field guide to preventing competitor price scraping, unwanted transactions, brute force attacks, and...

36
#RSPS15 #RSPS15 StubHub's Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, And Click Fraud SPONSORED BY:

Upload: distil-networks

Post on 18-Jan-2017

879 views

Category:

Retail


0 download

TRANSCRIPT

Page 1: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

#RSPS15#RSPS15

StubHub's Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force

Attacks, And Click Fraud

SPONSORED BY:

Page 2: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

#RSPS15

#RSPS15Retail Touchpoints: @RTouchPoints

Distil Networks: @DistilMarty Boos: @StubHub

Rami Essaid: @RamiEssaidAlicia Fiorletta: @AliciaFiorletta

Follow this event on LinkedIn & Twitter

Page 3: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

#RSPS15

Questions, Tweets & Resources

Submit your questions

here

Download today’s

resources

Join the conversation

#RSPS15

Page 4: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

#RSPS15

About Retail TouchPoints Launched in 2007 Over 30,000 retail subscribers To provide executives with

relevant, insightful content across a variety of digital medium

Sign up for our weekly newsletter: www.retailtouchpoints.com/subscribe

Page 5: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

#RSPS15

PanelistsMODERATOR:Alicia FiorlettaSenior Editor, Retail TouchPoints

Rami EssaidCEO & Co-Founder Distil Networks @ramiessaid

Marty BoosSr. Director Technology OperationsStubHub@StubHub

Page 6: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

StubHub’s Field Guide to Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force

Attacks, and Click Fraud

Elias Terman
[email protected] can you put this in the new case study format?
Page 7: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Agenda

The growing bot problemThe impact of bots on e-commerce businessesHow StubHub squashed malicious botsSelection criteria for a bot detection solutionQ & A

Page 8: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

What Is Web Scraping?Web ScrapingAlso known as screen scraping, web scraping is the act of copying large amounts of data from a website – either manually or with an automated program (Bot)

Legitimate ScrapingScraping can sometimes be benevolent and totally acceptable. For example, the search engine bots that index your website

Malicious ScrapingA systematic theft of intellectual property accessible on a website, including pricing, content, images, and proprietary data

Page 9: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Web Scraping at Large Online Beauty Retailer

Black Friday saw a 100x

Increase in Bad Bots

Page 10: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Challenges Distil Results

Competitors were scraping product and pricing data, using it to lure customers away

Stopped competitors from scraping pricing and product data by blocking bad bots

Traffic from malicious bots was consuming server resources and slowing site performance

Eliminated bad bot traffic, cutting server resource needs by 22% while improving performance

Tracking suspicious IP addresses manually was a tedious manual process

Automated the bot detection and mitigation process, saving valuable IT resources

Beauty Retailer Clamps Down on Competitive Data Mining

One of Europe’s largest online beauty retailers.

We have a handful of competitors that cause us a lot of headaches. With Distil, we’ve stopped them from scraping our data, which protects our competitive advantage. In addition, we’ve reduced the load by 22%, and our customers experience faster response times. ”-Principal Solutions Developer

Page 11: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

How Big is the Problem?

Up to 60% of traffic on ecommerce websites are Bad Bots

4.2 million IP addresses impacted by “Pushdo” botnet alone

15% bot traffic can equate to hitting each of your pricing pages 30 times per month

Page 12: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Why the Massive Increase in Bot Traffic? Online data has increased in valuePricing information, product availability, product descriptions, and vendor reviews are changing daily and highly valuable to competitors

Anyone can get in the gameCheap or free virtual servers, bandwidth, easy-to-use tools, and scrapers for hire

Bots no longer tied to IP addressesBots cycle through random IP addresses Bots hide behind anonymous proxies Consumer IPs now infected with bot traffic too

Page 13: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

High Profile Web Scraping in the Ecommerce Industry

QVC is an American television home shopping network and online ecommerce site.

Aggressive price and inventory scraping by shopping aggregator app resulted in the following repercussions for QVC

● Two day website outage● Loss of $2M in revenue● Highly publicized lawsuit● Damage to QVC Brand

Page 14: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Negative SEO Attacks

Bots steal content, product lists, and prices for duplication elsewhere on the Internet

Duplicated content reduces your company’s uniqueness and thus quality score

SEO damage may result, especially if○Your prices are undercut○The content is repurposed on a more popular site

Bots and Negative SEO Attacks

Page 15: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Bots and Competitive Data Mining

Duplicating your Product PortfolioBots can easily gather product and supplier listsfor replication elsewhere

Undermining your PricesBots monitor your prices, ensuring competitorscan undercut with lower price listings

Availability TrackingIdentifying when your supply has been exhausted provides competitors a unique opportunity to raise the price of their goods.

Page 16: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Bots and Security Breaches

Brute Force Account TakeoverUsing a bot to try stolen usernames and passwords from breaches at other websites on your site

Newly compromised accounts are then used for various forms of fraud/theft

Page 17: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Bots and Transaction Fraud

CardingCreating micro-transactions with stolen credit cards against e-commerce sites to test their validity

Page 18: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

About StubHub

Largest secondary ticket marketplace in the worldAn eBay companyProcesses nearly 500 transactions per second

○StubHub is an online marketplace

which provides services for buyers and

sellers of tickets for sports, concerts,

theater and other live entertainment

events.

Page 19: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

StubHub Bot Challenges

Bot Challenges○Bots were used for brute force account takeovers

○Competitors tried to game the system, scraping prices, and monitoring inventory and customer behavior

○Random spikes in bot traffic were causing increased utilizationof resources

○Tested multiple competitor solutions, but they were difficult to configure and in some cases broke our website

Page 20: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

StubHub Bot Selection Criteria

Bot Detection and Mitigation Solution Requirements○Block web scrapers without impacting human visitors

○Accurately identify good bots vs. bad bots

○Cannot solely rely on rule based systemMust include automated learning to “self tune”for defending against emerging and unknown threats

○Needs to include Distil community to improve accuracy of bot detection

○Must seamlessly co-exist with existing solutions(SIEM, CDN, WAF, etc.)

Page 21: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

StubHub Results with Distil Networks

Reduced competitive data mining and fraud

Drastically reduced competitive data mining, increased SEO rankings, and protected our marketplace ecosystem

Distil is a key piece of our fraud detection and prevention suite of tools

Page 22: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

StubHub Results with Distil Networks

Improved traffic quality and enriched analytic data

Cut pageviews in half, without impacting human users or ad deliveries

Quality of traffic has greatly improved by stopping unwanted bots and limiting site access for trusted bots

Page 23: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Negative Security Model - Blocking Bad Bots

Page 24: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Positive Security Model - Whitelisting Trusted Sources

Page 25: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

The Importance of No False Positives / Negative Impact on Humans

Orion Cassetto
[email protected] Can you help me track down a new screenshot for this? I still don't have access to the Distil portal. (i'll ping mark again)
Page 26: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Good bots make up over 35% of all traffic to the average website

○ Search engines - Google, Bing, Baidu, etc.,○ Alexa Crawler○ Pingdom, Keynote, etc.

Effective solutions block bad bots but leave good bots unhindered

The Importance of Accurately Identifying Good vs Bad Bots

Source: Distil Networks, 2015 Bad Bot Landscape Report

Page 27: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Bot detection should never rely on static signatures or manual rule creation

Automation and machine learning must be performed in real-time

Effective bot mitigation solutions ○Dynamically classify users by correlating dozens of data pointsas well as behavior patterns

○Constantly “self-tune” to evolve alongside the morphing threats they encounter and protect against

The Importance of Machine Learning and Self Tuning

Page 28: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

○Real-time updates from a centralized violators database help protect all sites and improve accuracy

○Data from attacks detected anywhere on the network should be centralized, correlated, and analyzed by a big data analysis platform

○Signatures are then constantly updated to drastically reduce false positives (blocking humans) and false negatives (missing bad bots)

The Importance of Community Supported Centralized Threat Database

Page 29: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

Many organizations have complex web environments which may include a multitude of different solutions including

○Content Delivery Networks (CDNs)○WAFs, FW, IPS○SIEMs○Load balancers○and more..

Bot mitigation must be able to seamlessly deployed alongside these technologies without impacting their performance or usage

The Importance of Seamless Compatibility

Page 30: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

The First Easy and Accurate Way to Defend Websites Against Malicious

Bots

Page 31: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

The World’s Most Accurate Bot Detection System

Inline FingerprintingFingerprints stick to the bot even if it attempts to reconnect from random IP addresses or hide behind an anonymous proxy. Known Violators DatabaseReal-time updates from the world’s largest Known Violators Database, which is based on the collective intelligence of all Distil-protected sites.

Browser ValidationThe first solution to disallow browser spoofing by validating each incoming request as self-reported and detects all known browser automation tools.

Behavioral Modeling and Machine LearningMachine-learning algorithms pinpoint behavioral anomalies specific to your site’s unique traffic patterns.

Page 32: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

How Ecommerce Companies Benefit from Distil

Increase insight & control over human, good bot & bad bot

traffic

○Block 99.9% of

malicious bots without

impacting legitimate

users

○Slash the high tax

bots place on internal

teams & web

infrastructure

○Protect data from

web scrapers,

unauthorized

aggregators & hackers

Page 33: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

www.distilnetworks.com/trial/Offer Ends October 15th

Two Months of Free Service + Traffic Analysis

Page 34: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

QUESTIONS….COMMENTS?I N F O @ D I S T I L N E T W O R K S . C O M

OR CALL US ON1.866.423.0606

www.distilnetworks.com

Page 35: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

#RSPS15

Q & A // PanelistsMODERATOR:Alicia Fiorletta Senior Editor, Retail TouchPoints

Rami EssaidCEO & Co-Founder Distil Networks @ramiessaid

Marty BoosSr. Director Technology OperationsStubHub@StubHub

Page 36: Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, Brute Force Attacks, and Click Fraud

#RSPS15

http://www3.retailtouchpoints.com/rsp15/

PLEASE JOIN US FOR OUR NEXT SESSION:Today at 2PM ET / 11AM PT

Thanks for attending!