Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Akamai Improves Bot Manager to Defend Against Credential Stuffing

    By
    Sean Michael Kerner
    -
    October 12, 2017
    Share
    Facebook
    Twitter
    Linkedin
      Akamai-botmanager-1088x725

      Among the most common type of attacks that hit the Akamai platform on a daily basis is one known as credential stuffing. In such an attack, automated bots aim to reuse passwords and credentials harvested from other sites and data breaches to exploit new systems.

      At the Akamai Edge conference on Oct. 11, Akamai announced an enhanced technology offering called Bot Manager Premier to help identify and block advanced credential stuffing attacks. Bot Manager Premier integrates bot detection technology Akamai acquired from Cyberfend in December 2016.

      “Pretty much everything depends on the internet today, and that means that pretty much everything is vulnerable,” Tom Leighton, co-founder and CEO of Akamai, said during his Akamai Edge keynote speech.

      Akamai already provides organizations with distributed denial-of-service (DDoS) attack mitigation capabilities, according to Leighton. DDoS attacks are typically volumetric and attempt to overwhelm sites and services with large amounts of traffic. Akamai also has the Kona Web Application Firewall (WAF) service, which defends against application layer attacks.

      While Kona is able to filter out some attack types, Leighton said many modern attackers use traffic that appears on the surface to be normal. That’s why there is a need for the Bot Manager technology.

      “Account hacking is a huge problem. Across our platform we’re now seeing that approximately two-thirds of log-in attempts are actually malicious,” he said. “The bots are getting really good at getting past traditional defenses.”

      Bot Manager Premier 

      Akamai already had its Bot Manager standard edition in the market prior to the Cyberfend acquisition 2016. With the standard edition, Akamai provides protection against web scraping, content aggregation and general bot management capabilities. The new Bot Manager Premier offering integrates Cyberfend capabilities to provide protection against credential abuse and web fraud.

      “Since the acquisition, the Cyberfend data scientist team has continued evolving the original detections with access to a greater breadth and variety of customer traffic, including bot traffic, afforded by the Akamai customer base,” Josh Shaul, vice president of web security product management at Akamai, told eWEEK. 

      Integrating Cyberfend with Bot Manager Premier means that Akamai can now deploy the credential abuse protection capabilities on the Akamai platform as part of the overall delivery of the protected website, he said. 

      “While this sounds minor, it actually makes it significantly easier for customers to consume this technology,” Shaul said. 

      The original Cyberfend technology required users to make changes to their applications to integrate the JavaScript-based detections. With Bot Manager Premier, the detection capabilities can be injected at the Akamai Edge while delivering the website without requiring any application changes, he said. 

      “This has a positive impact on both the deployment of Bot Manager Premier as well as ongoing changes by Akamai to detections and ongoing changes by the customer to their application,” Shaul said.

      The underlying infrastructure that enables Bot Manager Premier includes the use of custom algorithms with both supervised and unsupervised machine learning. Akamai is also providing a mobile software development kit (SDK) to enable developers to benefit from the Bot Manager service.

      “The mobile SDK allows customers to bake the data collection component of Bot Manager Premier’s behavior anomaly analysis detections into their mobile app,” Shaul said. “Once compiled, the mobile app essentially calls the SDK to collect the behavioral telemetry from the mobile device before sending it to Akamai to analyze.”

      With its DDoS mitigation, Kona WAF and Bot Defender services, Akamai is trying to do its part to help organizations stay safe on the internet, though it is an increasingly challenging environment.

      “Why are big name companies not able to defend themselves? I don’t think it’s because the executives that work at those companies were stupid or careless,” Leighton said during his keynote. “I think it’s because we’re up against some very large and well-funded adversaries, and on the internet it’s a lot harder to defend than it is to attack.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and contributor to several leading IT business web sites.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×