Some botnets are capable of a million attacks per hour

Dec 12, 2018 21:15 GMT  ·  By

According to an Osterman Research report, 211 large organizations with a mean of 16,822 employees have reported that during most weeks they experienced an average of 3,700 bot attacks targeting Internet exposed web apps.

Bot attacks (also known as botnet attacks) make use of large numbers of connected computers to try and take down entire networks, websites, or enterprise IT environments, as well as infiltrate computing systems to exfiltrate sensitive data.

This type of attack is designed to disrupt a company's day to day operations as much as possible or degrading the quality of the overall service provided by the targeted company.

Bot attacks will also try and compromise their targets using brute-force to infiltrate their victims' computing systems to steal funds, as well as send payment information and intellectual property to the actors behind this type of malicious campaign.

Osterman Research's report "found that a mean of more than 3,700 such attacks occur in the typical organization that we surveyed, although some large organizations are experiencing upwards of several million attempted incursions per day. In a single attack, some bots can launch well over one million per hour."

Bot attacks on cloud apps to surge during future campaigns

Out of the large variety of bot attacks reported by most large companies, the most common ones are click/ad fraud, application DDoS attacks, and company account takeovers.

Furthermore, although most bot attacks are focused on local network assets, attacks targeted at cloud apps will be the subject of a dramatic increase in the future as detailed in the report.

"Organizations most commonly use web application firewalls (WAFs) to manage bot attacks, but intrusion protection/intrusion prevention (IPS/IDS) solutions and security information and management systems (SIEMs) are also used," according to the survey's results.

To conclude, even though most companies that took part in the survey stated that bot management tools are essential to comply with industry regulations, only around one-third of them said that they use a such a tool.