OWASP "Automated threats" Overview
Overview
There are plenty of issues, that can stop internet business. In multiple cases organized criminals targeting companies websites and services, with simple goal to disrupt business and perform fraudulent operations. As more your business Internet-oriented as much you're exposing yourself to such kind of attacks. Typical misconception is "my website too small to be targeted". Criminals, especially organized, often using automated attacks to multiply their "revenue". Automated attacks can target services relatively randomly, and impact equally small and big companies. Let's take a look on types of attacks and how to protect your business.
OWASP Classification
Community of information security engineers supporting open industry classification for web threats. In this post we will mainly focus on "automated" attacks. We will try to group them and propose protection measures. Also this post will start series of detailed explanations for each threat "class". List of threats really long, but we will group them base on possible impact.
Big class of attacks related to simulation of user activities by attacker. In that case attacker orchestrating distributed system (botnet) to perform actions same as normal users will do on your website. But with multiple implications for you, consider that instead of real humans, you will have traffic from bots. Actions can be performed within existing business processes implemented by your service, but because this processes used automatically, you will have no outcome. Simply speaking bots can register accounts, but it will not grow your user base. Bots can purchase, but in the end - without generating revenue. Bots can click on Ad banners, but will never buy advertised product. In the end bots are impacting your budget, and budget of your customers.
- OAT-019 Account Creation
- OAT-003 Ad Fraud
- OAT-006 Expediting
- OAT-005 Scalping
- OAT-011 Scraping
- OAT-016 Skewing
- OAT-013 Sniping
Attacks aimed on compromising service protection measures. These attacks trying to bypass authentication and authorization system, compromise different users credentials to gain control on users accounts. Next step after this collection of user personal data, and steal user assets making operations on behalf of user.
- OAT-009 CAPTCHA Defeat
- OAT-007 Credential Cracking
- OAT-008 Credential Stuffing
- OAT-002 Token Cracking
Several threats in that list not actual "threats" by themselves, but more a reconnaissance technics, used by attackers to find weak spot in your application before attack. Collect some information, which can ease future attack on your service, or collect some user data to attack other services (this often can lead to leakage of personal data).
- OAT-004 Fingerprinting
- OAT-018 Footprinting
- OAT-014 Vulnerability Scanning
- OAT-020 Account Aggregation
There actual attacks, aiming do disrupt your business in a first place:
This attacks, usually, performed with botnets and in most cases characterized by massive amount of similar requests to your service. This requests consuming all capacity of your infrastructure and doesn't allow normal users access your website. Spam attacks are quite special case here, they can keep your web service available for clients, but not usable, and from that point of view spam attacks very close to Denial of Service.
Several attacks aimed not on your service directly, but onto your customers. This is equally painful for business and creates additional risks related to issues with prosecution services and regulators.
After introducing that classification, in the next blog post we will talk about protection and mitigation measures.
