TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»New Product Protects SMBs From Credential Stuffing Attacks
    Cyber Security

    New Product Protects SMBs From Credential Stuffing Attacks

    May 8, 2019Updated:May 8, 2019No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Shape Security has announced a new product designed to protect small and medium business (SMB) websites from the growing scourge of advanced bot-based credential stuffing.

    The Bad Bot problem is known and understood. When credentials are stolen, they are often used by bad bots for automated credential stuffing — that is, the automated and repetitive testing of stolen credentials against new targets of interest, where compromise can be used to generate income for the attacker.

    If credential stuffing bots are ‘simple’, then traditional firewalls can detect and block them. Today, however, bots are increasingly sophisticated and intelligent, and can easily defeat traditional security defenses. 

    “When you have a cybersecurity ecosystem that’s making millions of dollars on a daily basis,” Shuman Ghosemajumder, CTO at Shape Security told SecurityWeek, “the criminals have their own computer scientists who have invested in creating an attack specification incorporating many layers of abstraction. The starting point for them is to have hundreds of thousands of source IP addresses that they rotate constantly. Then there are other behavioral techniques that they use to make sure their transactions are similar to genuine transactions. They have invested in technology that allows them to mask the transactions, so they appear to be coming from different clients, and from different users that use their mouse in different ways, type on the keyboard with different mannerisms. They introduce a great deal of entropy so what is actually credential stuffing looks like a large quantity of organic traffic.”

    It works. Recorded Future reported last month, “The average success rate for credential stuffing is anywhere between one to three percent. Hence, for every one million random combinations of emails and passwords, attackers can potentially compromise between 10,000 and 30,000 accounts.” Bear in mind that 3 billion credentials were stolen or leaked in 2018 alone.

    According to Shape Security’s figures, credential stuffing fake traffic against unprotected online businesses can represent 90% or more of their website’s traffic. Overall, this fraudulent activity costs North American businesses over $5 billion annually in credit card chargeback fees and other fraud-related expenses.

    Shape is one of a handful of companies that have developed solutions able to detect the subtle differences between advanced bot traffic and genuine user traffic, and block the bad traffic before it hits the server. Most of these products serve larger enterprises and are priced accordingly. The Shape Enterprise Defense product is used by eight of the top 12 US banks, five of the top ten global airlines, two of the top five global hotels, and two of the largest US government agencies.

    “This is technology that we have built by investing more than $100 million dollars,” explains Ghosemajumder. “It is designed to be able to deal with the most sophisticated attacks that are out there, which disproportionally targets those larger organizations.”

    But smaller firms also suffer from the bad bot plague. “We realized,” he continued, “that we could fully productize our enterprise service, take out some of the service-based aspects (which includes a kind of white glove approach where we have data scientists and researchers that are dedicated to the different clients at the high-end), and just use automation instead. Doing this, we could reduce the cost and make it available to folks in a simple form factor.”

    This new product is called Shape Connect, announced May 7, 2019. It’s a self-serve model where customers can visit the Shape website and plug Connect into their own website with a DNS redirect. This is not a free service. It is not designed to protect small and personal websites — it is aimed at the growing SMB market that is currently poorly served.

    One of the strong points of Connect is that Shape claims a virtual zero delay for visitors. While there are some similar free services, they can introduce a delay between the user entering an URL and receiving the requested page. Some services insert a special page informing the user that there may be a delay of up to five seconds while the service checks the validity of the user’s browser. Ghosemajumder believes this is unacceptable for visitors (that is, potential customers).

    In an earlier position, his task was to protect Google from click fraud. “We did measurements and conducted experiments that showed that delays of even tens of milliseconds would result in us losing users if we increased latency by that much,” he told SecurityWeek. “Shape has had all of these conversations with our initial set of high end customers about performance and latency — it’s completely unacceptable to have additional latency that goes into the seconds. 

    “What we have,” he continued, “is an invisible mechanism that allows us to execute JavaScript that instantaneously determines whether a transaction is behaving in an anomalous manner. It’s our unique technology that allows us to protect in a way, and perform in a way, that other technologies cannot. We have simply chosen to put this technology into a new form factor that is not designed for the really small sites, but for the companies that are a bit larger. So, not Fortune 500, not Global 2000 — that’s what our high-end product and service is designed for — but for all of the other small and medium businesses that are out there that have the problem of fake or automated traffic being directed against them.”

    Mountain View, CA-based Shape Security was launched in 2011 by Derek Smith, Justin Call, and Sumit Agarwal, and emerged from stealth in 2014. It has raised a total of the $132 million in funding, with the latest being a Series E round for $26 million in November 2018. 

    Related: Credential Stuffing: A Successful and Growing Attack Methodology 

    Related: Bad Bots Steal Accounts, Content and Skew the Web Ecosystem 

    Related: Credential Stuffing Attacks Are Reaching DDoS Proportions

    Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

    Previous Columns by Kevin Townsend:
    Tags:



    Source link

    Digitpol
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.