Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

1/24/2017
04:00 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
100%
0%

Bad Bots Up Their Human Impersonation Game

Every third website visitor was an attack bot in 2016, and humans represent just under half of all Internet traffic, new Imperva data sample shows.

Unsavory traffic on the Web continues to flow at a steady clip with nearly one-third of it from bad bots.

New data released from Imperva today shows bots with the upper hand overall, with humans representing 48.2% of website traffic in 2016; so-called "good" bots (think feed-fetchers, search engine bots and crawlers) at 22.9%, and bad bots accounting for 28.9% of the traffic. Bad bots mainly include automated accounts posing as humans, which make up about one-fourth of all bad bots. Other bad actor bots: hacker tools, scrapers, and spammers.

Every third visitor to a website was a bad bot last year, and more than 94% of websites in the study suffered at least one attack by a bad bot during the 90-day study of some 16.7 billion visits to 100,000 randomly-selected domains on Imperva's Incapsula network, a cloud-based service that provides web security, DDoS protection, and optimization for content delivery networks.

"I don't know if people  know that every third visitor to their website is an attack bot," says Igal Zeifman, a senior manager at Imperva. "The majority of automated visits … are doing something they shouldn't be doing, scraping the content of a website," spamming, comment-spamming, link-spamming, auto-filling online forms, and of course, waging distributed denial-of-service (DDoS) attacks, he says.

Bad bots have maintained a steady presence online as the Internet continues to grow, at 31% in 2012, a dipping slightly to around 29% the past couple of years, according to Imperva's data.  "This talks [of] motivation" of attackers, and their ability to successfully attack via bots, he says.

Source: Imperva
Source: Imperva

Imperva's report says "impersonator" bots remain the most prolific brand of bad bot: they accounted for 243.% of all traffic on Imperva's Incapsula network last year. These are bots that not only launch DDoS attacks, but also pose as browsing users in order to evade security detection tools. Depending on the website, the biggest risk of these nasty bots is DDoS attacks, using the site as a malware distribution forum, or as the first phase of an attack that ultimately infiltrates the organization itself, according to Zeifman.

Distil Networks last year found that last year humans outnumbered bad bots on the Web for the first time since 2013. But Distil's data drew from its Hadoop cluster that includes some 74 million bot requests and other customer data. Unlike Imperva's data set, it doesn't include DDoS bots but instead all other types of bad bots, including digital ad fraud.

What was in common, however, was that Distil also saw an increase bad bots imitating human online behavior. "I think that what's interesting is that the sophistication of bots seems to be increasing," says Edward Roberts, director of product marketing at Distil, which currently is putting the finishing touches on its new 2016 bot activity report.

For example, these smarter and more human-like bad bots are spreading around website activity requests among thousands of IPs, he says, in order to remain under the radar of web security tools and teams. They pause a few seconds between page requests, for instance, and move the mouse similar to the way a human does, he says.

Some organizations are suffering more than others from bad bot activity. "Two of three requests are [via] bad bots on some companies'" websites, he says.

"This is something that's not going away," Distil's Roberts says.

Related Content:

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/25/2017 | 10:21:48 AM
Sophistication in automation
At the end of the day, though, bot activity -- by definition -- is automated.

Therefore, as bots get more sophisticated, the "good guys" working to stop them have to as well.

So if the bots move the mouse similar to the way a human does, they're still doing this activity on repeat from a set of instructions.  Accordingly, certain patterns must be learned -- and, from there, treated in an escalatedly guarded manner when detected.
I 'Hacked' My Accounts Using My Mobile Number: Here's What I Learned
Nicole Sette, Director in the Cyber Risk practice of Kroll, a division of Duff & Phelps,  11/19/2019
6 Top Nontechnical Degrees for Cybersecurity
Curtis Franklin Jr., Senior Editor at Dark Reading,  11/21/2019
Anatomy of a BEC Scam
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/21/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18610
PUBLISHED: 2019-11-22
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary syste...
CVE-2019-9536
PUBLISHED: 2019-11-22
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.
CVE-2013-6811
PUBLISHED: 2019-11-22
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom Services in Port Forwarding...
CVE-2013-6880
PUBLISHED: 2019-11-22
Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.
CVE-2019-15652
PUBLISHED: 2019-11-22
The web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn't properly sanitize input for error messages, leading to the ability to inject client-side code.