Cloud

1/24/2017
04:00 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
100%
0%

Bad Bots Up Their Human Impersonation Game

Every third website visitor was an attack bot in 2016, and humans represent just under half of all Internet traffic, new Imperva data sample shows.

Unsavory traffic on the Web continues to flow at a steady clip with nearly one-third of it from bad bots.

New data released from Imperva today shows bots with the upper hand overall, with humans representing 48.2% of website traffic in 2016; so-called "good" bots (think feed-fetchers, search engine bots and crawlers) at 22.9%, and bad bots accounting for 28.9% of the traffic. Bad bots mainly include automated accounts posing as humans, which make up about one-fourth of all bad bots. Other bad actor bots: hacker tools, scrapers, and spammers.

Every third visitor to a website was a bad bot last year, and more than 94% of websites in the study suffered at least one attack by a bad bot during the 90-day study of some 16.7 billion visits to 100,000 randomly-selected domains on Imperva's Incapsula network, a cloud-based service that provides web security, DDoS protection, and optimization for content delivery networks.

"I don't know if people  know that every third visitor to their website is an attack bot," says Igal Zeifman, a senior manager at Imperva. "The majority of automated visits … are doing something they shouldn't be doing, scraping the content of a website," spamming, comment-spamming, link-spamming, auto-filling online forms, and of course, waging distributed denial-of-service (DDoS) attacks, he says.

Bad bots have maintained a steady presence online as the Internet continues to grow, at 31% in 2012, a dipping slightly to around 29% the past couple of years, according to Imperva's data.  "This talks [of] motivation" of attackers, and their ability to successfully attack via bots, he says.

Source: Imperva
Source: Imperva

Imperva's report says "impersonator" bots remain the most prolific brand of bad bot: they accounted for 243.% of all traffic on Imperva's Incapsula network last year. These are bots that not only launch DDoS attacks, but also pose as browsing users in order to evade security detection tools. Depending on the website, the biggest risk of these nasty bots is DDoS attacks, using the site as a malware distribution forum, or as the first phase of an attack that ultimately infiltrates the organization itself, according to Zeifman.

Distil Networks last year found that last year humans outnumbered bad bots on the Web for the first time since 2013. But Distil's data drew from its Hadoop cluster that includes some 74 million bot requests and other customer data. Unlike Imperva's data set, it doesn't include DDoS bots but instead all other types of bad bots, including digital ad fraud.

What was in common, however, was that Distil also saw an increase bad bots imitating human online behavior. "I think that what's interesting is that the sophistication of bots seems to be increasing," says Edward Roberts, director of product marketing at Distil, which currently is putting the finishing touches on its new 2016 bot activity report.

For example, these smarter and more human-like bad bots are spreading around website activity requests among thousands of IPs, he says, in order to remain under the radar of web security tools and teams. They pause a few seconds between page requests, for instance, and move the mouse similar to the way a human does, he says.

Some organizations are suffering more than others from bad bot activity. "Two of three requests are [via] bad bots on some companies'" websites, he says.

"This is something that's not going away," Distil's Roberts says.

Related Content:

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/25/2017 | 10:21:48 AM
Sophistication in automation
At the end of the day, though, bot activity -- by definition -- is automated.

Therefore, as bots get more sophisticated, the "good guys" working to stop them have to as well.

So if the bots move the mouse similar to the way a human does, they're still doing this activity on repeat from a set of instructions.  Accordingly, certain patterns must be learned -- and, from there, treated in an escalatedly guarded manner when detected.
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I guess this answers the question: who's watching the watchers?
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20029
PUBLISHED: 2018-12-10
The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read.
CVE-2018-1279
PUBLISHED: 2018-12-10
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on ...
CVE-2018-15800
PUBLISHED: 2018-12-10
Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.
CVE-2018-15805
PUBLISHED: 2018-12-10
Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files or cause a denial of service (resource consumption).
CVE-2018-16635
PUBLISHED: 2018-12-10
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.