Statistics found in a new report from cloud security provider Barracuda Networks has revealed that automated traffic takes up nearly two-thirds of internet traffic (64%).
From this startling figure, 25% of automated traffic was made up by good bots – such as search engine crawlers and social network bots – while nearly two-fifths (39%) was from bad bots.
Bad bots include both basic web scrapers and attack scripts, as well as advanced, persistent bots.
These advanced bots try their best to evade standard defences and attempt to perform malicious activities under the radar. The report revealed that the most common of these persistent bots were ones that went after e-commerce applications and login portals.
The report, titled Bot attacks: Top Threats and Trends – Insights into the growing number of automated attacks, also included a breakdown of bad bot traffic by location.
It revealed that North America accounts for 67% of bad bot traffic, followed by Europe (22%) and then Asia (7.5%).
Interestingly, the European bot traffic was more likely to come in from hosting services (VPS) or residential IPs than the North American traffic, most of which originated from public data centres.
Commenting on the statistics, Nitzan Miron, VP of Product Management and Application Security at Barracuda, said: “While some bots like search engine crawlers are good, our research shows that over 60% of bots are dedicated to carrying out malicious activities at scale.
“When left unchecked, these bad bots can attack user accounts, skew analytics, steal data, affect site performance and destroy customer experience.
Recommended
- ICO stings firms with record 1580% rise in fines in 2020/21
- UK chip maker ARM’s China boss ‘declares independence’
- New partnership seeks to aid digital transformation in Scots industries
The research also revealed that most bot traffic comes in from the two largest public cloud vendors, AWS and Microsoft Azure, in roughly equal measure. This is likely because it is easy to set up a free account with either provider, and then use the account to set up the bad bots.
Finally, Barracuda researchers observed that bad bot traffic tends to follow the standard workday, allowing them to hide within normal human traffic streams to avoid raising alarm bells.
Commenting on this, Miron says: “[That’s why] it’s critically important to detect and effectively block bot traffic by investing in Web Application and API Protection technology that can identify and stop bad bots whilst simultaneously improving user experience and overall security.
“Today, many security decision makers in business can be overwhelmed by the process of protecting against newer attack threats, like bad bots, but fortunately, all it requires is for them to invest in the right application security solution that includes anti-bot protection alongside machine-learning capabilities, to most effectively detect and block sophisticated bot attacks.”





