Business Wire

AZ-EDGIO

Share
Web Application Attacks Intensify in Fourth Quarter of 2023, According to New Edgio Quarterly Attack Trends Report

Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.

Edgio’s report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization’s infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.

“As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today,” said Tom Gorup, Vice President of Security for Edgio. “We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it’s critical this knowledge is shared to build a safer Internet.”

The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.

In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio’s Top 10 for the quarter.

Top countries by malicious request origin, making up nearly 62% of all requests denied, include:

  • United States – 26.3%
  • France – 17.4%
  • Germany – 9.4%
  • Russia – 8.8%

Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.

Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.

Best practices for digital asset protection: proactively stop threats against websites and applications

Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:

  • Ensure your WAF provides a layered defense to protect organizations against the known bad, application-specific, and emerging threats. A complete solution will show a distribution of enforcement across access control rules, managed rulesets, and custom signatures.
  • Blocklists are still an effective and low-cost part of a layered security approach to safeguard Internet-facing assets. Organizations should also take advantage of threat intelligence feeds to further harden their security posture against known bad actors.
  • While managed rules are often maintained and updated by your WAF provider, it is not advisable to use a ‘set it and forget’ approach. As an application evolves and new functionalities are developed, policy reviews and analysis of managed ruleset enforcement is recommended. It is best to ensure rules are closely aligned with business application needs.
  • Organizations should take the time to understand where they are doing business and where they aren’t allowed to do business. Block the countries or sub-regions that bring no value to a brand to reduce their attack surface. Blocking embargoed countries is a great starting point, but don’t rely on this approach as a catch all for bad actors.
  • Know the application and use this knowledge to inform security solutions, like a WAF, to limit the application request methods or content types based on application needs.

To obtain a full copy of the report, click here.

About Edgio

Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240222674952/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Stronghold’s SHx Token Lists on Uphold27.11.2025 16:00:00 CET | Press release

Multi-Chain Expansion Accelerates With New Listing on a Trusted Platform Supporting Both Stellar and Ethereum Stronghold announced that its SHx token is now available for retail users to trade on Uphold, the global multi-asset digital money platform known for its transparency, regulatory alignment, and seamless support for assets across both the Stellar and Ethereum networks. The listing marks a major milestone for SHx, expanding access for users and businesses who rely on Stronghold’s token for payments, settlements, and governance participation. "Uphold is one of the only platforms that provides seamless support for both Stellar and Ethereum-based tokens, making it a perfect fit for SHx as we grow our multi-chain ecosystem. This listing was championed by our community, and we’re thrilled to deliver on a request that so many SHx holders have been asking for." — Tammy Camp, CEO & Co-Founder, Stronghold SHx is Stronghold’s native utility token, powering interoperable payments, DeFi-base

Wipro to Power Odido’s Digital Future Through AI-enabled End-to-End IT Modernization27.11.2025 14:22:00 CET | Press release

The multi-year engagement marks a significant shift in Odido’s IT strategywith Wipro bringing deep domain expertise, AI-powered delivery, and a design-led approach to drive innovation Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO), a leading AI-powered technology services and consulting company, today announced a multi-year engagement with Odido Netherlands B.V.* to transform its IT landscape and enhance customer experience across their enterprise and consumer segments. By combining AI and deep consulting expertise, Wipro will help Odido improve customer engagement and satisfaction, improve productivity, and streamline operations to reduce costs. A key highlight of this multi-year engagement is the use of a self-funded model, where productivity-driven savings are reinvested to continuously fund new digital initiatives, ensuring that innovation remains both sustainable and scalable. As part of the engagement, Wipro will lead a full-scale modernization of Odido’s digital and enterpri

Klarna Set to Take off With Lufthansa Group, Bringing Flexible Payments to Travellers Across Europe and the U.S.27.11.2025 14:00:00 CET | Press release

Klarna, the global digital bank and flexible payments provider, today announces a new multi-market partnership with Lufthansa Group, Europe’s leading airline group. The new agreement is facilitated by Klarna’s integration with Adyen, the financial technology platform of choice for leading businesses. From November, Lufthansa Group customers will be able to choose Klarna’s flexible payment options at checkout when booking travel experiences. This new integration gives travellers greater control and convenience by offering the choice to pay in full, pay later, or spread the cost of their journey over time. The new options will be available first to customers in Austria, Belgium, Denmark, Finland, Germany, the Netherlands, Norway, Sweden, Switzerland, and the United States. “Travel is one of the most meaningful investments people make,” said David Sykes, Chief Commercial Officer at Klarna. “Together, we’re giving travellers the confidence to book their trips their way—with more flexibilit

GE HealthCare announces CE Mark for new digital 4D SPECT/CT system, StarGuide GX27.11.2025 12:06:00 CET | Press release

FOR USE IN CE-MARK EUROPEAN COUNTRIES ONLY StarGuide GXi empowers personalized care and research innovation as nuclear medicine expands into new applications The system doubles volume sensitivity,ii maintains high resolution and enables clinicians to virtually scan all energies fast – including the acquisition of investigational alpha emitters like Actinium-225 – with exceptional clarity and quantitation GE HealthCare today announced CE Mark for its new StarGuide™ GX system,i a new digital 4D SPECT/CT designed with excellent precision, clinical efficiency and impressive versatility. This milestone marks a significant moment in molecular imaging’s evolution, helping empower clinicians to expand research and help personalize care across a growing range of nuclear medicine applications and tracers – including the acquisition of alpha emitters. StarGuide GX comes at a pivotal time for the field of nuclear medicine. As complex diseases such as cancer, Alzheimer’s and cardiovascular disease

Deetken Impact Expands Climate Finance Leadership as Canada Joins Inclusive Climate Action Fund27.11.2025 10:07:00 CET | Press release

Deetken Impact, a Canadian impact investment firm, is proud to partner with the Government of Canada and announce their CAD$106 million commitment in the new Inclusive Climate Action Fund (ICAF), a USD$300 million blended finance vehicle that will mobilize capital for climate finance initiatives across Latin America and the Caribbean (LAC). Announced at the 30th United Nations Climate Change Conference (COP30) in Belém, Brazil by the Honourable Julie Dabrusin, Canada’s Minister of Environment and Climate Change, ICAF will meaningfully contribute to sustainable and climate-resilient economies in LAC through the strategic provision of capital and technical assistance to companies and projects that drive climate mitigation and adaptation in key sectors such as clean energy, sustainable agriculture and agroforestry, and green finance. ICAF aims to achieve ambitious impacts including reducing, avoiding, or sequestering more than 5 million tCO2 and expanding access to climate solutions for 1

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye