AZ-EDGIO
Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.
Edgio’s report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization’s infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.
“As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today,” said Tom Gorup, Vice President of Security for Edgio. “We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it’s critical this knowledge is shared to build a safer Internet.”
The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.
In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio’s Top 10 for the quarter.
Top countries by malicious request origin, making up nearly 62% of all requests denied, include:
- United States – 26.3%
- France – 17.4%
- Germany – 9.4%
- Russia – 8.8%
Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.
Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.
Best practices for digital asset protection: proactively stop threats against websites and applications
Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:
- Ensure your WAF provides a layered defense to protect organizations against the known bad, application-specific, and emerging threats. A complete solution will show a distribution of enforcement across access control rules, managed rulesets, and custom signatures.
- Blocklists are still an effective and low-cost part of a layered security approach to safeguard Internet-facing assets. Organizations should also take advantage of threat intelligence feeds to further harden their security posture against known bad actors.
- While managed rules are often maintained and updated by your WAF provider, it is not advisable to use a ‘set it and forget’ approach. As an application evolves and new functionalities are developed, policy reviews and analysis of managed ruleset enforcement is recommended. It is best to ensure rules are closely aligned with business application needs.
- Organizations should take the time to understand where they are doing business and where they aren’t allowed to do business. Block the countries or sub-regions that bring no value to a brand to reduce their attack surface. Blocking embargoed countries is a great starting point, but don’t rely on this approach as a catch all for bad actors.
- Know the application and use this knowledge to inform security solutions, like a WAF, to limit the application request methods or content types based on application needs.
To obtain a full copy of the report, click here.
About Edgio
Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240222674952/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Cessna Citation Ascend Enters Into Service, Redefining Performance and Cabin Experience in the Midsize Business Jet Market31.12.2025 15:00:00 CET | Press release
The Cessna Citation Ascend achieved a major milestone as the first retail customer took delivery of the midsize business jet on Tuesday, December 30, marking the aircraft’s entry into service. Announced in 2023 the aircraft boasts an entirely new cockpit, improved performance and a luxurious flat floor cabin. The Citation Ascend received type certification from the Federal Aviation Administration (FAA) in November 2025. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251231586042/en/ Cessna Citation Ascend enters into service, redefining performance and cabin experience in the midsize business jet market. (Photo credit: Textron Aviation) The Cessna Citation Ascend is designed and manufactured by Textron Aviation Inc., a Textron Inc. (NYSE: TXT) company. “The first Citation Ascend delivery underscores Textron Aviation’s commitment to redefining the midsize segment with an aircraft that blends innovation, efficiency and unmatch
Aster Guardians Global Nursing Award 2026 Worth $250,000 Extends Deadline Till 11th January 202631.12.2025 14:08:00 CET | Press release
Due to an extraordinary global response of over 134,000 registrations from 214 countries, the submission deadline has been extended.Nurses worldwide can submit their nominations via www.asterguardians.com The Aster Guardians Global Nursing Award 2026, an initiative from Aster DM Healthcare – a leading integrated healthcare provider, has announced the extension of its deadline to January 11, 2026. The awards have already received over 134,000 registrations from 214 countries, highlighting its growing global reach and recognition among nurses worldwide. Nurses from around the world can submit their nominations through the dedicated platform at www.asterguardians.com. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251231986766/en/ Aster Guardians Global Nursing Award worth USD 250,000 (Photo: AETOSWire) This year, the prestigious award will be hosted in New Delhi, India, celebrating nursing excellence on a truly global stage. T
Tecnotree Included as a Representative Provider in Gartner® Innovation Insight: AI SOC Agents Accelerate CSP SecOps Transformation31.12.2025 11:59:00 CET | Press release
Tecnotree, a global digital platform and services provider for communications service providers (CSPs), today announced that it has been referenced as a Representative Provider alongside Google, Anthropic, Dropzone AI, DRUID, Palo Alto Networks, and Pegasystems in the Gartner® Innovation Insight: “AI SOC Agents Accelerate CSP SecOps Transformation,” published in December 2025. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251231210303/en/ Tecnotree Included as a Representative Provider in Gartner® Innovation Insight: AI SOC Agents Accelerate CSP SecOps Transformation The Gartner Innovation Insight examines the emerging role of AI-driven Security Operations Centre (SOC) agents in CSP environments, outlining how these agents are used to automate and augment security operations across signalling, core networks, RAN, Open RAN, and roaming domains. The research discusses use cases such as alert triage, investigation support, thr
UAE’s Medcare Treats First International SMA Patient With Revolutionary Intrathecal Gene Therapy30.12.2025 15:15:00 CET | Press release
The newly licensed intrathecal gene therapy expands life-changing treatment options for children and adults affected by SMA Medcare Women & Children Hospital has successfully administered a pioneering intrathecal gene therapy for Spinal Muscular Atrophy (SMA) to Hulus, a three-year-old patient from Turkey. This milestone positions Medcare among the first private healthcare providers worldwide to offer this innovative treatment to an older international patient, overcoming previous age and weight limitations. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251230695275/en/ World's first international patient, who received intrathecal gene therapy at Medcare Royal Hospital in Dubai, UAE, along with parents, and the hospital team. (Photo: AETOSWire) SMA is a rare neuromuscular disorder that progressively weakens muscles responsible for movement and breathing. This newly licensed one-time therapy addresses the root genetic cause
Amazfit Introduces Active Max: Bigger, Brighter, and Built for Maximum Performance30.12.2025 09:00:00 CET | Press release
The newest member of the Active family blends new design, expanded storage, and longer battery to help users train smarter and reach their goals with confidence. Amazfit, a leading global smart wearable brand by Zepp Health (NYSE: ZEPP), today announces the Amazfit Active Max, the newest member of the Amazfit Active family. Built for everyday athletes and anyone looking to elevate their wellness routine, Active Max blends a 1.5″ ultra-bright AMOLED display, up to 25 days of battery life, easy podcast listening and advanced training tools to support consistent training and clearer visibility across any activity. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251230279762/en/ Bigger Display. Max Clarity: A 1.5″ ultra-bright AMOLED display delivers exceptional clarity in any setting—whether in the gym, outdoors, or on the move. With up to 3,000 nits of peak brightness, the screen ensures real-time stats are always easy to read.
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
