Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

11/14/2018
02:30 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Airlines Have a Big Problem with Bad Bots

Bad bots account for 43.9% of all traffic on their websites, APIs, and mobile apps, according to a new analysis of 100 airlines.

(Image: profit_image, via stock.adobe.com)
(Image: profit_image, via stock.adobe.com)

As airlines are ramping up in preparation of the holiday travel season, bad bots are ramping up their activity on airlines' websites, mobile apps, and APIs. Analysts in the research arm of Distil Networks today published a study called "How Bots Affect Airlines," in which they analyzed 7.4 billion requests from 180 domains on 100 international airlines. They found malicious bots make up 43.9% of all airline web traffic — about double the 21.8% average for all industries. The highest bad bot percentage for one airline? About 94.6%.

In almost 30% of the domains that analysts studied, bad bots made up more than half of all traffic. Most bots (84.3%) on airline domains are moderate or advanced, and harder to detect. The highest proportion of bad bot traffic stems from the US (25.6%), followed by Singapore (15%).

At the core of the problem are airline websites and mobile apps, which serve as the home for flight data presented to customers: seat availability, pricing, booking processes, discounts. Some airlines use their own booking engines; others use third-party services for booking.

Online travel agencies (OTAs) like Expedia and Booking.com are channels designed to sell flights and process payment on behalf of airlines. Under commercial agreements, OTAs can scrape flight data in exchange for fees. Travel aggregators like Kayak and Skyscanner also display flight information but redirect shoppers to airlines' websites to finalize their booking.

Four attack groups deploy bots against airlines: unauthorized OTAs and travel aggregators avoid fees and scrape flight information and fares, then hold seats to resell them later (a process known as "seat spinning"). Competitor airlines also scrape flight data and fares to gain market intelligence and hold seats to block legitimate purchases. Criminals target loyalty programs with account takeover to steal points, and conduct credit card and loyalty program fraud.

Keeping Up with Competition
Airlines are hot targets because the value of the goods they sell has a finite timeline, says Edward Roberts, director of product marketing at Distil Networks. There's only a certain period of time a flight ticket will be valid, and price changes frequently based on destination and departure. Further, an ecosystem of OTAs and aggregators is constantly collecting data.

"The more competitive the market, the more competitive routes you fly, the more bots are competitive," he explains. Every airline has some combination of authorized and unauthorized data scraping on their sites. Bad bots can result in higher fees for third-party booking engines because they make it appear as though far more people are viewing than booking flights.

It's called a "look-to-book" ratio. Every time someone looks at a flight listing and asks "how much," that's considered a look, Roberts says. There should be one flight booked for every 100 looks, a number all airlines measure their progress against. "If that ratio suddenly spikes, you know that's bot behavior," he continues. "That's not human behavior."

The business implications of bad bots are significant, says Roberts. "Information from airlines states the financial cost and burden of this is getting to that point where they're saying 'we actively need to solve this problem because the cost to business is getting too large,'" he adds.

Loyalty rewards programs are hard hit by cybercriminals looking to monetize account access. If they can brute-force credentials and break in, they can steal and monetize points and miles.

"Anecdotally, airlines have a lot of seven-digit fraud coming through loyalty programs that they're concerned about," Roberts points out. Larger airlines typically have more value in their online loyalty program accounts, so those typically see larger amounts of account takeover attacks.

Attackers targeting the airline industry are becoming more advanced over time. Researchers note only 19.7% of airline bots were sophisticated in 2017; this year, the percentage jumped to 31.4%. At the same time, the percentage of simple bots decreased from 27.4% to 15.7%.

"Airlines are trying to deal with the problem, and they're trying to put mitigation in place so they can prevent the volume of bots from attacking them," says Roberts. "The bot operators are reacting." Some are trying to appear more human by moving their mouse, delaying between clicks, making themselves evasive to try and avoid detection.

Overall, he says, researchers didn't notice trends specific to airline size or location. "It's really unique to that airline — whether it's a flight route they have or the nature of how they created their websites," he explains.

The past few months have been rough on airline cybersecurity. Last month, Hong Kong-based Cathay Airlines suffered the largest breach of any carrier to date when attackers compromised information belonging to 9.4 million passengers. A cyberattack on British Airways exposed the data of 380,000 customers; shortly after, the airline found 185,000 additional victims were hit.

Related Content:

 

Black Hat Europe returns to London Dec. 3-6, 2018, with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-3154
PUBLISHED: 2020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
CVE-2019-17190
PUBLISHED: 2020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the...
CVE-2014-8161
PUBLISHED: 2020-01-27
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2014-9481
PUBLISHED: 2020-01-27
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
CVE-2015-0241
PUBLISHED: 2020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric ...