Le Lézard
Classified in: Science and technology
Subject: Economic News/Analysis

Web Application Attacks Intensify in Fourth Quarter of 2023, According to New Edgio Quarterly Attack Trends Report


Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.

Edgio's report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization's infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.

"As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today," said Tom Gorup, Vice President of Security for Edgio. "We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it's critical this knowledge is shared to build a safer Internet."

The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.

In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio's Top 10 for the quarter.

Top countries by malicious request origin, making up nearly 62% of all requests denied, include:

Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.

Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.

Best practices for digital asset protection: proactively stop threats against websites and applications

Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:

To obtain a full copy of the report, click here.

About Edgio

Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.


These press releases may also interest you

at 02:34
Elbit Systems Ltd.  ("Elbit Systems" or the "Company") announced today that it was awarded an initial contract of approximately $37 million to supply Iron Fist Active Protection Systems (APS) to General Dynamics Ordnance and Tactical Systems...

4 mai 2024
UroGen Pharma Ltd. , a biotech company dedicated to developing and commercializing innovative solutions that treat urothelial and specialty cancers, today announced results from a new analysis of the ATLAS trial, which estimates using Kaplan Meier...

4 mai 2024
U.S.-based tech startup Iozera, in collaboration with the Government of Morocco, announces an initiative set to transform the AI industry. Iozera has announced the signing of a Memorandum of Understanding (MOU) for the establishment of a pioneering...

4 mai 2024
OKX, a leading Web3 technology company, has issued updates for May 3, 2024. OKX today announced that its Web3 Wallet is now...

4 mai 2024
UroGen Pharma Ltd. , a biotech company dedicated to developing and commercializing novel solutions that treat urothelial and specialty cancers, today highlights the results of a sub-analysis from a real-world patient cohort review of JELMYTO...

4 mai 2024
With a remarkable achievement of 81.556 billion yuan in operating revenue, marking an 11.74% increase from the previous year, and a net profit attributable to shareholders of 7.039 billion yuan, soaring by 27.21%, JA Solar hit historic highs in both...



News published on and distributed by: