SlideShare uma empresa Scribd logo
1 de 38
Baixar para ler offline
© 2019 Akamai | Confidential1
Trust No One City Tour
What is a bot and why you
should care
Xavier Daspre
Sr. Cloud Security Architect - EMEA
© 2019 Akamai | Confidential2
AGENDA
• Understanding the bot problem
• Bots families
• Nice business
• Wrap up
© 2019 Akamai | Confidential3
What is a bot ?
© 2019 Akamai | Confidential4
THE “BOT PROBLEM”
Understanding the bots…
Your site traffic What you think your traffic looks
like
What your traffic actually looks
like
© 2019 Akamai | Confidential5
Those who eat
© 2019 Akamai | Confidential6
How to scrap digital content
Protect content
© 2019 Akamai | Confidential7
Scrap and consume
© 2019 Akamai | Confidential8
Transactional Endpoints- Two Classes of Bots
1. Scraping Bots
2. Transactional Bots
Example1 : Price Scraping (Good or Bad)
Example2 : Content Scraping (Good or Bad)
Example3 : Google Web Crawler (Good)
© 2019 Akamai | Confidential9
Transactional Endpoints- Two Types
1. Scraping Bots
2. Transactional Bots
Example 1 : Login Attack :: Credential Abuse (Bad)
Example 2 : Fake Account Signup (Bad)
Example 3 : Concert Ticket Grabbers (Bad)
© 2019 Akamai | Confidential10
Those who attack
© 2019 Akamai | Confidential11
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
Sign In
CS
User name
Password
© 2019 Akamai | Confidential12
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
CS
User nameXavie
PasswordLet’s talk credential stuff
Sign InSign In
in
r
g
© 2019 Akamai | Confidential13
© 2019 Akamai | Confidential14
© 2019 Akamai | Confidential15
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
Sign In
CS
Xavier
Let’s talk credential stuffing
© 2019 Akamai | Confidential16
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
Sign In
CS
Xavier
Let’s talk credential
Sign In
stuffing
© 2019 Akamai | Confidential17
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
Sign In
ABC
User name
Password
© 2019 Akamai | Confidential18
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
ABC
User nameXavier
PasswordLet’s talk credential
Sign InSign In
stuffing
© 2019 Akamai | Confidential19
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
Sign In
AFF
User name
Password
© 2019 Akamai | Confidential20
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
AFF
User nameXavier
PasswordLet’s talk credential
Sign InSign In
stuffing
© 2019 Akamai | Confidential21
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
My-Carrier 12:00 PM 21%
Edit
Hello!
Sign in to access your money.
Sign In
User name
Password
© 2019 Akamai | Confidential22
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
My-Carrier 12:00 PM 21%
Edit
Hello!
Sign in to access your money.
Sign In
User nameXavier
PasswordLet’s talk credential
Sign In
stuffing
© 2019 Akamai | Confidential23
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
Xavier D paid Joe Smith
for the lulz
Like Comment $-1,999.00
1m
Xavier D paid AdultFriendFinder
for XoXoXo
Like Comment $-1,000.00
1m
Xavier D paid Need Mulaah
for alcohol and drugs
Like Comment $-1,500.00
1m
Xavier D paid YouGotPwned
for 10QSucka
Like Comment $-1,999.00
1m
Xavier D
@Xavier_D
Member since Yesterday
Account balance: $6,500.00
My-Carrier 12:00 PM 21%
Edit
$4,501.00$3,501.00$2,001.00$2.00
2m
3m
4m
2m
3m
2m
© 2019 Akamai | Confidential24
Grow revenue opportunities with fast, personalized
web experiences and manage complexity from peak
demand, mobile devices and data collection.
Xavier D paid YouGotPwned
for 10QSucka
Like Comment $-1,999.00
1m
Xavier D paid Need Mulaah
for alcohol and drugs
Like Comment $-1,500.00
2m
Xavier D paid AdultFriendFinder
for XoXoXo
Like Comment $-1,000.00
3m
Xavier D paid Joe Smith
for the lulz
Like Comment $-1,999.00
4m
Xavier D paid YouGotPwned, Need Mulaah,
AdultFriendFinder, and Joe Smith
Like Comment WTF?
$-6,498.00
Xavier D
@Xavier_D
Member since Yesterday
Account balance: $2.00
My-Carrier 12:00 PM 21%
Edit
© 2019 Akamai | Confidential25
Xavier D paid YouGotPwned, Need Mulaah,
AdultFriendFinder, and Joe Smith
Like Comment WTF?
$-6,498.00
Xavier D
@Xavier_D
Member since Yesterday
Account balance: $2.00
My-Carrier 12:00 PM 21%
Edit
WTF?
© 2019 Akamai | Confidential26
Credential Abuse to ATO
© 2019 Akamai | Confidential27
Darknet insight : Sales !
© 2019 Akamai | Confidential28
Darknet insight : Sell the valued accounts
© 2019 Akamai | Confidential29
Money lost to fraud per
compromised account
25%
29%
22%
14%
10%
Less
than
$100
$100
to
$500
$501
to
$1,000
$1,001
to
$5,000
More
than
$5,000
Ponemon—The Cost of Credential Stuffing, Oct 2017
BUSINESS IMPACT
Understanding the cost of credential stuffing
Number of accounts
targeted per attack
19%
35%
28%
11%
7%
1 to
100
101 to
500
501 to
1,000
1,001
to
5,000
More
than
5,000
Number of credential
stuffing attacks per month
0%
41%
38%
12%
9%
None 1 to 5 6 to 10 11 to
20
More
than
21
© 2019 Akamai | Confidential30
Industry IPs Participating Login Requests % of Total Requests
Gaming 7,712,894 1,358,045,044 61.30%
Hotels & Resorts 122,026 232,309,946 10.49%
Cards & Payments 477,507 148,304,255 6.69%
Department Stores 326,151 104,748,065 4.73%
Commerce Portal 66,321 60,199,822 2.72%
Banking 349,474 55,356,808 2.50%
Airline 86,346 41,004,594 1.85%
Cosmetics 82,808 38,197,524 1.72%
Consumer Software (B2C) 224,707 28,202,339 1.27%
Social Media 127,396 26,557,605 1.20%
Enterprise Software (B2B) 21,290 25,383,158 1.15%
Consumer Electronics 50,984 25,264,381 1.14%
Apparel & Footwear 66,414 19,692,260 0.89%
Online Travel Agents 102,555 8,935,366 0.40%
Federal 3,403 7,454,257 0.34%
INDUSTRY BREAKDOWN
A 1-week view into Akamai customers
© 2019 Akamai | Confidential31
• Majority of IPs performing credential
stuffing make less than 1 request
per minute
• Average is 28 requests per hour
• Maximum request rate observed
from a single IP during the sampled
period - 625,000 requests per hour
(173 login requests per seconds)
Rate Controls are only effective against the rare bots that fall outside typical human request rate thresholds
ATTACK CHARACTERISTICS
What an attack looks like
© 2019 Akamai | Confidential32
CONSEQUENCES
Wide-ranging impacts of credential stuffing
5%
17%
41%
43%
50%
63%
67%
Other
Damaged brand equity from news
stories or social media
Lost business due to customers
switching to competitors
Compromised accounts leading to
fraud-related financial losses
Lower customer satisfaction
Cost to remediate compromised
accounts
Application downtime from large
spikes in login traffic
© 2019 Akamai | Confidential33
RESPONSIBILITY
Dispersed throughout the organization
5%
2%
3%
3%
9%
13%
16%
20%
21%
28%
3%
40%
Other
Compliance / audit
CEO / COO
Head of legal
Data center / IT…
Web hosting service…
Head of risk…
CISO / CSO
Fraud prevention /…
CIO / CTO
Line of business /…
No one function has…
© 2019 Akamai | Confidential34
IP Rate
Limiting
Network
Header
Analysis
Browser
Property
Analysis
BM Premier exploits ”what makes us human”.
Neuro-muscular interaction is much harder for
machine scripts to replicate.
Traditional Methods : Less Effective
against Credential Abuse.
How Akamai approaches the challenge
© 2019 Akamai | Confidential35
Conclusion
© 2019 Akamai | Confidential36
Achieving desired outcomes
AKAMAI DIFFERENCE
Ability to manage bot traffic on the Akamai
CDN before it reaches your website,
offloading your origin infrastructure
The latest technologies that can detect the
most sophisticated bots today even as they
evolve to avoid detection
Real-time intelligence from visibility into bot
traffic interacting with many of the largest web
presences around the world
Ability to manage wide array of both good and
bad bots and customize response based on
your business and IT goals
Granular visibility / reporting allows you to
analyze your bot traffic and implement your
bot strategy without being a black box
Security experts who can help implement
and tune your bot management strategy and
respond to security events
© 2019 Akamai | Confidential3737 | Akamai Nordics City Tour | © 2019 Akamai | Confidential
Thanks for your attention
Questions ?!
© 2019 Akamai | Confidential38

Mais conteúdo relacionado

Mais procurados

Transform with Cloud to drive your Future | AWS Summit Tel Aviv 2019
Transform with Cloud to drive your Future | AWS Summit Tel Aviv 2019Transform with Cloud to drive your Future | AWS Summit Tel Aviv 2019
Transform with Cloud to drive your Future | AWS Summit Tel Aviv 2019Amazon Web Services
 
Building AR-VR applications on AWS
Building AR-VR applications on AWSBuilding AR-VR applications on AWS
Building AR-VR applications on AWSAmazon Web Services
 
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics ServicesAWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics ServicesAWS Summits
 
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and TricksAWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and TricksAWS Summits
 
AWS Summit Singapore 2019 | Realising Business Value
AWS Summit Singapore 2019 | Realising Business ValueAWS Summit Singapore 2019 | Realising Business Value
AWS Summit Singapore 2019 | Realising Business ValueAWS Summits
 
Trends in Digital Transformation by Joe Chung
Trends in Digital Transformation by Joe ChungTrends in Digital Transformation by Joe Chung
Trends in Digital Transformation by Joe ChungSameer Kenkare
 
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...Symantec
 
AWS Summit Singapore 2019 | Microsoft DevOps on AWS
AWS Summit Singapore 2019 | Microsoft DevOps on AWSAWS Summit Singapore 2019 | Microsoft DevOps on AWS
AWS Summit Singapore 2019 | Microsoft DevOps on AWSAWS Summits
 
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWSAWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWSAWS Summits
 
AWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
AWS Summit Singapore 2019 | Amazon Digital User Engagement SolutionsAWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
AWS Summit Singapore 2019 | Amazon Digital User Engagement SolutionsAWS Summits
 
A culture of rapid innovation with DevOps, microservices, & serverless - MAD2...
A culture of rapid innovation with DevOps, microservices, & serverless - MAD2...A culture of rapid innovation with DevOps, microservices, & serverless - MAD2...
A culture of rapid innovation with DevOps, microservices, & serverless - MAD2...Amazon Web Services
 
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...AWS Summits
 
¿Qué significa Transformación Digital para las Empresas?
¿Qué significa Transformación Digital para las Empresas?¿Qué significa Transformación Digital para las Empresas?
¿Qué significa Transformación Digital para las Empresas?Amazon Web Services LATAM
 
Why the Future of Analytics is Cloud - AWS Summit Sydney
Why the Future of Analytics is Cloud - AWS Summit Sydney Why the Future of Analytics is Cloud - AWS Summit Sydney
Why the Future of Analytics is Cloud - AWS Summit Sydney Amazon Web Services
 
Amazon digital user engagement solutions - SVC221 - New York AWS Summit
Amazon digital user engagement solutions - SVC221 - New York AWS SummitAmazon digital user engagement solutions - SVC221 - New York AWS Summit
Amazon digital user engagement solutions - SVC221 - New York AWS SummitAmazon Web Services
 
Managing Security on AWS
Managing Security on AWSManaging Security on AWS
Managing Security on AWSAWS Summits
 
Alexa Voice Services by Linda Lian
Alexa Voice Services by Linda LianAlexa Voice Services by Linda Lian
Alexa Voice Services by Linda LianSameer Kenkare
 
Top Cloud Security Myths Dispelled
Top Cloud Security Myths DispelledTop Cloud Security Myths Dispelled
Top Cloud Security Myths DispelledAmazon Web Services
 

Mais procurados (20)

Transform with Cloud to drive your Future | AWS Summit Tel Aviv 2019
Transform with Cloud to drive your Future | AWS Summit Tel Aviv 2019Transform with Cloud to drive your Future | AWS Summit Tel Aviv 2019
Transform with Cloud to drive your Future | AWS Summit Tel Aviv 2019
 
Building AR-VR applications on AWS
Building AR-VR applications on AWSBuilding AR-VR applications on AWS
Building AR-VR applications on AWS
 
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics ServicesAWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
AWS Summit Singapore 2019 | Realising Business Value with AWS Analytics Services
 
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and TricksAWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
AWS Summit Singapore 2019 | Hiring a Global Rock Star Team: Tips and Tricks
 
AWS Summit Singapore 2019 | Realising Business Value
AWS Summit Singapore 2019 | Realising Business ValueAWS Summit Singapore 2019 | Realising Business Value
AWS Summit Singapore 2019 | Realising Business Value
 
Trends in Digital Transformation by Joe Chung
Trends in Digital Transformation by Joe ChungTrends in Digital Transformation by Joe Chung
Trends in Digital Transformation by Joe Chung
 
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
 
AWS Summit Singapore 2019 | Microsoft DevOps on AWS
AWS Summit Singapore 2019 | Microsoft DevOps on AWSAWS Summit Singapore 2019 | Microsoft DevOps on AWS
AWS Summit Singapore 2019 | Microsoft DevOps on AWS
 
樂居科技_AWS Startup day
樂居科技_AWS Startup day樂居科技_AWS Startup day
樂居科技_AWS Startup day
 
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWSAWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
AWS Summit Singapore 2019 | Driving Business Outcomes with Data Lake on AWS
 
AWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
AWS Summit Singapore 2019 | Amazon Digital User Engagement SolutionsAWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
AWS Summit Singapore 2019 | Amazon Digital User Engagement Solutions
 
A culture of rapid innovation with DevOps, microservices, & serverless - MAD2...
A culture of rapid innovation with DevOps, microservices, & serverless - MAD2...A culture of rapid innovation with DevOps, microservices, & serverless - MAD2...
A culture of rapid innovation with DevOps, microservices, & serverless - MAD2...
 
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
AWS Summit Singapore 2019 | The Serverless Lifecycle: Development and Operati...
 
¿Qué significa Transformación Digital para las Empresas?
¿Qué significa Transformación Digital para las Empresas?¿Qué significa Transformación Digital para las Empresas?
¿Qué significa Transformación Digital para las Empresas?
 
Why the Future of Analytics is Cloud - AWS Summit Sydney
Why the Future of Analytics is Cloud - AWS Summit Sydney Why the Future of Analytics is Cloud - AWS Summit Sydney
Why the Future of Analytics is Cloud - AWS Summit Sydney
 
Amazon digital user engagement solutions - SVC221 - New York AWS Summit
Amazon digital user engagement solutions - SVC221 - New York AWS SummitAmazon digital user engagement solutions - SVC221 - New York AWS Summit
Amazon digital user engagement solutions - SVC221 - New York AWS Summit
 
Managing Security on AWS
Managing Security on AWSManaging Security on AWS
Managing Security on AWS
 
Alexa Voice Services by Linda Lian
Alexa Voice Services by Linda LianAlexa Voice Services by Linda Lian
Alexa Voice Services by Linda Lian
 
Top Cloud Security Myths Dispelled
Top Cloud Security Myths DispelledTop Cloud Security Myths Dispelled
Top Cloud Security Myths Dispelled
 
AWS Startup Day- softchef
AWS Startup Day- softchefAWS Startup Day- softchef
AWS Startup Day- softchef
 

Semelhante a What is a Bot and why you should care

AWS re:Invent Comes to London 2019 - Cashflow, Customer Experience & Risk
AWS re:Invent Comes to London 2019 - Cashflow, Customer Experience & RiskAWS re:Invent Comes to London 2019 - Cashflow, Customer Experience & Risk
AWS re:Invent Comes to London 2019 - Cashflow, Customer Experience & RiskAmazon Web Services
 
人工智慧雲服務與金融服務應用
人工智慧雲服務與金融服務應用人工智慧雲服務與金融服務應用
人工智慧雲服務與金融服務應用Amazon Web Services
 
Becoming A High Frequency Enterprise
Becoming A High Frequency EnterpriseBecoming A High Frequency Enterprise
Becoming A High Frequency EnterpriseAmazon Web Services
 
Find IT & Marketing’s Common Ground: Make Your Site Faster
Find IT & Marketing’s Common Ground: Make Your Site FasterFind IT & Marketing’s Common Ground: Make Your Site Faster
Find IT & Marketing’s Common Ground: Make Your Site FasterGhostery, Inc.
 
AWS Startup Day Santiago - Taram: Fundraising Essentials
AWS Startup Day Santiago - Taram: Fundraising EssentialsAWS Startup Day Santiago - Taram: Fundraising Essentials
AWS Startup Day Santiago - Taram: Fundraising EssentialsAmazon Web Services LATAM
 
Bot Manager + Cloudlet Strengthen Mitigation Capability
Bot Manager + Cloudlet Strengthen Mitigation CapabilityBot Manager + Cloudlet Strengthen Mitigation Capability
Bot Manager + Cloudlet Strengthen Mitigation CapabilityAkamai Developers & Admins
 
2016: The Year to Align Marketing & IT Departments
2016: The Year to Align Marketing & IT Departments2016: The Year to Align Marketing & IT Departments
2016: The Year to Align Marketing & IT DepartmentsYottaa
 
Keynote_AWS_BecomingAHighFrequencyEnterprise
Keynote_AWS_BecomingAHighFrequencyEnterpriseKeynote_AWS_BecomingAHighFrequencyEnterprise
Keynote_AWS_BecomingAHighFrequencyEnterpriseAmazon Web Services
 
Creating New Models To Combat Business Email Compromise
Creating New Models To Combat Business Email CompromiseCreating New Models To Combat Business Email Compromise
Creating New Models To Combat Business Email CompromisePriyanka Aash
 
AWS Startup Day Bogotá - Fundraising Essentials: Raising a Seed Round Efficie...
AWS Startup Day Bogotá - Fundraising Essentials: Raising a Seed Round Efficie...AWS Startup Day Bogotá - Fundraising Essentials: Raising a Seed Round Efficie...
AWS Startup Day Bogotá - Fundraising Essentials: Raising a Seed Round Efficie...Amazon Web Services LATAM
 
Fundraising Essentials for Every Entrepreneur
Fundraising Essentials for Every EntrepreneurFundraising Essentials for Every Entrepreneur
Fundraising Essentials for Every EntrepreneurAmazon Web Services
 
클라우드 세상에서 CIO로 살아남기 - 이한주 대표이사, Bespin Global :: AWS Summit Seoul 2019
클라우드 세상에서 CIO로 살아남기 - 이한주 대표이사, Bespin Global :: AWS Summit Seoul 2019클라우드 세상에서 CIO로 살아남기 - 이한주 대표이사, Bespin Global :: AWS Summit Seoul 2019
클라우드 세상에서 CIO로 살아남기 - 이한주 대표이사, Bespin Global :: AWS Summit Seoul 2019Amazon Web Services Korea
 
Operando em Escala Preparando-se para a jornada
Operando em EscalaPreparando-se para a jornadaOperando em EscalaPreparando-se para a jornada
Operando em Escala Preparando-se para a jornadaAmazon Web Services LATAM
 
SaaStock 2019 - elizabeth cain
SaaStock 2019 - elizabeth cainSaaStock 2019 - elizabeth cain
SaaStock 2019 - elizabeth cainSaaStock
 
Webinar: Making the Move from Legacy IAM to Modern Digital Identity – On Your...
Webinar: Making the Move from Legacy IAM to Modern Digital Identity – On Your...Webinar: Making the Move from Legacy IAM to Modern Digital Identity – On Your...
Webinar: Making the Move from Legacy IAM to Modern Digital Identity – On Your...IdentityNorthEvents
 
The economics of incidents, and creative ways to thwart future threats - SEP3...
The economics of incidents, and creative ways to thwart future threats - SEP3...The economics of incidents, and creative ways to thwart future threats - SEP3...
The economics of incidents, and creative ways to thwart future threats - SEP3...Amazon Web Services
 
Leadership Session: Cloud Adoption and the Future of Financial Services (FSV2...
Leadership Session: Cloud Adoption and the Future of Financial Services (FSV2...Leadership Session: Cloud Adoption and the Future of Financial Services (FSV2...
Leadership Session: Cloud Adoption and the Future of Financial Services (FSV2...Amazon Web Services
 
Migrate-Critical-Workload-to-AWS-From-Domain-Driven-Design-perspective
Migrate-Critical-Workload-to-AWS-From-Domain-Driven-Design-perspectiveMigrate-Critical-Workload-to-AWS-From-Domain-Driven-Design-perspective
Migrate-Critical-Workload-to-AWS-From-Domain-Driven-Design-perspectiveAmazon Web Services
 
2019 Expansion SaaS Benchmarks
2019 Expansion SaaS Benchmarks2019 Expansion SaaS Benchmarks
2019 Expansion SaaS BenchmarksOpenView
 

Semelhante a What is a Bot and why you should care (20)

AWS re:Invent Comes to London 2019 - Cashflow, Customer Experience & Risk
AWS re:Invent Comes to London 2019 - Cashflow, Customer Experience & RiskAWS re:Invent Comes to London 2019 - Cashflow, Customer Experience & Risk
AWS re:Invent Comes to London 2019 - Cashflow, Customer Experience & Risk
 
人工智慧雲服務與金融服務應用
人工智慧雲服務與金融服務應用人工智慧雲服務與金融服務應用
人工智慧雲服務與金融服務應用
 
Becoming A High Frequency Enterprise
Becoming A High Frequency EnterpriseBecoming A High Frequency Enterprise
Becoming A High Frequency Enterprise
 
Find IT & Marketing’s Common Ground: Make Your Site Faster
Find IT & Marketing’s Common Ground: Make Your Site FasterFind IT & Marketing’s Common Ground: Make Your Site Faster
Find IT & Marketing’s Common Ground: Make Your Site Faster
 
AWS Startup Day Santiago - Taram: Fundraising Essentials
AWS Startup Day Santiago - Taram: Fundraising EssentialsAWS Startup Day Santiago - Taram: Fundraising Essentials
AWS Startup Day Santiago - Taram: Fundraising Essentials
 
Bot Manager + Cloudlet Strengthen Mitigation Capability
Bot Manager + Cloudlet Strengthen Mitigation CapabilityBot Manager + Cloudlet Strengthen Mitigation Capability
Bot Manager + Cloudlet Strengthen Mitigation Capability
 
2016: The Year to Align Marketing & IT Departments
2016: The Year to Align Marketing & IT Departments2016: The Year to Align Marketing & IT Departments
2016: The Year to Align Marketing & IT Departments
 
Keynote_AWS_BecomingAHighFrequencyEnterprise
Keynote_AWS_BecomingAHighFrequencyEnterpriseKeynote_AWS_BecomingAHighFrequencyEnterprise
Keynote_AWS_BecomingAHighFrequencyEnterprise
 
Creating New Models To Combat Business Email Compromise
Creating New Models To Combat Business Email CompromiseCreating New Models To Combat Business Email Compromise
Creating New Models To Combat Business Email Compromise
 
AWS Startup Day Bogotá - Fundraising Essentials: Raising a Seed Round Efficie...
AWS Startup Day Bogotá - Fundraising Essentials: Raising a Seed Round Efficie...AWS Startup Day Bogotá - Fundraising Essentials: Raising a Seed Round Efficie...
AWS Startup Day Bogotá - Fundraising Essentials: Raising a Seed Round Efficie...
 
Fundraising Essentials for Every Entrepreneur
Fundraising Essentials for Every EntrepreneurFundraising Essentials for Every Entrepreneur
Fundraising Essentials for Every Entrepreneur
 
클라우드 세상에서 CIO로 살아남기 - 이한주 대표이사, Bespin Global :: AWS Summit Seoul 2019
클라우드 세상에서 CIO로 살아남기 - 이한주 대표이사, Bespin Global :: AWS Summit Seoul 2019클라우드 세상에서 CIO로 살아남기 - 이한주 대표이사, Bespin Global :: AWS Summit Seoul 2019
클라우드 세상에서 CIO로 살아남기 - 이한주 대표이사, Bespin Global :: AWS Summit Seoul 2019
 
Operando em Escala Preparando-se para a jornada
Operando em EscalaPreparando-se para a jornadaOperando em EscalaPreparando-se para a jornada
Operando em Escala Preparando-se para a jornada
 
SaaStock 2019 - elizabeth cain
SaaStock 2019 - elizabeth cainSaaStock 2019 - elizabeth cain
SaaStock 2019 - elizabeth cain
 
AWS Startup Day Guadalajara - Fundraising
AWS Startup Day Guadalajara - FundraisingAWS Startup Day Guadalajara - Fundraising
AWS Startup Day Guadalajara - Fundraising
 
Webinar: Making the Move from Legacy IAM to Modern Digital Identity – On Your...
Webinar: Making the Move from Legacy IAM to Modern Digital Identity – On Your...Webinar: Making the Move from Legacy IAM to Modern Digital Identity – On Your...
Webinar: Making the Move from Legacy IAM to Modern Digital Identity – On Your...
 
The economics of incidents, and creative ways to thwart future threats - SEP3...
The economics of incidents, and creative ways to thwart future threats - SEP3...The economics of incidents, and creative ways to thwart future threats - SEP3...
The economics of incidents, and creative ways to thwart future threats - SEP3...
 
Leadership Session: Cloud Adoption and the Future of Financial Services (FSV2...
Leadership Session: Cloud Adoption and the Future of Financial Services (FSV2...Leadership Session: Cloud Adoption and the Future of Financial Services (FSV2...
Leadership Session: Cloud Adoption and the Future of Financial Services (FSV2...
 
Migrate-Critical-Workload-to-AWS-From-Domain-Driven-Design-perspective
Migrate-Critical-Workload-to-AWS-From-Domain-Driven-Design-perspectiveMigrate-Critical-Workload-to-AWS-From-Domain-Driven-Design-perspective
Migrate-Critical-Workload-to-AWS-From-Domain-Driven-Design-perspective
 
2019 Expansion SaaS Benchmarks
2019 Expansion SaaS Benchmarks2019 Expansion SaaS Benchmarks
2019 Expansion SaaS Benchmarks
 

Mais de Elisabeth Bitsch-Christensen

Datadriven organizations and the digital customer journey
Datadriven organizations and the digital customer journeyDatadriven organizations and the digital customer journey
Datadriven organizations and the digital customer journeyElisabeth Bitsch-Christensen
 
Creating a datadriven news room - Expressen in Sweden
Creating a datadriven news room - Expressen in SwedenCreating a datadriven news room - Expressen in Sweden
Creating a datadriven news room - Expressen in SwedenElisabeth Bitsch-Christensen
 
Social Airlines and Customer Experience in Social Media
Social Airlines and Customer Experience in Social MediaSocial Airlines and Customer Experience in Social Media
Social Airlines and Customer Experience in Social MediaElisabeth Bitsch-Christensen
 
The digital journey in 8 steps: from catalog to content and digital
The digital journey in 8 steps: from catalog to content and digitalThe digital journey in 8 steps: from catalog to content and digital
The digital journey in 8 steps: from catalog to content and digitalElisabeth Bitsch-Christensen
 
Digital CMO - Dataföreningens Nätverk För Marketing Professionals
Digital CMO - Dataföreningens Nätverk För Marketing ProfessionalsDigital CMO - Dataföreningens Nätverk För Marketing Professionals
Digital CMO - Dataföreningens Nätverk För Marketing ProfessionalsElisabeth Bitsch-Christensen
 
The ROI of Social Media - Show me the money presented at Sweden Social Web Ca...
The ROI of Social Media - Show me the money presented at Sweden Social Web Ca...The ROI of Social Media - Show me the money presented at Sweden Social Web Ca...
The ROI of Social Media - Show me the money presented at Sweden Social Web Ca...Elisabeth Bitsch-Christensen
 

Mais de Elisabeth Bitsch-Christensen (15)

Trust No One - Zero Trust on the Akamai Platform
Trust No One - Zero Trust on the Akamai PlatformTrust No One - Zero Trust on the Akamai Platform
Trust No One - Zero Trust on the Akamai Platform
 
Designing for API Doomsday
Designing for API DoomsdayDesigning for API Doomsday
Designing for API Doomsday
 
The Akamai Security Portfolio
The Akamai Security PortfolioThe Akamai Security Portfolio
The Akamai Security Portfolio
 
Datadriven organizations and the digital customer journey
Datadriven organizations and the digital customer journeyDatadriven organizations and the digital customer journey
Datadriven organizations and the digital customer journey
 
Creating a datadriven news room - Expressen in Sweden
Creating a datadriven news room - Expressen in SwedenCreating a datadriven news room - Expressen in Sweden
Creating a datadriven news room - Expressen in Sweden
 
Social Airlines and Customer Experience in Social Media
Social Airlines and Customer Experience in Social MediaSocial Airlines and Customer Experience in Social Media
Social Airlines and Customer Experience in Social Media
 
The digital journey in 8 steps: from catalog to content and digital
The digital journey in 8 steps: from catalog to content and digitalThe digital journey in 8 steps: from catalog to content and digital
The digital journey in 8 steps: from catalog to content and digital
 
Digital CMO - Dataföreningens Nätverk För Marketing Professionals
Digital CMO - Dataföreningens Nätverk För Marketing ProfessionalsDigital CMO - Dataföreningens Nätverk För Marketing Professionals
Digital CMO - Dataföreningens Nätverk För Marketing Professionals
 
Hermods gymnasium-4-feb (1)
Hermods gymnasium-4-feb (1)Hermods gymnasium-4-feb (1)
Hermods gymnasium-4-feb (1)
 
Digital Strategy in Presidential Elections
Digital Strategy in Presidential ElectionsDigital Strategy in Presidential Elections
Digital Strategy in Presidential Elections
 
Engagement marketing: Influence the Influencer
Engagement marketing: Influence the InfluencerEngagement marketing: Influence the Influencer
Engagement marketing: Influence the Influencer
 
CCT Nordics Stockholm 10.15 Gallery
CCT Nordics Stockholm 10.15 GalleryCCT Nordics Stockholm 10.15 Gallery
CCT Nordics Stockholm 10.15 Gallery
 
The ROI of Social Media - Show me the money presented at Sweden Social Web Ca...
The ROI of Social Media - Show me the money presented at Sweden Social Web Ca...The ROI of Social Media - Show me the money presented at Sweden Social Web Ca...
The ROI of Social Media - Show me the money presented at Sweden Social Web Ca...
 
Web forumsocialairlines
Web forumsocialairlinesWeb forumsocialairlines
Web forumsocialairlines
 
SSMX SocialAirlines
SSMX SocialAirlinesSSMX SocialAirlines
SSMX SocialAirlines
 

Último

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfOverkill Security
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKJago de Vreede
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfOverkill Security
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 

Último (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 

What is a Bot and why you should care

  • 1. © 2019 Akamai | Confidential1 Trust No One City Tour What is a bot and why you should care Xavier Daspre Sr. Cloud Security Architect - EMEA
  • 2. © 2019 Akamai | Confidential2 AGENDA • Understanding the bot problem • Bots families • Nice business • Wrap up
  • 3. © 2019 Akamai | Confidential3 What is a bot ?
  • 4. © 2019 Akamai | Confidential4 THE “BOT PROBLEM” Understanding the bots… Your site traffic What you think your traffic looks like What your traffic actually looks like
  • 5. © 2019 Akamai | Confidential5 Those who eat
  • 6. © 2019 Akamai | Confidential6 How to scrap digital content Protect content
  • 7. © 2019 Akamai | Confidential7 Scrap and consume
  • 8. © 2019 Akamai | Confidential8 Transactional Endpoints- Two Classes of Bots 1. Scraping Bots 2. Transactional Bots Example1 : Price Scraping (Good or Bad) Example2 : Content Scraping (Good or Bad) Example3 : Google Web Crawler (Good)
  • 9. © 2019 Akamai | Confidential9 Transactional Endpoints- Two Types 1. Scraping Bots 2. Transactional Bots Example 1 : Login Attack :: Credential Abuse (Bad) Example 2 : Fake Account Signup (Bad) Example 3 : Concert Ticket Grabbers (Bad)
  • 10. © 2019 Akamai | Confidential10 Those who attack
  • 11. © 2019 Akamai | Confidential11 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. Sign In CS User name Password
  • 12. © 2019 Akamai | Confidential12 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. CS User nameXavie PasswordLet’s talk credential stuff Sign InSign In in r g
  • 13. © 2019 Akamai | Confidential13
  • 14. © 2019 Akamai | Confidential14
  • 15. © 2019 Akamai | Confidential15 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. Sign In CS Xavier Let’s talk credential stuffing
  • 16. © 2019 Akamai | Confidential16 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. Sign In CS Xavier Let’s talk credential Sign In stuffing
  • 17. © 2019 Akamai | Confidential17 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. Sign In ABC User name Password
  • 18. © 2019 Akamai | Confidential18 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. ABC User nameXavier PasswordLet’s talk credential Sign InSign In stuffing
  • 19. © 2019 Akamai | Confidential19 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. Sign In AFF User name Password
  • 20. © 2019 Akamai | Confidential20 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. AFF User nameXavier PasswordLet’s talk credential Sign InSign In stuffing
  • 21. © 2019 Akamai | Confidential21 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. My-Carrier 12:00 PM 21% Edit Hello! Sign in to access your money. Sign In User name Password
  • 22. © 2019 Akamai | Confidential22 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. My-Carrier 12:00 PM 21% Edit Hello! Sign in to access your money. Sign In User nameXavier PasswordLet’s talk credential Sign In stuffing
  • 23. © 2019 Akamai | Confidential23 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. Xavier D paid Joe Smith for the lulz Like Comment $-1,999.00 1m Xavier D paid AdultFriendFinder for XoXoXo Like Comment $-1,000.00 1m Xavier D paid Need Mulaah for alcohol and drugs Like Comment $-1,500.00 1m Xavier D paid YouGotPwned for 10QSucka Like Comment $-1,999.00 1m Xavier D @Xavier_D Member since Yesterday Account balance: $6,500.00 My-Carrier 12:00 PM 21% Edit $4,501.00$3,501.00$2,001.00$2.00 2m 3m 4m 2m 3m 2m
  • 24. © 2019 Akamai | Confidential24 Grow revenue opportunities with fast, personalized web experiences and manage complexity from peak demand, mobile devices and data collection. Xavier D paid YouGotPwned for 10QSucka Like Comment $-1,999.00 1m Xavier D paid Need Mulaah for alcohol and drugs Like Comment $-1,500.00 2m Xavier D paid AdultFriendFinder for XoXoXo Like Comment $-1,000.00 3m Xavier D paid Joe Smith for the lulz Like Comment $-1,999.00 4m Xavier D paid YouGotPwned, Need Mulaah, AdultFriendFinder, and Joe Smith Like Comment WTF? $-6,498.00 Xavier D @Xavier_D Member since Yesterday Account balance: $2.00 My-Carrier 12:00 PM 21% Edit
  • 25. © 2019 Akamai | Confidential25 Xavier D paid YouGotPwned, Need Mulaah, AdultFriendFinder, and Joe Smith Like Comment WTF? $-6,498.00 Xavier D @Xavier_D Member since Yesterday Account balance: $2.00 My-Carrier 12:00 PM 21% Edit WTF?
  • 26. © 2019 Akamai | Confidential26 Credential Abuse to ATO
  • 27. © 2019 Akamai | Confidential27 Darknet insight : Sales !
  • 28. © 2019 Akamai | Confidential28 Darknet insight : Sell the valued accounts
  • 29. © 2019 Akamai | Confidential29 Money lost to fraud per compromised account 25% 29% 22% 14% 10% Less than $100 $100 to $500 $501 to $1,000 $1,001 to $5,000 More than $5,000 Ponemon—The Cost of Credential Stuffing, Oct 2017 BUSINESS IMPACT Understanding the cost of credential stuffing Number of accounts targeted per attack 19% 35% 28% 11% 7% 1 to 100 101 to 500 501 to 1,000 1,001 to 5,000 More than 5,000 Number of credential stuffing attacks per month 0% 41% 38% 12% 9% None 1 to 5 6 to 10 11 to 20 More than 21
  • 30. © 2019 Akamai | Confidential30 Industry IPs Participating Login Requests % of Total Requests Gaming 7,712,894 1,358,045,044 61.30% Hotels & Resorts 122,026 232,309,946 10.49% Cards & Payments 477,507 148,304,255 6.69% Department Stores 326,151 104,748,065 4.73% Commerce Portal 66,321 60,199,822 2.72% Banking 349,474 55,356,808 2.50% Airline 86,346 41,004,594 1.85% Cosmetics 82,808 38,197,524 1.72% Consumer Software (B2C) 224,707 28,202,339 1.27% Social Media 127,396 26,557,605 1.20% Enterprise Software (B2B) 21,290 25,383,158 1.15% Consumer Electronics 50,984 25,264,381 1.14% Apparel & Footwear 66,414 19,692,260 0.89% Online Travel Agents 102,555 8,935,366 0.40% Federal 3,403 7,454,257 0.34% INDUSTRY BREAKDOWN A 1-week view into Akamai customers
  • 31. © 2019 Akamai | Confidential31 • Majority of IPs performing credential stuffing make less than 1 request per minute • Average is 28 requests per hour • Maximum request rate observed from a single IP during the sampled period - 625,000 requests per hour (173 login requests per seconds) Rate Controls are only effective against the rare bots that fall outside typical human request rate thresholds ATTACK CHARACTERISTICS What an attack looks like
  • 32. © 2019 Akamai | Confidential32 CONSEQUENCES Wide-ranging impacts of credential stuffing 5% 17% 41% 43% 50% 63% 67% Other Damaged brand equity from news stories or social media Lost business due to customers switching to competitors Compromised accounts leading to fraud-related financial losses Lower customer satisfaction Cost to remediate compromised accounts Application downtime from large spikes in login traffic
  • 33. © 2019 Akamai | Confidential33 RESPONSIBILITY Dispersed throughout the organization 5% 2% 3% 3% 9% 13% 16% 20% 21% 28% 3% 40% Other Compliance / audit CEO / COO Head of legal Data center / IT… Web hosting service… Head of risk… CISO / CSO Fraud prevention /… CIO / CTO Line of business /… No one function has…
  • 34. © 2019 Akamai | Confidential34 IP Rate Limiting Network Header Analysis Browser Property Analysis BM Premier exploits ”what makes us human”. Neuro-muscular interaction is much harder for machine scripts to replicate. Traditional Methods : Less Effective against Credential Abuse. How Akamai approaches the challenge
  • 35. © 2019 Akamai | Confidential35 Conclusion
  • 36. © 2019 Akamai | Confidential36 Achieving desired outcomes AKAMAI DIFFERENCE Ability to manage bot traffic on the Akamai CDN before it reaches your website, offloading your origin infrastructure The latest technologies that can detect the most sophisticated bots today even as they evolve to avoid detection Real-time intelligence from visibility into bot traffic interacting with many of the largest web presences around the world Ability to manage wide array of both good and bad bots and customize response based on your business and IT goals Granular visibility / reporting allows you to analyze your bot traffic and implement your bot strategy without being a black box Security experts who can help implement and tune your bot management strategy and respond to security events
  • 37. © 2019 Akamai | Confidential3737 | Akamai Nordics City Tour | © 2019 Akamai | Confidential Thanks for your attention Questions ?!
  • 38. © 2019 Akamai | Confidential38