HomeBusinessBusinesses: Are they ready to face the threat of bots?

Businesses: Are they ready to face the threat of bots?

Businesses know that bots pose a major threat to their security and sensitive data. However, they don’t seem to be doing enough to mitigate the threat and the problems it poses. This perception reflects the findings of a new study by Netacea, which examined data across the travel, entertainment, e-commerce and financial services industries.


The survey found a high level of awareness of how attacks can have a negative and damaging impact on a business. Specifically, over 70% of businesses believe they are aware of the most common bot, including credential stuffing and card cracking. However, 76% reported having been the victim of a bot attack.

bots

The survey, titled “The Bot Management Review: The Challenge of High Awareness and Limited Understanding,”also found that the same businesses said that only 15% of their web application resources are occupied by bots. According to the survey, this shows that businesses are not prepared to address and mitigate a potential bot attack. Given that over half of web traffic is now generated by bots, businesses are unaware of much of the bot traffic on their sites. The survey also reported that businesses are unaware of dark web sites, where usernames and passwords , with only 1% of respondents saying they are aware of these sites.

bots - attacks

Who is responsible for addressing bot attacks?
The survey found that only 1 in 10 businesses say that mitigating bots is the responsibility of a single department or individual. Additionally, about two-thirds said it is the responsibility of four or more departments to address the problem. In addition, businesses can often ignore the problem altogether. Harish Siripurapu, founder of Cyber ​​Align, said that some organizations may be confused by the type of attacks that typically occur with bots.


The main problem is that credential stuffing attacks are a gray area between cybersecurity and fraud. Hacking into a customer’s account using credentials found on the dark webis fraud and scam, but not necessarily a cyberattack, Siripurapu explained. He added that even in companies where CISOs are responsible for e-commerce security, fraud and scamsare usually not managed by them. Siripurapu also noted that bot detection technologies are not on the security roadmap, so there is a lack of visibility and awareness. DDoS attacks are the attacks that attract the attention of CISOs in most organizations.

bots

These days, credential stuffing is one of the most well-known attack methods used by botnet criminals. The most recent Verizon Data Breach Investigations Report (DBIR) from 2019 states that credential stuffing was used in 29% of data breaches.

Credential stuffing has been ranked as the world’s number one security threat for several years now and has been steadily increasing since the term was coined in 2011, said Shuman Ghosemajumder, head of global artificial intelligence (AI) at F5. He added that measuring bot activity is difficult, and he suggests that security teams who want to detect bots as accurately as possible should use the best technology they can afford. Just as different analytics products measure users differently, most technologies to have both false positives and false negatives when it comes to detecting highly sophisticated bots.


Finally, Netacea's research showed that almost all businesses are either investing or planning to invest in bot management, while almost none are cutting back on such technologies.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS