AZ-EDGIO
22.2.2024 14:01:35 CET | Business Wire | Press release
Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.
Edgio’s report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization’s infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.
“As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today,” said Tom Gorup, Vice President of Security for Edgio. “We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it’s critical this knowledge is shared to build a safer Internet.”
The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.
In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio’s Top 10 for the quarter.
Top countries by malicious request origin, making up nearly 62% of all requests denied, include:
- United States – 26.3%
- France – 17.4%
- Germany – 9.4%
- Russia – 8.8%
Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.
Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.
Best practices for digital asset protection: proactively stop threats against websites and applications
Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:
- Ensure your WAF provides a layered defense to protect organizations against the known bad, application-specific, and emerging threats. A complete solution will show a distribution of enforcement across access control rules, managed rulesets, and custom signatures.
- Blocklists are still an effective and low-cost part of a layered security approach to safeguard Internet-facing assets. Organizations should also take advantage of threat intelligence feeds to further harden their security posture against known bad actors.
- While managed rules are often maintained and updated by your WAF provider, it is not advisable to use a ‘set it and forget’ approach. As an application evolves and new functionalities are developed, policy reviews and analysis of managed ruleset enforcement is recommended. It is best to ensure rules are closely aligned with business application needs.
- Organizations should take the time to understand where they are doing business and where they aren’t allowed to do business. Block the countries or sub-regions that bring no value to a brand to reduce their attack surface. Blocking embargoed countries is a great starting point, but don’t rely on this approach as a catch all for bad actors.
- Know the application and use this knowledge to inform security solutions, like a WAF, to limit the application request methods or content types based on application needs.
To obtain a full copy of the report, click here.
About Edgio
Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240222674952/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
SLB Collaborates with Qualcomm on Edge AI Solutions for Energy Operations9.6.2026 16:28:00 CEST | Press release
Collaboration combines edge computing and energy workflows to support real-time operational decision-making Global energy technology company SLB (NYSE: SLB) today announced a memorandum of understanding with Qualcomm Technologies, Inc. to enable edge AI solutions for the energy industry, supporting real-time operational decision-making across wells, facilities and production systems. The collaboration combines Qualcomm Technologies’ low-power edge computing and AI processing capabilities, with SLB’s Agora™ edge AI and IoT solutions developed for remote and operationally complex environments. “Together, SLB and Qualcomm Technologies aim to help operators apply AI more effectively across energy infrastructure,” said Rakesh Jaggi, president, Digital, SLB. “Many energy operations rely on real-time decision-making in remote environments where connectivity and responsiveness directly affect performance. AI systems designed around the realities of energy operations can help support more consi
RevBits and Stony Brook University’s Ethos Lab Establish a Collaborative Partnership to Further the Field of Cyber Security Education and Application9.6.2026 16:15:00 CEST | Press release
Through the partnership, RevBits will provide its full suite of cybersecurity solutions to Stony Brook University’s Ethos Lab, to deliver the capability to advance student education and equip them with the knowledge needed to face modern cyber threats in a realistic, contained environment. Stony Brook University’s (SBU) Ethos Lab, in the College of Engineering and Applied Sciences Department of Computer Science, recently announced a collaborative partnership with RevBits, LLC. Through the partnership, SBU’s Ethos Lab will utilize the RevBits solutions suite to build computer science labs and a cybersecurity-focused curriculum, reinforcing lessons from the classroom. The platform simulates environments containing five major threat landscapes, including Endpoint Security, Privileged Access Management, Email Security, Zero Trust Network and Deception Technology. SBU’s Department of Computer Science was recently designated as a National Center of Academic Excellence in Cybersecurity Resear
Marie® by Leo Cancer Care Makes History at Stanford Medicine — World First in Compact Upright Proton Therapy9.6.2026 15:22:00 CEST | Press release
The first patient treated was a child. The milestone marks the moment upright proton therapy moves from innovation to adoption — and reflects exactly what Leo Cancer Care built Marie® to achieve Following the landmark first treatment at Stanford Medicine Cancer Center Care June 4, Leo Cancer Care today announces the role of its Marie® upright patient positioning and imaging platform in enabling the world's first compact upright proton therapy patient treatment. Delivered using the Mevion S250-FIT™ Proton Therapy System and powered by RayStation from RaySearch, the milestone is the culmination of a decade of development. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260609870736/en/ The treatment room at Stanford Medicine Cancer Center, Palo Alto, California, housing the Marie® upright patient positioning platform by Leo Cancer Care (center foreground) integrated with the Mevion S250-FIT™ Proton Therapy System. The circular
Volante Technologies launches “Vol360i” Agentic AI at the core of payments, setting a new global standard for intelligence in banking9.6.2026 15:00:00 CEST | Press release
Agents deliver configurable, confidence-based automation and predictability to financial institutions through exception handling, routing, and SLA monitoring Volante Technologies, the global leader in Payments as a Service (PaaS), today announced that its Payments Platform and PaaS operations are now powered by its “Vol360i” Agentic AI. The core upgrade unlocks autonomous and semi-autonomous collaboration to reduce manual intervention, significantly increasing straight-through processing (STP) rates to over 95%, accelerating exception resolution, and proactively managing SLA performance. Vol360i is immediately available to Volante banking and financial institution clients, with four main operating principles guiding Volante’s agentic framework to deliver a frictionless payments experience: Prevent Agents: Eliminate failures before they occur, boosting reliability and reducing customer-impacting errors. Repair Agents: Self-healing AI fixes problems in real time, allowing operators to fo
Boomi Adds Snowflake Cortex Agents Support to Agentstudio to Enable Unified AI Agent Governance9.6.2026 15:00:00 CEST | Press release
Snowflake Cortex Agents support in Boomi Agentstudioenables joint customers to govern all their agents in a single, vendor-agnostic control tower Boomi, the data activation company for AI and an Elite Snowflake partner, today announced the launch of Snowflake Cortex Agents support for Agentstudio. This new integration, powered by Snowflake, enables organizations to monitor, manage, and govern every Cortex Agent that is part of their agentic workforce. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260609131798/en/ Boomi Adds Snowflake Cortex Agents Support to Agentstudio to Enable Unified AI Agent Governance "Customers are scaling AI agents into production, and partners are bringing new solutions to market at record speed, both powered by Boomi Agentstudio,” said Steve Lucas, Chairman and CEO at Boomi. “This dual momentum reflects the unique strength of the Boomi Enterprise Platform, empowering innovation while ensuring gove
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
