Chapter 4. Malicious Bots
This category includes bot activity that is designed simply to have a negative impact on a website rather than the negative impact being a by-product of another activity designed to benefit the bot operator directly.
This bot activity has a lot of overlap with other types of security attacks, such as DDoS attacks or vulnerability exploits (as already mentioned, these are not covered at length here, as there is a wealth of literature on these topics). Attacks like this are usually orchestrated by groups wanting to hold companies to ransom in return for stopping the attacks, groups who have ideological objections to companies’ activities, or occasionally, malicious competitors.
Traditionally the use of automated traffic as we define it here has not been the means of malicious attack but this will change as defense against DDoS attacks and other security systems improve.
Let’s now take a look at an example of malicious bots.
Application DDoS
The objective of a DDoS attack is to undertake a large amount of activity such that the server under attack is unable to provide the service that it is in place to provide. While this is partly done by the quantity of traffic, it is also done by forming the network requests in such a manner as to exploit weaknesses in the network protocols that make a failure more likely. As a very simple example, this could be simply ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access