SlideShare a Scribd company logo
1 of 36
#RSPS15
#RSPS15
StubHub's Field Guide To Preventing Competitor
Price Scraping, Unwanted Transactions, Brute Force
Attacks, And Click Fraud
SPONSORED BY:
#RSPS15
#RSPS15
Retail Touchpoints: @RTouchPoints
Distil Networks: @Distil
Marty Boos: @StubHub
Rami Essaid: @RamiEssaid
Alicia Fiorletta: @AliciaFiorletta
Follow this event on LinkedIn & Twitter
#RSPS15
Questions, Tweets & Resources
Submit your
questions
here
Download
today’s
resources
Join the
conversation
#RSPS15
#RSPS15
About Retail TouchPoints
 Launched in 2007
 Over 30,000 retail subscribers
 To provide executives with relevant,
insightful content across a variety of
digital medium
Sign up for our weekly newsletter:
www.retailtouchpoints.com/subscribe
#RSPS15
Panelists
MODERATOR:
Alicia Fiorletta
Senior Editor, Retail TouchPoints
Rami Essaid
CEO & Co-Founder
Distil Networks
@ramiessaid
Marty Boos
Sr. Director Technology Operations
StubHub
@StubHub
StubHub’s Field Guide to Preventing Competitor Price
Scraping, Unwanted Transactions, Brute Force Attacks, and
Click Fraud
Agenda
The growing bot problem
The impact of bots on e-commerce businesses
How StubHub squashed malicious bots
Selection criteria for a bot detection solution
Q & A
What Is Web Scraping?
Web Scraping
Also known as screen scraping, web scraping is the act of
copying large amounts of data from a website – either
manually or with an automated program (Bot)
Legitimate Scraping
Scraping can sometimes be benevolent and totally
acceptable. For example, the search engine bots that index
your website
Malicious Scraping
A systematic theft of intellectual property accessible on a
website, including pricing, content, images, and proprietary
data
Web Scraping at Large Online Beauty Retailer
Black Friday saw a
100x Increase in
Bad Bots
Challenges Distil Results
Competitors were scraping product and pricing data,
using it to lure customers away
Stopped competitors from scraping pricing and product data by
blocking bad bots
Traffic from malicious bots was consuming server
resources and slowing site performance
Eliminated bad bot traffic, cutting server resource needs by
22% while improving performance
Tracking suspicious IP addresses manually was a
tedious manual process
Automated the bot detection and mitigation process, saving
valuable IT resources
Beauty Retailer Clamps Down on Competitive Data Mining
One of Europe’s largest
online beauty retailers.
We have a handful of competitors that cause us a lot of
headaches. With Distil, we’ve stopped them from scraping our
data, which protects our competitive advantage. In addition,
we’ve reduced the load by 22%, and our customers experience
faster response times. ”
-Principal Solutions Developer
“
How Big is the Problem?
Up to 60% of traffic on ecommerce websites are Bad Bots
4.2 million IP addresses impacted by “Pushdo” botnet alone
15% bot traffic can equate to hitting each of your pricing pages
30 times per month
Why the Massive Increase in Bot Traffic?
Online data has increased in value
Pricing information, product availability, product
descriptions, and vendor reviews are changing
daily and highly valuable to competitors
Anyone can get in the game
Cheap or free virtual servers, bandwidth, easy-to-
use tools, and scrapers for hire
Bots no longer tied to IP addresses
Bots cycle through random IP addresses
Bots hide behind anonymous proxies
Consumer IPs now infected with bot traffic too
High Profile Web Scraping in the Ecommerce
Industry
QVC is an American television home shopping
network and online ecommerce site.
Aggressive price and inventory scraping by shopping aggregator app
resulted in the following repercussions for QVC
● Two day website outage
● Loss of $2M in revenue
● Highly publicized lawsuit
● Damage to QVC Brand
Negative SEO Attacks
Bots steal content, product lists, and prices for
duplication elsewhere on the Internet
Duplicated content reduces your company’s
uniqueness and thus quality score
SEO damage may result, especially if
○Your prices are undercut
○The content is repurposed on a more popular site
Bots and Negative SEO Attacks
Bots and Competitive Data Mining
Duplicating your Product Portfolio
Bots can easily gather product and supplier lists
for replication elsewhere
Undermining your Prices
Bots monitor your prices, ensuring competitors
can undercut with lower price listings
Availability Tracking
Identifying when your supply has been exhausted provides competitors a unique
opportunity to raise the price of their goods.
Bots and Security Breaches
Brute Force Account Takeover
Using a bot to try stolen usernames and passwords from
breaches at other websites on your site
Newly compromised accounts are then used for various forms
of fraud/theft
Bots and Transaction Fraud
Carding
Creating micro-transactions with stolen credit cards
against e-commerce sites to test their validity
About StubHub
Largest secondary ticket marketplace in the world
An eBay company
Processes nearly 500 transactions per second
StubHub is an online marketplace which provides
services for buyers and sellers of tickets for sports,
concerts, theater and other live entertainment
events.
StubHub Bot Challenges
Bot Challenges
○ Bots were used for brute force account takeovers
○ Competitors tried to game the system, scraping prices, and
monitoring inventory and customer behavior
○ Random spikes in bot traffic were causing increased utilization
of resources
○ Tested multiple competitor solutions, but they were difficult to
configure and in some cases broke our website
StubHub Bot Selection Criteria
Bot Detection and Mitigation Solution Requirements
○Block web scrapers without impacting human visitors
○Accurately identify good bots vs. bad bots
○Cannot solely rely on rule based system
Must include automated learning to “self tune”for defending against emerging
and unknown threats
○Needs to include Distil community to improve accuracy of bot detection
○Must seamlessly co-exist with existing solutions
(SIEM, CDN, WAF, etc.)
StubHub Results with Distil Networks
Reduced competitive data mining and fraud
Drastically reduced competitive data mining,
increased SEO rankings, and protected our
marketplace ecosystem
Distil is a key piece of our fraud detection and
prevention suite of tools
StubHub Results with Distil Networks
Improved traffic quality and enriched
analytic data
Cut pageviews in half, without impacting
human users or ad deliveries
Quality of traffic has greatly improved by
stopping unwanted bots and limiting site
access for trusted bots
Negative Security Model - Blocking Bad Bots
Positive Security Model - Whitelisting Trusted
Sources
The Importance of No False Positives / Negative Impact on
Humans
Good bots make up over 35% of all traffic to the average website
○ Search engines - Google, Bing, Baidu, etc.,
○ Alexa Crawler
○ Pingdom, Keynote, etc.
Effective solutions block bad bots but leave good bots unhindered
The Importance of Accurately Identifying Good vs Bad Bots
Source: Distil Networks,
2015 Bad Bot Landscape Report
Bot detection should never rely on static signatures or manual rule creation
Automation and machine learning must be performed in real-time
Effective bot mitigation solutions
○Dynamically classify users by correlating dozens of data points
as well as behavior patterns
○Constantly “self-tune” to evolve alongside
the morphing threats they encounter and protect against
The Importance of Machine Learning and Self
Tuning
○ Real-time updates from a centralized violators database help protect
all sites and improve accuracy
○ Data from attacks detected anywhere on the network should be
centralized, correlated, and analyzed by a big data analysis platform
○ Signatures are then constantly updated to
drastically reduce false positives (blocking humans)
and false negatives (missing bad bots)
The Importance of Community Supported Centralized Threat
Database
Many organizations have complex web environments which may include a
multitude of different solutions including
○ Content Delivery Networks (CDNs)
○ WAFs, FW, IPS
○ SIEMs
○ Load balancers
○ and more..
Bot mitigation must be able to seamlessly deployed alongside these
technologies without impacting their performance or usage
The Importance of Seamless Compatibility
The First Easy and Accurate Way to Defend
Websites Against Malicious Bots
The World’s Most Accurate Bot Detection
System
Inline Fingerprinting
Fingerprints stick to the bot even if it attempts to
reconnect from random IP addresses or hide behind an
anonymous proxy.
Known Violators Database
Real-time updates from the world’s largest Known
Violators Database, which is based on the collective
intelligence of all Distil-protected sites.
Browser Validation
The first solution to disallow browser spoofing by
validating each incoming request as self-reported and
detects all known browser automation tools.
Behavioral Modeling and Machine Learning
Machine-learning algorithms pinpoint behavioral
anomalies specific to your site’s unique traffic patterns.
How Ecommerce Companies Benefit from
Distil
Increase insight & control
over human, good bot &
bad bot traffic
Block 99.9% of
malicious bots without
impacting legitimate
users
Slash the high tax bots
place on internal teams
& web infrastructure
Protect data from web
scrapers, unauthorized
aggregators & hackers
www.distilnetworks.com/trial/
Offer Ends October 15th
Two Months of Free Service + Traffic
Analysis
QUESTIONS….COMMENTS
?I N F O @ D I S T I L N E T W O R K S . C O M
OR CALL US ON
1.866.423.0606
www.distilnetworks.com
#RSPS15
Q & A // Panelists
MODERATOR:
Alicia Fiorletta
Senior Editor, Retail TouchPoints
Rami Essaid
CEO & Co-Founder
Distil Networks
@ramiessaid
Marty Boos
Sr. Director Technology Operations
StubHub
@StubHub
#RSPS15
http://www3.retailtouchpoints.com/rsp15/
PLEASE JOIN US FOR OUR NEXT SESSION:
Today at 2PM ET / 11AM PT
Thanks for attending!

More Related Content

What's hot

Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!Distil Networks
 
Ias guide ad fraud essentials_2017 (1)
Ias guide ad fraud essentials_2017 (1)Ias guide ad fraud essentials_2017 (1)
Ias guide ad fraud essentials_2017 (1)Wossname
 
Bot Benchmark study - White Ops & DCN
Bot Benchmark study - White Ops & DCNBot Benchmark study - White Ops & DCN
Bot Benchmark study - White Ops & DCNWhite Ops
 
Rtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deckRtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deckG3 Communications
 
2015 Bot Baseline Report - White Ops & ANA
2015 Bot Baseline Report - White Ops & ANA2015 Bot Baseline Report - White Ops & ANA
2015 Bot Baseline Report - White Ops & ANAWhite Ops
 
The Many Faces of Ad Fraud
The Many Faces of Ad FraudThe Many Faces of Ad Fraud
The Many Faces of Ad FraudWhite Ops
 
White Ops & Videology Whitepaper
White Ops & Videology WhitepaperWhite Ops & Videology Whitepaper
White Ops & Videology WhitepaperWhite Ops
 
Presentation - How to do Fraud like Vietnamese
Presentation - How to do Fraud like VietnamesePresentation - How to do Fraud like Vietnamese
Presentation - How to do Fraud like VietnameseKevin Nguyen
 
Ensuring Property Portal Listing Data Security
Ensuring Property Portal Listing Data SecurityEnsuring Property Portal Listing Data Security
Ensuring Property Portal Listing Data SecurityDistil Networks
 
easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...
easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...
easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...tnooz
 
The Murky Waters of the Internet: Anatomy of Malvertising and Other e-Threats
The Murky Waters of the Internet: Anatomy of Malvertising and Other e-ThreatsThe Murky Waters of the Internet: Anatomy of Malvertising and Other e-Threats
The Murky Waters of the Internet: Anatomy of Malvertising and Other e-Threats- Mark - Fullbright
 
The Wrong Impression | Adfraud
The Wrong Impression | AdfraudThe Wrong Impression | Adfraud
The Wrong Impression | AdfraudAditya Labhe
 
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website DefendersDistil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website DefendersEnterprise Management Associates
 
Bp Corp Pres Short
Bp Corp Pres ShortBp Corp Pres Short
Bp Corp Pres Shortkevinjoy
 
Revenue sources-for-copyright-infringing-sites-in-eu-march-2015
Revenue sources-for-copyright-infringing-sites-in-eu-march-2015Revenue sources-for-copyright-infringing-sites-in-eu-march-2015
Revenue sources-for-copyright-infringing-sites-in-eu-march-2015Raffaella Natale
 
Fraud & Abuse Report 2020 by Arkose LabsFraud report q1 2020
Fraud & Abuse Report 2020 by Arkose LabsFraud report q1 2020Fraud & Abuse Report 2020 by Arkose LabsFraud report q1 2020
Fraud & Abuse Report 2020 by Arkose LabsFraud report q1 2020Jeff Martinez
 
Kaspersky lab financial_cyberthreats_in_2017
Kaspersky lab financial_cyberthreats_in_2017Kaspersky lab financial_cyberthreats_in_2017
Kaspersky lab financial_cyberthreats_in_2017malvvv
 

What's hot (20)

Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!
 
Ias guide ad fraud essentials_2017 (1)
Ias guide ad fraud essentials_2017 (1)Ias guide ad fraud essentials_2017 (1)
Ias guide ad fraud essentials_2017 (1)
 
Digital ad fraud superheroes the good guys by augustine fou
Digital ad fraud superheroes the good guys by augustine fouDigital ad fraud superheroes the good guys by augustine fou
Digital ad fraud superheroes the good guys by augustine fou
 
Bot Benchmark study - White Ops & DCN
Bot Benchmark study - White Ops & DCNBot Benchmark study - White Ops & DCN
Bot Benchmark study - White Ops & DCN
 
Rtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deckRtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deck
 
2015 Bot Baseline Report - White Ops & ANA
2015 Bot Baseline Report - White Ops & ANA2015 Bot Baseline Report - White Ops & ANA
2015 Bot Baseline Report - White Ops & ANA
 
IAB Best Practices Traffic Fraud Final
IAB Best Practices Traffic Fraud FinalIAB Best Practices Traffic Fraud Final
IAB Best Practices Traffic Fraud Final
 
The Many Faces of Ad Fraud
The Many Faces of Ad FraudThe Many Faces of Ad Fraud
The Many Faces of Ad Fraud
 
White Ops & Videology Whitepaper
White Ops & Videology WhitepaperWhite Ops & Videology Whitepaper
White Ops & Videology Whitepaper
 
Presentation - How to do Fraud like Vietnamese
Presentation - How to do Fraud like VietnamesePresentation - How to do Fraud like Vietnamese
Presentation - How to do Fraud like Vietnamese
 
Ensuring Property Portal Listing Data Security
Ensuring Property Portal Listing Data SecurityEnsuring Property Portal Listing Data Security
Ensuring Property Portal Listing Data Security
 
easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...
easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...
easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...
 
The Murky Waters of the Internet: Anatomy of Malvertising and Other e-Threats
The Murky Waters of the Internet: Anatomy of Malvertising and Other e-ThreatsThe Murky Waters of the Internet: Anatomy of Malvertising and Other e-Threats
The Murky Waters of the Internet: Anatomy of Malvertising and Other e-Threats
 
The Wrong Impression | Adfraud
The Wrong Impression | AdfraudThe Wrong Impression | Adfraud
The Wrong Impression | Adfraud
 
Ways To Think About Solving Digital Ad Fraud Augustine Fou Mike Moran Ted McC...
Ways To Think About Solving Digital Ad Fraud Augustine Fou Mike Moran Ted McC...Ways To Think About Solving Digital Ad Fraud Augustine Fou Mike Moran Ted McC...
Ways To Think About Solving Digital Ad Fraud Augustine Fou Mike Moran Ted McC...
 
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website DefendersDistil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
 
Bp Corp Pres Short
Bp Corp Pres ShortBp Corp Pres Short
Bp Corp Pres Short
 
Revenue sources-for-copyright-infringing-sites-in-eu-march-2015
Revenue sources-for-copyright-infringing-sites-in-eu-march-2015Revenue sources-for-copyright-infringing-sites-in-eu-march-2015
Revenue sources-for-copyright-infringing-sites-in-eu-march-2015
 
Fraud & Abuse Report 2020 by Arkose LabsFraud report q1 2020
Fraud & Abuse Report 2020 by Arkose LabsFraud report q1 2020Fraud & Abuse Report 2020 by Arkose LabsFraud report q1 2020
Fraud & Abuse Report 2020 by Arkose LabsFraud report q1 2020
 
Kaspersky lab financial_cyberthreats_in_2017
Kaspersky lab financial_cyberthreats_in_2017Kaspersky lab financial_cyberthreats_in_2017
Kaspersky lab financial_cyberthreats_in_2017
 

Similar to Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Are Bot Operators Eating Your Lunch?
Are Bot Operators Eating Your Lunch?Are Bot Operators Eating Your Lunch?
Are Bot Operators Eating Your Lunch?Distil Networks
 
Bot how to find them 2014_27_03
Bot how to find them 2014_27_03Bot how to find them 2014_27_03
Bot how to find them 2014_27_03IABmembership
 
Iab bots how to_find_them_webinar_2014_03_27
Iab bots how to_find_them_webinar_2014_03_27Iab bots how to_find_them_webinar_2014_03_27
Iab bots how to_find_them_webinar_2014_03_27IABmembership
 
How to clean up travel website traffic from bots and spammers?
How to clean up travel website traffic from bots and spammers?How to clean up travel website traffic from bots and spammers?
How to clean up travel website traffic from bots and spammers?tnooz
 
Cleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammersCleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammersDistil Networks
 
Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상
Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상
Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상Jean Ryu
 
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...Property Portal Watch
 
How the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem
How the BOTS Act Impacts Premium Onsales and the Ticketing Industry EcosystemHow the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem
How the BOTS Act Impacts Premium Onsales and the Ticketing Industry EcosystemDistil Networks
 
Ana White OPS - the bot baseline - fraud in digital advertising - 2015
Ana White OPS - the bot baseline - fraud in digital advertising - 2015Ana White OPS - the bot baseline - fraud in digital advertising - 2015
Ana White OPS - the bot baseline - fraud in digital advertising - 2015Romain Fonnier
 
Fraud in Digital Advertising (ANA study)
Fraud in Digital Advertising (ANA study)Fraud in Digital Advertising (ANA study)
Fraud in Digital Advertising (ANA study)Margarita Zlatkova
 
The Bot Baseline - Fraud in Digital Advertising
The Bot Baseline - Fraud in Digital AdvertisingThe Bot Baseline - Fraud in Digital Advertising
The Bot Baseline - Fraud in Digital Advertisingyann le gigan
 
Bot detection deck 042514 final
Bot detection deck 042514 finalBot detection deck 042514 final
Bot detection deck 042514 finalVindicoGroup
 
How bots impact major onsales [Webinar]
How bots impact major onsales [Webinar]How bots impact major onsales [Webinar]
How bots impact major onsales [Webinar]Queue-it
 
DEFCON 23 - Mark Ryan Talabis - The Bieber Project
DEFCON 23 - Mark Ryan Talabis - The Bieber ProjectDEFCON 23 - Mark Ryan Talabis - The Bieber Project
DEFCON 23 - Mark Ryan Talabis - The Bieber ProjectFelipe Prado
 
45 key vendors and thier online fraud prevention solutions
45 key vendors and thier online fraud prevention solutions45 key vendors and thier online fraud prevention solutions
45 key vendors and thier online fraud prevention solutionsRasool Irfan
 
How to use Online Marketing Technology to Improve Campaign Performance - Lowe...
How to use Online Marketing Technology to Improve Campaign Performance - Lowe...How to use Online Marketing Technology to Improve Campaign Performance - Lowe...
How to use Online Marketing Technology to Improve Campaign Performance - Lowe...Online Marketing Summit
 
Artificial Intelligence: How Enterprises Can Crush It With Apache Spark: Keyn...
Artificial Intelligence: How Enterprises Can Crush It With Apache Spark: Keyn...Artificial Intelligence: How Enterprises Can Crush It With Apache Spark: Keyn...
Artificial Intelligence: How Enterprises Can Crush It With Apache Spark: Keyn...Spark Summit
 

Similar to Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud (20)

Are Bot Operators Eating Your Lunch?
Are Bot Operators Eating Your Lunch?Are Bot Operators Eating Your Lunch?
Are Bot Operators Eating Your Lunch?
 
Bot how to find them 2014_27_03
Bot how to find them 2014_27_03Bot how to find them 2014_27_03
Bot how to find them 2014_27_03
 
Iab bots how to_find_them_webinar_2014_03_27
Iab bots how to_find_them_webinar_2014_03_27Iab bots how to_find_them_webinar_2014_03_27
Iab bots how to_find_them_webinar_2014_03_27
 
How to clean up travel website traffic from bots and spammers?
How to clean up travel website traffic from bots and spammers?How to clean up travel website traffic from bots and spammers?
How to clean up travel website traffic from bots and spammers?
 
Cleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammersCleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammers
 
Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상
Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상
Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상
 
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
 
Botman Profile Deck
Botman Profile DeckBotman Profile Deck
Botman Profile Deck
 
How the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem
How the BOTS Act Impacts Premium Onsales and the Ticketing Industry EcosystemHow the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem
How the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem
 
Ana White OPS - the bot baseline - fraud in digital advertising - 2015
Ana White OPS - the bot baseline - fraud in digital advertising - 2015Ana White OPS - the bot baseline - fraud in digital advertising - 2015
Ana White OPS - the bot baseline - fraud in digital advertising - 2015
 
Fraud in Digital Advertising (ANA study)
Fraud in Digital Advertising (ANA study)Fraud in Digital Advertising (ANA study)
Fraud in Digital Advertising (ANA study)
 
The Bot Baseline - Fraud in Digital Advertising
The Bot Baseline - Fraud in Digital AdvertisingThe Bot Baseline - Fraud in Digital Advertising
The Bot Baseline - Fraud in Digital Advertising
 
How To Protect Your Website From Bot Attacks
How To Protect Your Website From Bot AttacksHow To Protect Your Website From Bot Attacks
How To Protect Your Website From Bot Attacks
 
Independent Objective Reviews of Anti-Fraud Companies by Augustine Fou
Independent Objective Reviews of Anti-Fraud Companies by Augustine FouIndependent Objective Reviews of Anti-Fraud Companies by Augustine Fou
Independent Objective Reviews of Anti-Fraud Companies by Augustine Fou
 
Bot detection deck 042514 final
Bot detection deck 042514 finalBot detection deck 042514 final
Bot detection deck 042514 final
 
How bots impact major onsales [Webinar]
How bots impact major onsales [Webinar]How bots impact major onsales [Webinar]
How bots impact major onsales [Webinar]
 
DEFCON 23 - Mark Ryan Talabis - The Bieber Project
DEFCON 23 - Mark Ryan Talabis - The Bieber ProjectDEFCON 23 - Mark Ryan Talabis - The Bieber Project
DEFCON 23 - Mark Ryan Talabis - The Bieber Project
 
45 key vendors and thier online fraud prevention solutions
45 key vendors and thier online fraud prevention solutions45 key vendors and thier online fraud prevention solutions
45 key vendors and thier online fraud prevention solutions
 
How to use Online Marketing Technology to Improve Campaign Performance - Lowe...
How to use Online Marketing Technology to Improve Campaign Performance - Lowe...How to use Online Marketing Technology to Improve Campaign Performance - Lowe...
How to use Online Marketing Technology to Improve Campaign Performance - Lowe...
 
Artificial Intelligence: How Enterprises Can Crush It With Apache Spark: Keyn...
Artificial Intelligence: How Enterprises Can Crush It With Apache Spark: Keyn...Artificial Intelligence: How Enterprises Can Crush It With Apache Spark: Keyn...
Artificial Intelligence: How Enterprises Can Crush It With Apache Spark: Keyn...
 

Recently uploaded

Indian Call Girl In Dubai #$# O5634O3O18 #$# Dubai Call Girl
Indian Call Girl In Dubai #$# O5634O3O18 #$# Dubai Call GirlIndian Call Girl In Dubai #$# O5634O3O18 #$# Dubai Call Girl
Indian Call Girl In Dubai #$# O5634O3O18 #$# Dubai Call GirlAroojKhan71
 
Top Rated Pune Call Girls Talegaon Dabhade ⟟ 6297143586 ⟟ Call Me For Genuin...
Top Rated  Pune Call Girls Talegaon Dabhade ⟟ 6297143586 ⟟ Call Me For Genuin...Top Rated  Pune Call Girls Talegaon Dabhade ⟟ 6297143586 ⟟ Call Me For Genuin...
Top Rated Pune Call Girls Talegaon Dabhade ⟟ 6297143586 ⟟ Call Me For Genuin...Call Girls in Nagpur High Profile
 
Best VIP Call Girls Noida Sector 51 Call Me: 8448380779
Best VIP Call Girls Noida Sector 51 Call Me: 8448380779Best VIP Call Girls Noida Sector 51 Call Me: 8448380779
Best VIP Call Girls Noida Sector 51 Call Me: 8448380779Delhi Call girls
 
Dubai Call Girls O525547&19 (Asii) Call Girls Dubai
Dubai Call Girls O525547&19 (Asii) Call Girls DubaiDubai Call Girls O525547&19 (Asii) Call Girls Dubai
Dubai Call Girls O525547&19 (Asii) Call Girls Dubaikojalkojal131
 
The 15 Minute Breakdown: 2024 Beauty Marketing Study
The 15 Minute Breakdown: 2024 Beauty Marketing StudyThe 15 Minute Breakdown: 2024 Beauty Marketing Study
The 15 Minute Breakdown: 2024 Beauty Marketing StudyKatherineBishop4
 
The 15 Minute Breakdown: 2024 Beauty Marketing Study
The 15 Minute Breakdown: 2024 Beauty Marketing StudyThe 15 Minute Breakdown: 2024 Beauty Marketing Study
The 15 Minute Breakdown: 2024 Beauty Marketing StudyTinuiti
 
Best VIP Call Girls Noida Sector 50 Call Me: 8448380779
Best VIP Call Girls Noida Sector 50 Call Me: 8448380779Best VIP Call Girls Noida Sector 50 Call Me: 8448380779
Best VIP Call Girls Noida Sector 50 Call Me: 8448380779Delhi Call girls
 
Film= Dubai Call Girls O525547819 Call Girls Dubai Whsatapp
Film= Dubai Call Girls O525547819 Call Girls Dubai WhsatappFilm= Dubai Call Girls O525547819 Call Girls Dubai Whsatapp
Film= Dubai Call Girls O525547819 Call Girls Dubai Whsatappkojalkojal131
 
Supermarket Floral Ad Roundup- Week 17 2024.pdf
Supermarket Floral Ad Roundup- Week 17 2024.pdfSupermarket Floral Ad Roundup- Week 17 2024.pdf
Supermarket Floral Ad Roundup- Week 17 2024.pdfKarliNelson4
 
Best VIP Call Girls Noida Sector 55 Call Me: 8448380779
Best VIP Call Girls Noida Sector 55 Call Me: 8448380779Best VIP Call Girls Noida Sector 55 Call Me: 8448380779
Best VIP Call Girls Noida Sector 55 Call Me: 8448380779Delhi Call girls
 

Recently uploaded (10)

Indian Call Girl In Dubai #$# O5634O3O18 #$# Dubai Call Girl
Indian Call Girl In Dubai #$# O5634O3O18 #$# Dubai Call GirlIndian Call Girl In Dubai #$# O5634O3O18 #$# Dubai Call Girl
Indian Call Girl In Dubai #$# O5634O3O18 #$# Dubai Call Girl
 
Top Rated Pune Call Girls Talegaon Dabhade ⟟ 6297143586 ⟟ Call Me For Genuin...
Top Rated  Pune Call Girls Talegaon Dabhade ⟟ 6297143586 ⟟ Call Me For Genuin...Top Rated  Pune Call Girls Talegaon Dabhade ⟟ 6297143586 ⟟ Call Me For Genuin...
Top Rated Pune Call Girls Talegaon Dabhade ⟟ 6297143586 ⟟ Call Me For Genuin...
 
Best VIP Call Girls Noida Sector 51 Call Me: 8448380779
Best VIP Call Girls Noida Sector 51 Call Me: 8448380779Best VIP Call Girls Noida Sector 51 Call Me: 8448380779
Best VIP Call Girls Noida Sector 51 Call Me: 8448380779
 
Dubai Call Girls O525547&19 (Asii) Call Girls Dubai
Dubai Call Girls O525547&19 (Asii) Call Girls DubaiDubai Call Girls O525547&19 (Asii) Call Girls Dubai
Dubai Call Girls O525547&19 (Asii) Call Girls Dubai
 
The 15 Minute Breakdown: 2024 Beauty Marketing Study
The 15 Minute Breakdown: 2024 Beauty Marketing StudyThe 15 Minute Breakdown: 2024 Beauty Marketing Study
The 15 Minute Breakdown: 2024 Beauty Marketing Study
 
The 15 Minute Breakdown: 2024 Beauty Marketing Study
The 15 Minute Breakdown: 2024 Beauty Marketing StudyThe 15 Minute Breakdown: 2024 Beauty Marketing Study
The 15 Minute Breakdown: 2024 Beauty Marketing Study
 
Best VIP Call Girls Noida Sector 50 Call Me: 8448380779
Best VIP Call Girls Noida Sector 50 Call Me: 8448380779Best VIP Call Girls Noida Sector 50 Call Me: 8448380779
Best VIP Call Girls Noida Sector 50 Call Me: 8448380779
 
Film= Dubai Call Girls O525547819 Call Girls Dubai Whsatapp
Film= Dubai Call Girls O525547819 Call Girls Dubai WhsatappFilm= Dubai Call Girls O525547819 Call Girls Dubai Whsatapp
Film= Dubai Call Girls O525547819 Call Girls Dubai Whsatapp
 
Supermarket Floral Ad Roundup- Week 17 2024.pdf
Supermarket Floral Ad Roundup- Week 17 2024.pdfSupermarket Floral Ad Roundup- Week 17 2024.pdf
Supermarket Floral Ad Roundup- Week 17 2024.pdf
 
Best VIP Call Girls Noida Sector 55 Call Me: 8448380779
Best VIP Call Girls Noida Sector 55 Call Me: 8448380779Best VIP Call Girls Noida Sector 55 Call Me: 8448380779
Best VIP Call Girls Noida Sector 55 Call Me: 8448380779
 

Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

  • 1. #RSPS15 #RSPS15 StubHub's Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, And Click Fraud SPONSORED BY:
  • 2. #RSPS15 #RSPS15 Retail Touchpoints: @RTouchPoints Distil Networks: @Distil Marty Boos: @StubHub Rami Essaid: @RamiEssaid Alicia Fiorletta: @AliciaFiorletta Follow this event on LinkedIn & Twitter
  • 3. #RSPS15 Questions, Tweets & Resources Submit your questions here Download today’s resources Join the conversation #RSPS15
  • 4. #RSPS15 About Retail TouchPoints  Launched in 2007  Over 30,000 retail subscribers  To provide executives with relevant, insightful content across a variety of digital medium Sign up for our weekly newsletter: www.retailtouchpoints.com/subscribe
  • 5. #RSPS15 Panelists MODERATOR: Alicia Fiorletta Senior Editor, Retail TouchPoints Rami Essaid CEO & Co-Founder Distil Networks @ramiessaid Marty Boos Sr. Director Technology Operations StubHub @StubHub
  • 6. StubHub’s Field Guide to Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud
  • 7. Agenda The growing bot problem The impact of bots on e-commerce businesses How StubHub squashed malicious bots Selection criteria for a bot detection solution Q & A
  • 8. What Is Web Scraping? Web Scraping Also known as screen scraping, web scraping is the act of copying large amounts of data from a website – either manually or with an automated program (Bot) Legitimate Scraping Scraping can sometimes be benevolent and totally acceptable. For example, the search engine bots that index your website Malicious Scraping A systematic theft of intellectual property accessible on a website, including pricing, content, images, and proprietary data
  • 9. Web Scraping at Large Online Beauty Retailer Black Friday saw a 100x Increase in Bad Bots
  • 10. Challenges Distil Results Competitors were scraping product and pricing data, using it to lure customers away Stopped competitors from scraping pricing and product data by blocking bad bots Traffic from malicious bots was consuming server resources and slowing site performance Eliminated bad bot traffic, cutting server resource needs by 22% while improving performance Tracking suspicious IP addresses manually was a tedious manual process Automated the bot detection and mitigation process, saving valuable IT resources Beauty Retailer Clamps Down on Competitive Data Mining One of Europe’s largest online beauty retailers. We have a handful of competitors that cause us a lot of headaches. With Distil, we’ve stopped them from scraping our data, which protects our competitive advantage. In addition, we’ve reduced the load by 22%, and our customers experience faster response times. ” -Principal Solutions Developer “
  • 11. How Big is the Problem? Up to 60% of traffic on ecommerce websites are Bad Bots 4.2 million IP addresses impacted by “Pushdo” botnet alone 15% bot traffic can equate to hitting each of your pricing pages 30 times per month
  • 12. Why the Massive Increase in Bot Traffic? Online data has increased in value Pricing information, product availability, product descriptions, and vendor reviews are changing daily and highly valuable to competitors Anyone can get in the game Cheap or free virtual servers, bandwidth, easy-to- use tools, and scrapers for hire Bots no longer tied to IP addresses Bots cycle through random IP addresses Bots hide behind anonymous proxies Consumer IPs now infected with bot traffic too
  • 13. High Profile Web Scraping in the Ecommerce Industry QVC is an American television home shopping network and online ecommerce site. Aggressive price and inventory scraping by shopping aggregator app resulted in the following repercussions for QVC ● Two day website outage ● Loss of $2M in revenue ● Highly publicized lawsuit ● Damage to QVC Brand
  • 14. Negative SEO Attacks Bots steal content, product lists, and prices for duplication elsewhere on the Internet Duplicated content reduces your company’s uniqueness and thus quality score SEO damage may result, especially if ○Your prices are undercut ○The content is repurposed on a more popular site Bots and Negative SEO Attacks
  • 15. Bots and Competitive Data Mining Duplicating your Product Portfolio Bots can easily gather product and supplier lists for replication elsewhere Undermining your Prices Bots monitor your prices, ensuring competitors can undercut with lower price listings Availability Tracking Identifying when your supply has been exhausted provides competitors a unique opportunity to raise the price of their goods.
  • 16. Bots and Security Breaches Brute Force Account Takeover Using a bot to try stolen usernames and passwords from breaches at other websites on your site Newly compromised accounts are then used for various forms of fraud/theft
  • 17. Bots and Transaction Fraud Carding Creating micro-transactions with stolen credit cards against e-commerce sites to test their validity
  • 18. About StubHub Largest secondary ticket marketplace in the world An eBay company Processes nearly 500 transactions per second StubHub is an online marketplace which provides services for buyers and sellers of tickets for sports, concerts, theater and other live entertainment events.
  • 19. StubHub Bot Challenges Bot Challenges ○ Bots were used for brute force account takeovers ○ Competitors tried to game the system, scraping prices, and monitoring inventory and customer behavior ○ Random spikes in bot traffic were causing increased utilization of resources ○ Tested multiple competitor solutions, but they were difficult to configure and in some cases broke our website
  • 20. StubHub Bot Selection Criteria Bot Detection and Mitigation Solution Requirements ○Block web scrapers without impacting human visitors ○Accurately identify good bots vs. bad bots ○Cannot solely rely on rule based system Must include automated learning to “self tune”for defending against emerging and unknown threats ○Needs to include Distil community to improve accuracy of bot detection ○Must seamlessly co-exist with existing solutions (SIEM, CDN, WAF, etc.)
  • 21. StubHub Results with Distil Networks Reduced competitive data mining and fraud Drastically reduced competitive data mining, increased SEO rankings, and protected our marketplace ecosystem Distil is a key piece of our fraud detection and prevention suite of tools
  • 22. StubHub Results with Distil Networks Improved traffic quality and enriched analytic data Cut pageviews in half, without impacting human users or ad deliveries Quality of traffic has greatly improved by stopping unwanted bots and limiting site access for trusted bots
  • 23. Negative Security Model - Blocking Bad Bots
  • 24. Positive Security Model - Whitelisting Trusted Sources
  • 25. The Importance of No False Positives / Negative Impact on Humans
  • 26. Good bots make up over 35% of all traffic to the average website ○ Search engines - Google, Bing, Baidu, etc., ○ Alexa Crawler ○ Pingdom, Keynote, etc. Effective solutions block bad bots but leave good bots unhindered The Importance of Accurately Identifying Good vs Bad Bots Source: Distil Networks, 2015 Bad Bot Landscape Report
  • 27. Bot detection should never rely on static signatures or manual rule creation Automation and machine learning must be performed in real-time Effective bot mitigation solutions ○Dynamically classify users by correlating dozens of data points as well as behavior patterns ○Constantly “self-tune” to evolve alongside the morphing threats they encounter and protect against The Importance of Machine Learning and Self Tuning
  • 28. ○ Real-time updates from a centralized violators database help protect all sites and improve accuracy ○ Data from attacks detected anywhere on the network should be centralized, correlated, and analyzed by a big data analysis platform ○ Signatures are then constantly updated to drastically reduce false positives (blocking humans) and false negatives (missing bad bots) The Importance of Community Supported Centralized Threat Database
  • 29. Many organizations have complex web environments which may include a multitude of different solutions including ○ Content Delivery Networks (CDNs) ○ WAFs, FW, IPS ○ SIEMs ○ Load balancers ○ and more.. Bot mitigation must be able to seamlessly deployed alongside these technologies without impacting their performance or usage The Importance of Seamless Compatibility
  • 30. The First Easy and Accurate Way to Defend Websites Against Malicious Bots
  • 31. The World’s Most Accurate Bot Detection System Inline Fingerprinting Fingerprints stick to the bot even if it attempts to reconnect from random IP addresses or hide behind an anonymous proxy. Known Violators Database Real-time updates from the world’s largest Known Violators Database, which is based on the collective intelligence of all Distil-protected sites. Browser Validation The first solution to disallow browser spoofing by validating each incoming request as self-reported and detects all known browser automation tools. Behavioral Modeling and Machine Learning Machine-learning algorithms pinpoint behavioral anomalies specific to your site’s unique traffic patterns.
  • 32. How Ecommerce Companies Benefit from Distil Increase insight & control over human, good bot & bad bot traffic Block 99.9% of malicious bots without impacting legitimate users Slash the high tax bots place on internal teams & web infrastructure Protect data from web scrapers, unauthorized aggregators & hackers
  • 33. www.distilnetworks.com/trial/ Offer Ends October 15th Two Months of Free Service + Traffic Analysis
  • 34. QUESTIONS….COMMENTS ?I N F O @ D I S T I L N E T W O R K S . C O M OR CALL US ON 1.866.423.0606 www.distilnetworks.com
  • 35. #RSPS15 Q & A // Panelists MODERATOR: Alicia Fiorletta Senior Editor, Retail TouchPoints Rami Essaid CEO & Co-Founder Distil Networks @ramiessaid Marty Boos Sr. Director Technology Operations StubHub @StubHub
  • 36. #RSPS15 http://www3.retailtouchpoints.com/rsp15/ PLEASE JOIN US FOR OUR NEXT SESSION: Today at 2PM ET / 11AM PT Thanks for attending!

Editor's Notes

  1. Side Owner: Rami
  2. Side Owner: Rami
  3. Side Owner: Rami
  4. Side Owner: Rami
  5. Side Owner: Rami
  6. Side Owner: Rami QVC Sues Shopping App for Web Scraping That Allegedly Triggered Site Outage - http://newmedialaw.proskauer.com/2014/12/05/qvc-sues-shopping-app-for-web-scraping-that-allegedly-triggered-site-outage/
  7. Side Owner: Rami
  8. Side Owner: Rami
  9. Side Owner: Rami
  10. Side Owner: Rami
  11. Slide Owner: Marty
  12. Slide Owner: Marty
  13. Slide Owner: Marty
  14. Slide Owner: Marty Rami can ask- What have you noticed in terms of trends or changes in the fraud environment Ashley Madison hack prompt What are you seeing out there that concerns you in terms of fraud
  15. Slide Owner: Marty Rami can ask: Marty, what do you mean by trusted bots?
  16. Slide Owner: Marty
  17. Slide Owner: Marty Rami can ask- you’ve got a huge amount of whitelisted traffic. Why do you have to whitelist so much?
  18. Slide Owner: Marty Takeaway - Bots don’t solve CATPTCHAs
  19. Slide Owner: Marty
  20. Slide Owner: Marty
  21. Slide Owner: Marty How often do we update our threat database? Marty can ask Rami. The last thing we want to do is to take down a device to update a rule set. It’s nice that this is a totally hands off approach.
  22. Slide Owner: Marty Complex environments that include a multitude of security and web infrascture solutions Hadoop Note that this is Marty’s last slide
  23. Transition slide back to Rami
  24. Slide owner: Rami
  25. Slide Owner: Rami
  26. Slide Owner: Rami If you’re on this webinar, we’ve got your information and you’re eligible for two months of free service + traffic analysis at no charge.
  27. Slide Owner: Rami