Cequence Security Releases EMA Findings on Detecting and Thwarting Automated Bot Attacks
Findings Provide Fresh Insight into Automated Bot Attacks, and the New Mitigation Strategies Succeeding for Major Organizations.
SUNNYVALE, Calif. – May 05, 2020 — Cequence Security today published research findings on automated bot attacks, developed with Enterprise Management Associates (EMA), focusing on the automated malicious bot attacks targeting public-facing API and web-based applications.
The study “The Imitation Game: Detecting and Thwarting Automated Bot Attacks” was developed by EMA and Cequence based on responses from hundreds of IT and IT security teams about the many ways by which their public-facing web, mobile, and API-based applications are targeted by automated bot attack campaigns. The study found that inexpensive, easily launched automated malicious bot attacks exploit the business logic of these applications to hijack user accounts, create fake accounts, scrape content, carry out application distributed denial of service attacks, and launch other types of attacks.
Among key findings:
- 85 percent of all respondents believe they are a target for automated attacks including account takeovers, application denial of service and fake account creation,
- A mere 17 percent of the respondents felt their APIs were a primary target with the number expected to increase (not because of more visibility) but because of more APIs being built into applications. In contrast, 60 percent of who believe their organization’s web-based applications are the primary target.
- The survey finds that 57% of the respondents regularly see attackers relaunch attacks from the same source in an effort to thwart the initial detection, highlighting the sophistication and agility of the attack campaigns.