571
PUBLISHED: 2019-07-16
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.
CVE-2019-6160
PUBLISHED: 2019-07-16
A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.