AZ-EDGIO
22.2.2024 14:01:35 CET | Business Wire | Press release
Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.
Edgio’s report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization’s infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.
“As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today,” said Tom Gorup, Vice President of Security for Edgio. “We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it’s critical this knowledge is shared to build a safer Internet.”
The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.
In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio’s Top 10 for the quarter.
Top countries by malicious request origin, making up nearly 62% of all requests denied, include:
- United States – 26.3%
- France – 17.4%
- Germany – 9.4%
- Russia – 8.8%
Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.
Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.
Best practices for digital asset protection: proactively stop threats against websites and applications
Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:
- Ensure your WAF provides a layered defense to protect organizations against the known bad, application-specific, and emerging threats. A complete solution will show a distribution of enforcement across access control rules, managed rulesets, and custom signatures.
- Blocklists are still an effective and low-cost part of a layered security approach to safeguard Internet-facing assets. Organizations should also take advantage of threat intelligence feeds to further harden their security posture against known bad actors.
- While managed rules are often maintained and updated by your WAF provider, it is not advisable to use a ‘set it and forget’ approach. As an application evolves and new functionalities are developed, policy reviews and analysis of managed ruleset enforcement is recommended. It is best to ensure rules are closely aligned with business application needs.
- Organizations should take the time to understand where they are doing business and where they aren’t allowed to do business. Block the countries or sub-regions that bring no value to a brand to reduce their attack surface. Blocking embargoed countries is a great starting point, but don’t rely on this approach as a catch all for bad actors.
- Know the application and use this knowledge to inform security solutions, like a WAF, to limit the application request methods or content types based on application needs.
To obtain a full copy of the report, click here.
About Edgio
Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240222674952/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Vertex to Present New Data on ALYFTREK® at the North American Cystic Fibrosis Conference9.10.2026 19:15:00 CEST | Press release
- Data on ALYFTREK in children ages 2 to 5 years demonstrate recovery of pancreatic function in some children –- Additional abstracts on clinical and real-world evidence on CFTR modulators also presented - Vertex Pharmaceuticals Incorporated (Nasdaq: VRTX) today announced new interim data from the ALYFTREK® (vanzacaftor/tezacaftor/deutivacaftor) 2 to 5 years old open-label extension study, highlighting recovery of exocrine pancreatic function in some children in that age group, allowing those children to discontinue pancreatic enzyme replacement therapy (PERT). Pancreatic exocrine insufficiency in children with cystic fibrosis (CF) was previously believed to be irreversible. These data were presented at the North American Cystic Fibrosis Conference (NACFC). “The data presented at NACFC underscore the safety and efficacy of our CF medicines in the real world and in clinical trials in younger age groups. The data from the Phase 3 open-label study in 2 to 5 year olds evaluating exocrine p
Andersen Consulting udvider med TalentSmartEQ for at fremme lederskab og virksomhedstransformation9.10.2026 18:48:00 CEST | Pressemeddelelse
Andersen Consulting styrker sine kompetencer inden for humankapital gennem en samarbejdsaftale med TalentSmartEQ, en San Diego-baseret virksomhed, der har fokus på at skabe praktiske, engagerende og handlingsorienterede læringsoplevelser med udgangspunkt i emotionel intelligens (EQ) og lederudvikling. I mere end to årtier har TalentSmartEQ arbejdet sammen med organisationer verden over med henblik på at udvikle ledelseskompetencer ved hjælp af emotionel intelligens og dermed styrke medarbejderengagement, teamwork og de samlede resultater. Virksomheden kombinerer forskningsbaserede metoder med praktiske læringsforløb, vurderinger, coaching og skræddersyede programmer, der skal omsætte opbygningen af emotionel intelligens til vedvarende ændringer i adfærden på arbejdspladsen. Som førende aktør i branchen samarbejder TalentSmartEQ med organisationer lige fra Fortune 500-virksomheder til offentlige myndigheder og privatejede virksomheder. "Organisationer stiller stadig større krav til dere
Verdant Rock Receives A (low) Financial Strength Rating from Morningstar DBRS, Adding a Second International Investment-Grade Assessment9.10.2026 16:00:00 CEST | Press release
Verdant Rock now holds Financial Strength Ratings from both Fitch Ratings and Morningstar DBRS, providing counterparties with dual-agency confirmation and reinforcing the security architecture behind each financial guarantee Verdant Rock Limited, a Bermuda Monetary Authority-regulated Class 3B insurance company, has received an A (low) Financial Strength Rating from Morningstar DBRS. The rating reflects Verdant Rock’s financial strength and its capacity to meet policyholder obligations as an investment-grade financial guarantor for Emerging Markets credit. Morningstar DBRS is a global credit rating agency with coverage across North America, Europe, Asia, and Latin America. Its assessment of Verdant Rock reflects the company’s strong projected earnings ability, robust risk profile, sound liquidity, and good capitalization. Morningstar DBRS also assigned an A (low) Issuer Rating to Verdant Rock. The rating follows Verdant Rock’s BBB+ Long-Term Insurer Financial Strength Rating with a Sta
Tecnotree Named a Visionary in the Inaugural 2026 Gartner® Magic Quadrant™ for CSP AI-Enabled Marketing and Sales Solutions9.10.2026 15:17:00 CEST | Press release
We think Gartner recognizes Tecnotree's open, governed approach to agentic AI as operators make AI the engine of their revenue operations Tecnotree, a global digital platform and services leader for AI, 5G, and cloud-native technologies, today announced that Gartner has positioned it as a Visionary in the first-ever Magic Quadrant for AI-Enabled CSP Marketing and Sales Solutions. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20261009905430/en/ Tecnotree Named a Visionary in the Inaugural 2026 Gartner® Magic Quadrant™ for CSP AI-Enabled Marketing and Sales Solutions A new category for a new operating model. CSPs are fighting saturated markets, rising acquisition costs, and accelerating churn. They are responding with AI-driven automation across the full revenue cycle, from segmentation and campaigns to lead management, CPQ, and renewals, increasingly executed by autonomous agents. According to us, Gartner creation of this Magi
Positive New Data on Corcym’s Perceval Plus Sutureless Aortic Heart Valve Encompasses up to 7-Year Follow-up9.10.2026 15:15:00 CEST | Press release
Data Presented at Annual Meeting of European Association for Cardio-Thoracic Surgery (EACTS), Along with 6 Perceval Plus E-PostersEACTS Also Marks Commercial Launch of TriMemo and Memo 4D Curve, Innovative Repair Devices for Tricuspid and Mitral Valves Corcym, a global medical device company dedicated to cardiac surgery, today announced that positive mid-term data from a sub-analysis of its Perceval Plus sutureless aortic heart valve as part of its MANTRA clinical trial was featured in an oral presentation today at the annual meeting of the European Association for Cardio-Thoracic Surgery (EACTS). The study is the longest follow-up available for Perceval Plus and the FREE tissue treatment from an international multicenter study, and demonstrated excellent durability, safety and quality of life improvements. Perceval Plus is the only sutureless and collapsible aortic surgical heart valve. Its unique design performs in any surgical scenario and is optimal for endoscopy and robotics. The
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
