how do you prevent competitive online price scraping, stop ... · how do you prevent competitive...

27
How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection?

Upload: others

Post on 06-Jul-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection?

Page 2: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Bad Bots Cause the Majority of Website Problems

19% of Traffic Causes the Following Problems

Page 3: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

What Sorts of Problems Are We Solving for Travel Organizations?

Page 4: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Skewed Analytics

Page 5: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Page Views

Unique Visitors

Bounce Rate

Look to Book

Campaign ROI

Web Traffic Data Drives Business Decisions

Page 6: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Web Scraping

Page 7: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Web scrapers use advanced persistent bots to

Perform Competitive Intelligence

Steal Unique content and intellectual property

Damage SEO Rankings

Web Scraping Causes Content Theft and Loss of Intellectual Property

Page 8: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Bots and Competitive Data Mining

Duplicating your Product PortfolioBots can easily gather product and supplier listsfor replication elsewhere

Undermining your PricesBots monitor your prices, ensuring competitorscan undercut with lower price listings

Availability TrackingIdentifying when your supply has been exhausted provides competitors a unique opportunity to raise the price of their goods.

Your Website

Page 9: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Brute Force Account Takeover and Online Fraud

Page 10: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Major Brand Breaches in the News

Home DepotData Hack impacts 56 million Payment Cards

Kohl’sFraudsters Change

Gift Cards Into Cash

Highlights from Neiman Marcus Article● “comprised an estimated 5,200 accounts”● "Mitigating these types of account takeovers is critical to maintaining

customer loyalty” ● “one in four fraud victims in 2015 avoided merchants post-fraud"

Sources: krebsonsecurity.com, bankinfosecurity.com, bloomberg.com, & privacyandsecuritymatters.com

Target Data Breach Costs

$252 Million

Page 11: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Bots Make Large Scale Account Takeover Possible

Billions of username, password combinations exist in the wild

Bot operators create bots to test millions of username/password combinations from breaches at other websites to find the credentials that also work on your site

Newly compromised accounts are then used for various forms of fraud/theft

Page 12: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

http://krebsonsecurity.com/2016/08/united-airlines-sets-minimum-bar-on-security/

Security

Versus

User Experience

United Airlines Account Protection

Page 13: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

47% of fraudulent transactions are successful based on

2012-2015 data

Virtually no improvement preventing fraud over past

four years

200% growth in Volume of Fraudulent Transactions

from 2012 to 2015

No Improvement in Fraud Prevention

SOURCE: 2015 True Cost of Fraud Study - LexisNexis

Page 14: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

• Site Performance / Reliability

• Form Spam

• Infrastructure Costs

• Unauthorized Vulnerability Scans

• Denial of Service Attacks

• Ad Fraud

Other Areas of Impact

Page 15: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

The Distil Solution

Page 16: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Travel Customer Case Studies

Ecommerce

Travel

Publishers

Directories

Marketplace

Services/Finance

Page 17: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Homegrown Solutions Are Ineffective

Creates a poor user experience Bots appear human in logs Defeated by distributed IP attacks

Defeated by advanced bots Labor intensive Defeated by low and slow crawlers

Defeated by CAPTCHA farms Distributed attacks hard to pinpoint Defeated by peer-to-peer / proxies

Reduces conversions by up to 27% Reactive in nature Reactive in nature

Page 18: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Majority of Bots are Advanced Persistent Bots (APBs)

APBs have one or more of the following abilities:

AdvancedMimic human behaviorLoad JavaScriptLoad external resourcesSupport cookiesBrowser automation (Selenium, PhantomJS)

PersistentDynamic IP rotationDistribute attacks across IP addressesHide behind anonymous and peer-to-peer proxies

2016 Distil Bad Bot Report

Page 19: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Web App Security Requires Complementary Solutions

l

DDoS Mitigation Firewall WAF Distil Bot Protection

Core Competency

Volumetric attacks on infrastructure Network layer attacks Application coding exploits Automated abuse, misuse, and attacks

(scraping, fraud, account takeover, etc.)

Techniques Scrubbing centers,Large pipes

Access Control Lists (ACLs),

Rules-Based

App layer understanding, ACLs, Rules-Based

Real-time Analysis, Fingerprinting, Honeypotting, Machine learning,

Behavioral modeling

Page 20: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

The Most Accurate Device Fingerprint in the Bot Mitigation Industry

IP Address

Header & User Agent Information

Cookie Browser

200+ Attributes of data Navigator, WebGL, Plugins, Audio, Video, etc.

Tamper proofing layer

Distil Hi-Def Fingerprint

Page 21: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

How the Distil Bot Detection Solution Works

As web traffic passes through Distil, the system

1. Fingerprints each incoming connection and compares it to our Known Violators Database

1. If it’s a new fingerprint, validates the browser to determine if it’s a Bot or Not

1. Based on your preferences, automatically tags, challenges, or blocks the bot

Page 22: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Threat Intelligence From All Distil-Protected Sites

Known Violators DatabaseReal-time updates from the world’s largest Known Violators Database, which is based on the collective intelligence of all Distil-protected sites

Distil customers are automatically protected against new threats discovered anywhere on the network

Page 23: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Browser ValidationDetects all known browser automation tools, such as Selenium and Phantom JS

Protects against browser spoofing by validating each incoming request as self reported

Advanced Bot Detection Increases Accuracy

Behavioral Modeling and Machine LearningMachine-learning algorithms pinpoint behavioral anomalies specific to your site’s unique traffic patterns

Self optimizing algorithms improve bot detection and mitigation without manual configuration

Page 24: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Distil API Security Protects APIs from Automated Attackers

l

Leverages your existing authentication methods for easy deployment

Inspects each client connection in real-time

Detects API clients masquerading as legitimate browsers

Works across web, mobile browser, and mobile native applications

Page 25: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

Distil Analyst Managed Service

“Distil Analyst Managed Service helps keep our site fast and responsive and helps ensure our customers - wherever they are booking - get our price and availability content through our approved API channels.”

Anthony Drury, Head of Business

Bringing Human Intelligence to the Science of Bot Mitigation

Page 26: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

○ Install on virtualized or bare metal appliance(s)○ High availability configurations with failover monitoring○ Heartbeat up to Distil Cloud ○ Deploys in days

Flexible Deployment Options

○ Automatically compresses and optimizes content for faster delivery○ 17 global datacenters automatically fail over when a primary location goes

offline○ Automatically increases infrastructure and bandwidth to accommodate

spikes○ Deploys in hours

Physical or Virtual Appliances

Content Delivery Network

Page 27: How do you prevent competitive online price scraping, stop ... · How do you prevent competitive online price scraping, stop fraud and clean up skewed data with bot detection? Bad

www.distilnetworks.com

QUESTIONS….COMMENTS?KELLEY@ D I S T I L N E T W O R K S . C O M

1.866.423.0606OR CALL US ON