Business Wire

AZ-EDGIO

22.2.2024 14:01:35 CET | Business Wire | Press release

Share
Web Application Attacks Intensify in Fourth Quarter of 2023, According to New Edgio Quarterly Attack Trends Report

Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.

Edgio’s report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization’s infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.

“As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today,” said Tom Gorup, Vice President of Security for Edgio. “We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it’s critical this knowledge is shared to build a safer Internet.”

The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.

In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio’s Top 10 for the quarter.

Top countries by malicious request origin, making up nearly 62% of all requests denied, include:

  • United States – 26.3%
  • France – 17.4%
  • Germany – 9.4%
  • Russia – 8.8%

Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.

Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.

Best practices for digital asset protection: proactively stop threats against websites and applications

Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:

  • Ensure your WAF provides a layered defense to protect organizations against the known bad, application-specific, and emerging threats. A complete solution will show a distribution of enforcement across access control rules, managed rulesets, and custom signatures.
  • Blocklists are still an effective and low-cost part of a layered security approach to safeguard Internet-facing assets. Organizations should also take advantage of threat intelligence feeds to further harden their security posture against known bad actors.
  • While managed rules are often maintained and updated by your WAF provider, it is not advisable to use a ‘set it and forget’ approach. As an application evolves and new functionalities are developed, policy reviews and analysis of managed ruleset enforcement is recommended. It is best to ensure rules are closely aligned with business application needs.
  • Organizations should take the time to understand where they are doing business and where they aren’t allowed to do business. Block the countries or sub-regions that bring no value to a brand to reduce their attack surface. Blocking embargoed countries is a great starting point, but don’t rely on this approach as a catch all for bad actors.
  • Know the application and use this knowledge to inform security solutions, like a WAF, to limit the application request methods or content types based on application needs.

To obtain a full copy of the report, click here.

About Edgio

Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240222674952/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

PMCOrganometallix Announces Price Increase on All Products24.4.2026 22:55:00 CEST | Press release

Due to significant changes in market conditions, PMC Organometallix, Inc. announces that effective May 1, 2026, or as contracts permit, prices across all product lines globally will increase by 10-25%. This adjustment is driven by sustained cost pressures from key inputs including rising raw material costs and escalating freight and logistics expenses. While the company has been absorbing these increases, the current economic environment brought on by the geopolitical crisis of the Iran conflict requires this adjustment to continue providing the high-quality, consistent materials and supply reliability that customers expect. PMC Organometallix will implement these changes in a transparent, collaborative manner and values your partnership while navigating these economic challenges. Customers with questions or to discuss a specific situation should contact their account representative. About PMC Group PMC Group is a growth-oriented, diversified, global chemicals and plastics company deli

Frankfurt Higher Regional Court upholds BESREMi® arbitral award in favor of AOP Health24.4.2026 18:52:00 CEST | Press release

Today, the Higher Regional Court of Frankfurt upheld the February 20251 partial final ICC arbitral award in favor of AOP Orphan Pharmaceuticals GmbH (“AOP Health”) in its dispute with PharmaEssentia Corp. (“PharmaEssentia”). The ruling confirms the award which found the Taiwanese company to be liable for certain damages. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260424005227/en/ Portrait Dr. Rudolf Widmann, Founder AOP Health Credit: AOP Health/Daniel Ospelt Dr. Rudolf Widmann, one of the two founders of AOP Health, explains: “We very much welcome the Frankfurt Higher Regional Court’s decision that confirms our position. In the interest of our patients, we are dedicated to maintaining stable and sustainable access to BESREMi® and to responsibly navigating future challenges.” The Product in Dispute The conflict centers around BESREMi® (ropeginterferon alfa-2b), a product launched in 2019 and developed by AOP Health into

Compass Pathways Announces FDA Granted NDA Rolling Review Request and Awarded Commissioner's National Priority Voucher24.4.2026 16:37:00 CEST | Press release

Compass is the most advanced company in classic psychedelics and has generated positive data from two ongoing large, well controlled Phase 3 clinical trials, designed to uphold the highest regulatory standardsFDA grants Compass NDA rolling submission and review request, based on Phase 3 dataCNPV awarded for COMP360, Compass’ proprietary formulation of synthetic psilocybin, for treatment-resistant depression (TRD)CNPV further accelerates momentum and Compass is confident and ready to deliver for patients Compass Pathways plc (Nasdaq: CMPS), a biotechnology company dedicated to accelerating patient access to evidence-based innovation in mental health, today announced the U.S. Food and Drug Administration (FDA) granted Compass NDA rolling review request and selected COMP360, Compass’ proprietary formulation of synthetic psilocybin, for the Commissioner's National Priority Voucher (CNPV) program for treatment-resistant depression (TRD). Companies selected for the voucher program will be en

Banma Intelligence and Alipay Launch AI Cockpit Solution Powered by Alipay AI Pay, Enabling Seamless and Secure In-Car Transactions by Voice24.4.2026 16:04:00 CEST | Press release

At the 2026 Beijing International Automotive Exhibition (“Auto China 2026”), OS and AI technology company Banma Intelligence and Alipay today launched a new AI cockpit solution integrating Alipay AI Pay, enabling drivers to complete purchases by voice command directly from their vehicle. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260424618328/en/ Industry-first AI Cockpit Solution with Alipay AI Pay Unveiled “In the past two years, smart cockpits have achieved rapid advances in perception and decision-making,” said Ming Cai, Banma Intelligence Chief Product Officer. “With large models onboard, vehicles can understand user intent and make recommendations. By integrating Alipay AI Pay into our AI cockpit solution, we are removing the last friction point in the in-car smart cockpit experience - drivers simply speak to pay, no phone required.” The new AI cockpit solution initially covers two high-frequency use cases: enterta

Spatial Announces the Release 2026 1.0.1: New Enhancements Across 3D InterOp, Data Prep, Meshing, and 3D Modeling SDKs24.4.2026 15:21:00 CEST | Press release

Spatial Corp., the leading software development kit provider for design, manufacturing and engineering solutions and a subsidiary of Dassault Systèmes, today announced new enhancements across several of its product lines. These updates further strengthen Spatial’s commitment to delivering high-performance solutions that optimize interoperability, data preparation, and advanced modeling workflows. Designed to improve efficiency and robustness across CAD translation, modeling, meshing, and simulation processes, the latest updates introduce expanded format support, enhanced PMI handling, and new capabilities for complex geometry processing. 3D InterOp NX Reader Enhancement for 2D Drawings The NX reader imports 2D drawings as visualization data from NX 2412 and later versions. glTF Writer Supports Draco Compression glTF export incorporates Draco compression for meshes and point-clouds to significantly reduce output file sizes. Enhanced Support for Reading Product Manufacturing Information

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye