BOT Attack and Data Security Overview
All most all organizations face cyber attacks from many types such as Brute Force Attack, Data Security Breach, Encrypted web attack, Web Scraping, SQL Injection, Cross-site scripting etc.
Sometimes attackers use automated attack programs where “BOT” works instead of attacker direct.
In other words, BOT attack refers to automated web requests (written scripts) used by attackers to manipulate website, application, API and end users. Sometimes attackers send SPAM emails, lauch DDoS attacks using this BOTs. Generally it is carried by BOTNETS, which are networks of infected, unpatched systems controlled centrally by attackers and that follow set of instructions or patterns as programmed.
BOTS make traditional attack vector more effective, faster and with larger impact. Example of BOT driven attack are as;
- Web scraping
- Web Application DDoS
- Brute Force attack
- Credential Stuffing
- Account takeover fraud
- Ticketing BOT attack
- Websites
- Online ecommerce sites
- Financial firms
- Individuals
- Healthcare firms
- Data Breach
- Web or Server downtime
- Regulatory Penalty
- Reputational Damage
- 45% of respondents report that they suffered a data breach, including 45% in the financial Services sector, 45% in retail and 46% in healthcare.
- More than 60% are not confident that they can quickly detect application-layer attacks, including 59% in financial services, 67% in retail and 67% in healthcare.
- More than 70% are not confident their organization can protect itself against an application-layer DDoS Attack, including 66% in financial services, 68% in retail and 70% in healthcare.
- Nearly 60% of respondents do not track sensitive data they share with third parties once the data leaves the corporate network.
- Approximately 70% of organizations fail to protect credit card data online.
- Monitor the incoming traffic in real time.
- Use firewalls and next gen firewalls in the network.
- Strengthen Authentication process.
- Strengthen User awareness.
No comments:
Post a Comment