Photo Showing Hypothetical Malware Code on Screen
© Przemek Klos/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Malicious bots have become more sophisticated and elusive over the past decade, posing a threat to all, cybersecurity firm Imperva said in a recent report, revealing that bad bots were responsible for about 30 percent of all internet traffic in 2022.

Imperva’s 2023 Bad Bot Report, published on May 10, warns that application programming interfaces (APIs) are a prime target for automated attacks. While bad bots affect all industries, travel, retail, and financial services are the most targeted industries.

“Bad bots interact with applications like legitimate users would, making them harder to detect and block. They abuse business logic by exploiting the way a business operates, rather than exploiting technical vulnerabilities,” Imperva explained in its report. “They enable high-speed abuse, misuse, and attacks on websites, mobile apps, and APIs.”

These bots use various techniques to evade detection, including “cycling through random IPs, entering through anonymous proxies, changing their identities, mimicking human behavior, delaying requests, defeating CAPTCHA challenges, and more,” Imperva said.

Imperva’s findings are based on data collected from its global network in 2022 — including six trillion blocked requests from bad bots.

How Bad Bots are Used

“Gone are the days where you can effectively protect your site from bad bots with just a few tweaks and configurations,” Peter Klimek, director of technology, Office of the CTO at Imperva, said in an email to VPNOverview.

According to Imperva, bad bots are used in criminal schemes like “web scraping, competitive data mining, personal and financial data harvesting, brute-force login, scalping, digital ad fraud, denial of service, spam, transaction fraud, and more.”

Furthermore, bots “consume bandwidth, slow down servers, and steal sensitive data, leading to financial losses and damage to a company’s reputation.”

Bad bots were once rudimentary tools used to send spam emails. Today, they have evolved into dangerous malware commonly used for DDoS attacks, malicious code injection, fraud, and disrupting critical infrastructure.

Cybercriminals increasingly use bad bots to target APIs in account takeover attacks, and Imperva expects this trend to continue.

“With 17% of all the attacks targeting APIs in 2022 coming from bots that sought to abuse business logic, every organization should expect to see an increase in automated attacks targeting their APIs in the coming years,” Klimek said.

“The challenge with protecting APIs from bad bots is that all traffic looks the same to the API, as they’re designed for automated clients. What’s more, APIs lack built-in defense mechanisms, and returning a CAPTCHA challenge to an API request breaks the calling application. This makes it difficult to detect and block malicious bot traffic while enabling attackers to use automation without the risk of raising any alarms,” he explained.

Bad Bots’ Evasive Maneuvers

Imperva revealed that advanced-level bots can now solve CAPTCHA by leveraging various platforms and tools.

The report also highlights the growing use of proxies and P2P (peer-to-peer) networks that allow bad bots to evade detection by cycling IP addresses and login credentials.

“Now more than ever, we are seeing bad bots employ a wide variety of evasion methods,” such as making it appear like “the requests are being made from different browsers, changing their user agents, and more,” the report said.

“They often choose a “low and slow” approach, which enables them to carry out significant attacks using fewer requests and even delay requests, allowing them to not stand out from the normal traffic patterns and avoid triggering rate-based security direction thresholds,” Imperva added.

The report noted a dramatic increase in the use of Apple’s Safari iPhone browser as a preferred disguise, exploiting its privacy settings and attributes. In this case, bad bots imitate human users, allowing them to go unnoticed. According to Imperva, this is usually done using browser automation software.

“What started as an advanced evasion technique a decade ago is now a commodity across most, if not all, bad bots,” the report said.

Safari is the mobile browser of choice for bad bots, closely followed by Google Chrome.

To protect against bots masquerading as browsers, Klimek recommends that organizations identify what functionalities and pages on their site could expose them to bot attacks and evaluate their traffic “rigorously” for signs of bot activity.

“Strong indications of bot traffic include: high bounce rates, low conversion rates, or unexplained traffic spikes to a particular URL. Seeing an increase in traffic or failures on login or checkout pages? Those could also be signs of bot traffic!” he explained.

Defending Against Malicious Automated Bots

Imperva’s recommendations for defending against bad bots include protecting exposed APIs and apps, blocking access from outdated browsers and bulk IP data centers, and using a bot management solution.

“Organizations need to implement a bot management solution that can identify and stop sophisticated automation that targets APIs and application business logic, while not affecting the experience of legitimate users,” Klimek said. “To do this, organizations should implement a solution with machine learning, device fingerprinting, and behavioral analysis built-in that can pinpoint anomalies specific to your site’s unique traffic patterns.”

For high-traffic parts of a site, Klimek recommends more “aggressive protection measures—such as block, allow, CAPTCHA, force-identify, monitor, challenge, rate-limit, delay, tarpit, and more.”

Automated bots can be chained to create a “botnet” (a bot network). Find out just how dangerous this threat is and how to protect your systems in our extensive guide to botnets. You can protect their device from botnet attacks with an antivirus that offers real-time protection. We’ve tested several antivirus solutions. You can learn about our experience and top picks in our article on the best antivirus software.

Leave a comment