SlideShare a Scribd company logo
악성 봇의 허상과 실상
5월 21일 오후 3시 KST
Jean Ryu
Solutions Engineer, Cloudflare
Live webinar
We are helping
build a better
Internet
2
27M+
Internet properties
200
Cities and 95 countries
37 Tbps
Network Capacity
DDoS mitigation capacity
99%
Of the Internet-connected population
in the developed world is located
within 100 milliseconds of our
network
Note: Data as of June 28, 2019.
Cloudflare’s network operates at massive
scale
Confidential. Copyright © Cloudflare, Inc.
Customers benefit from integrated security, performance, and reliability
35% performance
improvement
50% acceleration in
DNS performance
60% reduction in
malicious traffic
41k WAF blocks
per month
900k login attempts
blocked in 2 hours
50% decrease
in page load times
Facts
● Automated program designed to perform specific task
● Execute tasks over and over at a much faster rate than a human could
● Interact with a webpage, fill out and submit forms, click on links, scan
(or "crawl") text, and download content
● Watch videos, post comments, and post, like, or retweet on social
media platforms
What are bots
Myth #1: All Bots are Bad
Facts
● Bad bots tend to get the most attention, good bots are almost as
prevalent
● Good bots play crucial roles in keeping digital business flowing.
● Google, Bing and Baidu for SEO, Partner bots, site monitoring bots
● Hackers deliberately design malicious bots to mimic the behavior of
the good bots
● Malicious bots have become more sophisticated and prevalent, from
impersonating human behavior to changing tactics
Myth #2: Bad bots only attack e-commerce,
travel, and finance
Facts
● Many high-profile bot attacks have targeted banks, airlines, hotels, and
e-commerce companies
● Increased bot attacks on - Healthcare facilities, educational
institutions, gaming companies, marketing firms, publishing houses,
and even government agencies
● Every industry has a different bot problem
○ Ecommerce, travel – price scraping is a big concern
○ Healthcare, tech, ecommerce - credential stuffing on rise
Myth #3: Bot attacks are only a holiday shopping
problem
Facts
● Bot attacks can strike at any time of the year
○ Major event like a product launch,
○ Political events
○ During Covid
● Credential stuffing attack on Zoom - March 2020
● Credential stuffing attack on J.Crew - April 2019
Myth #4: Isolated tactics can stop all malicious
bots
Facts
● DDoS mitigation - can be effective against volumetric attacks but less
adept at detecting individual bots that imitate human user behavior
● Web Application Firewall (WAF) – can defend against SQL injections,
cross-site scripting (XSS), and zero-day attacks but not block bots that
scrape content
● Rate limiting - can block simplistic bot attacks but cannot detect bots
that go “low and slow”
● Multi-factor authentication or Captcha – provides additional layer of
security but don’t work for the all of bot use cases and adds friction to
user experience
Myth #5: I should build a custom bot
management tool
Facts
● May prove effective in the immediate term but requires
○ In-house technical expertise
○ Costly maintenance
○ Tedious upgrades
○ Constant fine- tuning of rules and policies
Cloudflare’s Bot Management Solution
Built for security needs of the modern business
Configuration
Flexibility
Threat Intelligence
At-Scale
Automatic Whitelists
No JS injection
Integrated Security
and Performance
Mobile App Endpoint and
API Protection
Complete without
Complexity
Bot Management
How it works
Advantages of Bot Management solution
Simple
Deployment
Quick
Mitigation
Accurate
Detection
Rich
Analytics
● No JavaScript
● No mobile SDK
● Behavioral analysis
● Machine learning
● Fingerprinting
● Alternative content
● Captcha
● Log
● Block
● Reports
● SIEM integrations
Protect revenue and
customer trust
by enhancing sales
and reducing
customer churn.
Rich user experience due
to availability of website
during business hours
providing consistent user
experience without delays
Reduced operational
cost by eliminating the
manual effort of
detecting and blocking
bad bots
Benefits of Cloudflare’s Bot Management
Solution
CHALLENGES
• ArtStation saw account takeovers creating a bad experience for customers,
jeopardizing their business which grows through word-of-mouth and a positive
brand.
• Spamming and “social engineering” via mass posting and fake comments also
risked hurting the brand, making the environment feel unsafe.
• Competitors were scraping user information to spam them with competing offers.
ArtStation provides artists with an
amazing platform to showcase their
portfolio, find work and connect with
opportunities.
“Cloudflare Bot Management gives us
peace of mind as we scale our
business. Our team can focus on
creating value for our clients instead
of dealing with bots! It also results in a
better experience for our clients with
reduced spam, account takeovers and
malicious activity.”
Leonard Teo
CEO
http://cfl.re/art-station-customer-case
ArtStation / Customer Case Study
16
CLOUDFLARE SOLUTION
● Cloudflare’s bot management
classified and mitigated bad bots
that were waging credential stuffing
attacks.
● It did so without false positives or
blocking good bots.
● Built on Cloudflare, very simple to
integrate.
KEY RESULTS
● Peace of mind - knowing that
Cloudflare was working behind the
scenes to protect the site.
● Developers can focus on building
high value things instead of dealing
with malicious bots.
● Better experience for our clients
results in increased reputation.
We are helping
build a better
Internet
Q&A

More Related Content

Similar to Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상

Pixels.camp - Machine Learning: Building Successful Products at Scale
Pixels.camp - Machine Learning: Building Successful Products at ScalePixels.camp - Machine Learning: Building Successful Products at Scale
Pixels.camp - Machine Learning: Building Successful Products at Scale
António Alegria
 
BSFI Technology Offerings by Value Innovation Labs
BSFI Technology Offerings by Value Innovation LabsBSFI Technology Offerings by Value Innovation Labs
BSFI Technology Offerings by Value Innovation Labs
Mount Talent Consulting
 
The Imitation Game: Detecting and Thwarting Automated Bot Attacks
The Imitation Game: Detecting and Thwarting Automated Bot AttacksThe Imitation Game: Detecting and Thwarting Automated Bot Attacks
The Imitation Game: Detecting and Thwarting Automated Bot Attacks
Enterprise Management Associates
 
Fight bad bot on the internet
Fight bad bot on the internetFight bad bot on the internet
Fight bad bot on the internet
Cloudflare
 
Cyber security fundamentals
Cyber security fundamentalsCyber security fundamentals
Cyber security fundamentals
Cloudflare
 
Cocolevio AI Chatbot 9.20.19
Cocolevio AI Chatbot 9.20.19Cocolevio AI Chatbot 9.20.19
Cocolevio AI Chatbot 9.20.19
Maurice Harris
 
Getting Started with Sitelock on ResellerClub
Getting Started with Sitelock on ResellerClubGetting Started with Sitelock on ResellerClub
Getting Started with Sitelock on ResellerClub
ResellerClub
 
Bot audit
Bot auditBot audit
Bot audit
Anika Mittal
 
Cybrilla fintech presentation
Cybrilla fintech presentationCybrilla fintech presentation
Cybrilla fintech presentation
Anchal Jajodia
 
Digital Transformation - Why you need to embrace it now
Digital Transformation - Why you need to embrace it nowDigital Transformation - Why you need to embrace it now
Digital Transformation - Why you need to embrace it now
Muliadi Jeo
 
MITRE ATT&CKcon Power Hour - November
MITRE ATT&CKcon Power Hour - NovemberMITRE ATT&CKcon Power Hour - November
MITRE ATT&CKcon Power Hour - November
MITRE - ATT&CKcon
 
Cleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammersCleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammers
Distil Networks
 
How to clean up travel website traffic from bots and spammers?
How to clean up travel website traffic from bots and spammers?How to clean up travel website traffic from bots and spammers?
How to clean up travel website traffic from bots and spammers?
tnooz
 
Cyber Security 101
Cyber Security 101Cyber Security 101
Cyber Security 101
Cloudflare
 
Rtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deckRtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deck
G3 Communications
 
Blue Bricks Business Collateral
Blue Bricks Business CollateralBlue Bricks Business Collateral
Blue Bricks Business Collateral
Vikram Sareen
 
The cyber security hype cycle is upon us
The cyber security hype cycle is upon usThe cyber security hype cycle is upon us
The cyber security hype cycle is upon us
Jonathan Sinclair
 
Identity - building trust in a digital world
Identity - building trust in a digital worldIdentity - building trust in a digital world
Identity - building trust in a digital world
Conor Bronsdon
 
Identity Modernization eBook
Identity Modernization eBookIdentity Modernization eBook
Identity Modernization eBook
Pablo Junco
 

Similar to Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상 (20)

Pixels.camp - Machine Learning: Building Successful Products at Scale
Pixels.camp - Machine Learning: Building Successful Products at ScalePixels.camp - Machine Learning: Building Successful Products at Scale
Pixels.camp - Machine Learning: Building Successful Products at Scale
 
BSFI Technology Offerings by Value Innovation Labs
BSFI Technology Offerings by Value Innovation LabsBSFI Technology Offerings by Value Innovation Labs
BSFI Technology Offerings by Value Innovation Labs
 
The Imitation Game: Detecting and Thwarting Automated Bot Attacks
The Imitation Game: Detecting and Thwarting Automated Bot AttacksThe Imitation Game: Detecting and Thwarting Automated Bot Attacks
The Imitation Game: Detecting and Thwarting Automated Bot Attacks
 
Fight bad bot on the internet
Fight bad bot on the internetFight bad bot on the internet
Fight bad bot on the internet
 
Cyber security fundamentals
Cyber security fundamentalsCyber security fundamentals
Cyber security fundamentals
 
Cocolevio AI Chatbot 9.20.19
Cocolevio AI Chatbot 9.20.19Cocolevio AI Chatbot 9.20.19
Cocolevio AI Chatbot 9.20.19
 
Getting Started with Sitelock on ResellerClub
Getting Started with Sitelock on ResellerClubGetting Started with Sitelock on ResellerClub
Getting Started with Sitelock on ResellerClub
 
Bot audit
Bot auditBot audit
Bot audit
 
Cybrilla fintech presentation
Cybrilla fintech presentationCybrilla fintech presentation
Cybrilla fintech presentation
 
OCTOBERFINAL 9
OCTOBERFINAL 9OCTOBERFINAL 9
OCTOBERFINAL 9
 
Digital Transformation - Why you need to embrace it now
Digital Transformation - Why you need to embrace it nowDigital Transformation - Why you need to embrace it now
Digital Transformation - Why you need to embrace it now
 
MITRE ATT&CKcon Power Hour - November
MITRE ATT&CKcon Power Hour - NovemberMITRE ATT&CKcon Power Hour - November
MITRE ATT&CKcon Power Hour - November
 
Cleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammersCleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammers
 
How to clean up travel website traffic from bots and spammers?
How to clean up travel website traffic from bots and spammers?How to clean up travel website traffic from bots and spammers?
How to clean up travel website traffic from bots and spammers?
 
Cyber Security 101
Cyber Security 101Cyber Security 101
Cyber Security 101
 
Rtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deckRtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deck
 
Blue Bricks Business Collateral
Blue Bricks Business CollateralBlue Bricks Business Collateral
Blue Bricks Business Collateral
 
The cyber security hype cycle is upon us
The cyber security hype cycle is upon usThe cyber security hype cycle is upon us
The cyber security hype cycle is upon us
 
Identity - building trust in a digital world
Identity - building trust in a digital worldIdentity - building trust in a digital world
Identity - building trust in a digital world
 
Identity Modernization eBook
Identity Modernization eBookIdentity Modernization eBook
Identity Modernization eBook
 

More from Jean Ryu

Introduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile PaymentIntroduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile Payment
Jean Ryu
 
No trade-offs: 안전하고, 빠르고, 안정적인 네트워크 구축하기 / Building secure, fast, and reliabl...
No trade-offs: 안전하고, 빠르고, 안정적인 네트워크 구축하기 / Building secure, fast, and reliabl...No trade-offs: 안전하고, 빠르고, 안정적인 네트워크 구축하기 / Building secure, fast, and reliabl...
No trade-offs: 안전하고, 빠르고, 안정적인 네트워크 구축하기 / Building secure, fast, and reliabl...
Jean Ryu
 
Cloudflare로 DDoS 방어하기 실전편
Cloudflare로 DDoS 방어하기 실전편Cloudflare로 DDoS 방어하기 실전편
Cloudflare로 DDoS 방어하기 실전편
Jean Ryu
 
DDoS 방어를 위한 Cloudflare 활용법
DDoS 방어를 위한 Cloudflare 활용법DDoS 방어를 위한 Cloudflare 활용법
DDoS 방어를 위한 Cloudflare 활용법
Jean Ryu
 
사이버보안 핵심원리 / Cybersecurity Fundamentals
사이버보안 핵심원리 / Cybersecurity Fundamentals사이버보안 핵심원리 / Cybersecurity Fundamentals
사이버보안 핵심원리 / Cybersecurity Fundamentals
Jean Ryu
 
최신 DDoS 동향 - Modern DDoS Trends
최신 DDoS 동향 - Modern DDoS Trends최신 DDoS 동향 - Modern DDoS Trends
최신 DDoS 동향 - Modern DDoS Trends
Jean Ryu
 

More from Jean Ryu (6)

Introduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile PaymentIntroduction of Cloudflare Solution for Mobile Payment
Introduction of Cloudflare Solution for Mobile Payment
 
No trade-offs: 안전하고, 빠르고, 안정적인 네트워크 구축하기 / Building secure, fast, and reliabl...
No trade-offs: 안전하고, 빠르고, 안정적인 네트워크 구축하기 / Building secure, fast, and reliabl...No trade-offs: 안전하고, 빠르고, 안정적인 네트워크 구축하기 / Building secure, fast, and reliabl...
No trade-offs: 안전하고, 빠르고, 안정적인 네트워크 구축하기 / Building secure, fast, and reliabl...
 
Cloudflare로 DDoS 방어하기 실전편
Cloudflare로 DDoS 방어하기 실전편Cloudflare로 DDoS 방어하기 실전편
Cloudflare로 DDoS 방어하기 실전편
 
DDoS 방어를 위한 Cloudflare 활용법
DDoS 방어를 위한 Cloudflare 활용법DDoS 방어를 위한 Cloudflare 활용법
DDoS 방어를 위한 Cloudflare 활용법
 
사이버보안 핵심원리 / Cybersecurity Fundamentals
사이버보안 핵심원리 / Cybersecurity Fundamentals사이버보안 핵심원리 / Cybersecurity Fundamentals
사이버보안 핵심원리 / Cybersecurity Fundamentals
 
최신 DDoS 동향 - Modern DDoS Trends
최신 DDoS 동향 - Modern DDoS Trends최신 DDoS 동향 - Modern DDoS Trends
최신 DDoS 동향 - Modern DDoS Trends
 

Recently uploaded

Latest trends in computer networking.pptx
Latest trends in computer networking.pptxLatest trends in computer networking.pptx
Latest trends in computer networking.pptx
JungkooksNonexistent
 
This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!
nirahealhty
 
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
3ipehhoa
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
Rogerio Filho
 
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
3ipehhoa
 
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
3ipehhoa
 
The+Prospects+of+E-Commerce+in+China.pptx
The+Prospects+of+E-Commerce+in+China.pptxThe+Prospects+of+E-Commerce+in+China.pptx
The+Prospects+of+E-Commerce+in+China.pptx
laozhuseo02
 
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
CIOWomenMagazine
 
Bài tập unit 1 English in the world.docx
Bài tập unit 1 English in the world.docxBài tập unit 1 English in the world.docx
Bài tập unit 1 English in the world.docx
nhiyenphan2005
 
Comptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guideComptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guide
GTProductions1
 
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shopHistory+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
laozhuseo02
 
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
keoku
 
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptxBridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Brad Spiegel Macon GA
 
1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...
JeyaPerumal1
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
Arif0071
 
Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027
harveenkaur52
 
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
eutxy
 
How to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptxHow to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptx
Gal Baras
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
Javier Lasa
 

Recently uploaded (20)

Latest trends in computer networking.pptx
Latest trends in computer networking.pptxLatest trends in computer networking.pptx
Latest trends in computer networking.pptx
 
This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!
 
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
 
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
 
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
 
The+Prospects+of+E-Commerce+in+China.pptx
The+Prospects+of+E-Commerce+in+China.pptxThe+Prospects+of+E-Commerce+in+China.pptx
The+Prospects+of+E-Commerce+in+China.pptx
 
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
 
Bài tập unit 1 English in the world.docx
Bài tập unit 1 English in the world.docxBài tập unit 1 English in the world.docx
Bài tập unit 1 English in the world.docx
 
Comptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guideComptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guide
 
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shopHistory+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
 
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
 
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptxBridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
 
1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
 
Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027
 
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
 
How to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptxHow to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptx
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
 

Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상

  • 1. 악성 봇의 허상과 실상 5월 21일 오후 3시 KST Jean Ryu Solutions Engineer, Cloudflare Live webinar
  • 2. We are helping build a better Internet 2
  • 3. 27M+ Internet properties 200 Cities and 95 countries 37 Tbps Network Capacity DDoS mitigation capacity 99% Of the Internet-connected population in the developed world is located within 100 milliseconds of our network Note: Data as of June 28, 2019. Cloudflare’s network operates at massive scale Confidential. Copyright © Cloudflare, Inc.
  • 4. Customers benefit from integrated security, performance, and reliability 35% performance improvement 50% acceleration in DNS performance 60% reduction in malicious traffic 41k WAF blocks per month 900k login attempts blocked in 2 hours 50% decrease in page load times
  • 5. Facts ● Automated program designed to perform specific task ● Execute tasks over and over at a much faster rate than a human could ● Interact with a webpage, fill out and submit forms, click on links, scan (or "crawl") text, and download content ● Watch videos, post comments, and post, like, or retweet on social media platforms What are bots
  • 6. Myth #1: All Bots are Bad Facts ● Bad bots tend to get the most attention, good bots are almost as prevalent ● Good bots play crucial roles in keeping digital business flowing. ● Google, Bing and Baidu for SEO, Partner bots, site monitoring bots ● Hackers deliberately design malicious bots to mimic the behavior of the good bots ● Malicious bots have become more sophisticated and prevalent, from impersonating human behavior to changing tactics
  • 7. Myth #2: Bad bots only attack e-commerce, travel, and finance Facts ● Many high-profile bot attacks have targeted banks, airlines, hotels, and e-commerce companies ● Increased bot attacks on - Healthcare facilities, educational institutions, gaming companies, marketing firms, publishing houses, and even government agencies ● Every industry has a different bot problem ○ Ecommerce, travel – price scraping is a big concern ○ Healthcare, tech, ecommerce - credential stuffing on rise
  • 8. Myth #3: Bot attacks are only a holiday shopping problem Facts ● Bot attacks can strike at any time of the year ○ Major event like a product launch, ○ Political events ○ During Covid ● Credential stuffing attack on Zoom - March 2020 ● Credential stuffing attack on J.Crew - April 2019
  • 9. Myth #4: Isolated tactics can stop all malicious bots Facts ● DDoS mitigation - can be effective against volumetric attacks but less adept at detecting individual bots that imitate human user behavior ● Web Application Firewall (WAF) – can defend against SQL injections, cross-site scripting (XSS), and zero-day attacks but not block bots that scrape content ● Rate limiting - can block simplistic bot attacks but cannot detect bots that go “low and slow” ● Multi-factor authentication or Captcha – provides additional layer of security but don’t work for the all of bot use cases and adds friction to user experience
  • 10. Myth #5: I should build a custom bot management tool Facts ● May prove effective in the immediate term but requires ○ In-house technical expertise ○ Costly maintenance ○ Tedious upgrades ○ Constant fine- tuning of rules and policies
  • 12. Built for security needs of the modern business Configuration Flexibility Threat Intelligence At-Scale Automatic Whitelists No JS injection Integrated Security and Performance Mobile App Endpoint and API Protection Complete without Complexity Bot Management
  • 14. Advantages of Bot Management solution Simple Deployment Quick Mitigation Accurate Detection Rich Analytics ● No JavaScript ● No mobile SDK ● Behavioral analysis ● Machine learning ● Fingerprinting ● Alternative content ● Captcha ● Log ● Block ● Reports ● SIEM integrations
  • 15. Protect revenue and customer trust by enhancing sales and reducing customer churn. Rich user experience due to availability of website during business hours providing consistent user experience without delays Reduced operational cost by eliminating the manual effort of detecting and blocking bad bots Benefits of Cloudflare’s Bot Management Solution
  • 16. CHALLENGES • ArtStation saw account takeovers creating a bad experience for customers, jeopardizing their business which grows through word-of-mouth and a positive brand. • Spamming and “social engineering” via mass posting and fake comments also risked hurting the brand, making the environment feel unsafe. • Competitors were scraping user information to spam them with competing offers. ArtStation provides artists with an amazing platform to showcase their portfolio, find work and connect with opportunities. “Cloudflare Bot Management gives us peace of mind as we scale our business. Our team can focus on creating value for our clients instead of dealing with bots! It also results in a better experience for our clients with reduced spam, account takeovers and malicious activity.” Leonard Teo CEO http://cfl.re/art-station-customer-case ArtStation / Customer Case Study 16 CLOUDFLARE SOLUTION ● Cloudflare’s bot management classified and mitigated bad bots that were waging credential stuffing attacks. ● It did so without false positives or blocking good bots. ● Built on Cloudflare, very simple to integrate. KEY RESULTS ● Peace of mind - knowing that Cloudflare was working behind the scenes to protect the site. ● Developers can focus on building high value things instead of dealing with malicious bots. ● Better experience for our clients results in increased reputation.
  • 17. We are helping build a better Internet Q&A