Business Wire

AZ-EDGIO

22.2.2024 14:01:35 CET | Business Wire | Press release

Share
Web Application Attacks Intensify in Fourth Quarter of 2023, According to New Edgio Quarterly Attack Trends Report

Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.

Edgio’s report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization’s infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.

“As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today,” said Tom Gorup, Vice President of Security for Edgio. “We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it’s critical this knowledge is shared to build a safer Internet.”

The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.

In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio’s Top 10 for the quarter.

Top countries by malicious request origin, making up nearly 62% of all requests denied, include:

  • United States – 26.3%
  • France – 17.4%
  • Germany – 9.4%
  • Russia – 8.8%

Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.

Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.

Best practices for digital asset protection: proactively stop threats against websites and applications

Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:

  • Ensure your WAF provides a layered defense to protect organizations against the known bad, application-specific, and emerging threats. A complete solution will show a distribution of enforcement across access control rules, managed rulesets, and custom signatures.
  • Blocklists are still an effective and low-cost part of a layered security approach to safeguard Internet-facing assets. Organizations should also take advantage of threat intelligence feeds to further harden their security posture against known bad actors.
  • While managed rules are often maintained and updated by your WAF provider, it is not advisable to use a ‘set it and forget’ approach. As an application evolves and new functionalities are developed, policy reviews and analysis of managed ruleset enforcement is recommended. It is best to ensure rules are closely aligned with business application needs.
  • Organizations should take the time to understand where they are doing business and where they aren’t allowed to do business. Block the countries or sub-regions that bring no value to a brand to reduce their attack surface. Blocking embargoed countries is a great starting point, but don’t rely on this approach as a catch all for bad actors.
  • Know the application and use this knowledge to inform security solutions, like a WAF, to limit the application request methods or content types based on application needs.

To obtain a full copy of the report, click here.

About Edgio

Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240222674952/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

FPT Launches Flezi Foundry™, Advancing AI-Augmented Delivery for Global Enterprises22.5.2026 10:11:00 CEST | Press release

Global IT corporation FPT announced the launch of Flezi Foundry™ (FPT Digital Foundry™), an AI-augmented delivery platform for software development and IT operations. Built around a governed Service-as-a-Software model, the platform combines autonomous AI agents, human expert oversight, secure infrastructure, and outcome-based delivery mechanisms to help enterprises modernize technology delivery as AI agents become part of software engineering and IT operations. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260521235556/en/ Flezi Foundry applies Agentic Engineering, a structured delivery approach for software development and IT operations. The model brings AI agents into delivery workflows with human supervision, governance, transparency, and performance measurement built into the process. Flezi Foundry operates through two service modes: Agentic Development Lifecycle (ADLC) supports software development by using specialize

Boomi Named One of The Sunday Times Best Places to Work 202622.5.2026 08:00:00 CEST | Press release

Employee-led recognition places Boomi among the UK's top medium-sized employers, with a flight risk of just 3% against a technology sector average of 42% Boomi achieves an average employee happiness score of 86%, rated Excellent across all six dimensions of WorkL's workplace framework Flight risk of just 3%, compared to a technology sector average of 42%, reflecting exceptional levels of employee loyalty Rated Excellent for Diversity and Inclusion and Confidence in Management Boomi, the data activation company for AI, has today been named one of The Sunday Times Best Places to Work 2026 in the Medium Organisation category. The prestigious annual list, produced by The Sunday Times in partnership with global workplace analytics company WorkL, recognises the UK's finest employers based entirely on direct employee feedback, making it one of the most credible and transparent employer benchmarks in the country. This press release features multimedia. View the full release here: https://www.b

LTM Has Issued an Offer to Acquire Randstad’s Technology and Consulting Services Business in Europe and Australia to Scale Domain-Driven Solutions and AI Services22.5.2026 07:09:00 CEST | Press release

The deal would be part of a 360° partnership with Randstad involving: Proposed acquisition of USD 500M+ (€469M) business, primarily across Aerospace & Defence, Automotive, Utilities and BFS Five-year IT services partnership to drive AI-enabled transformation for Randstad’s India Global Capability Center Strategic talent MSP to support LTM’s expanding global workforce LTM and Randstad announced that LTM has issued an offer to acquire Randstad’s Technology and Consulting Servicesbusiness in France, Germany, Belgium, Luxembourg and Australia, representing USD 500+ million (€469M) in annual revenue, to scale domain-driven solutions and AI services in the region. The proposed acquisition would expand LTM’s presence in key markets, primarily across Aerospace & Defence, Automotive, Utilities and BFS. It would enable local domain expertise and complementary regional capabilities in domain-driven digital engineering, cybersecurity and IoT, supported by onshore and nearshore delivery through cen

Polpharma Biologics and Tuteur Sign Licensing Agreement for a Biosimilar for Autoimmune Diseases22.5.2026 07:00:00 CEST | Press release

Polpharma Biologics, a leading biopharmaceutical company specializing in the development and manufacturing of biosimilars, today announced the signing of a landmark licensing agreement with Argentina-based Tuteur. Under this strategic partnership, Tuteur will obtain exclusive rights to commercialize a biosimilar for autoimmune diseases across Latin America (LATAM), excluding Brazil. Polpharma Biologics will retain full responsibility for the development and manufacturing of the biosimilar. Tuteur will be responsible for commercialization, marketing, and distribution in the licensed territories. This collaboration reflects a shared commitment to expanding patient access to high-quality, affordable biological therapies across the region. “Partnering with Tuteur represents an important step in advancing our mission to broaden access to biosimilars globally,” said Anjan Selz, CEO of Polpharma Biologics. “With their strong regional expertise and commercial capabilities in LATAM, we are well

Global Stars Ahn Hyo-seop and Khalid Release New Cross-Market Single “Something Special” via FANDOM Today22.5.2026 06:00:00 CEST | Press release

Produced by Woo “RAINSTONE” Rhee and Grammy Award-Winning Producer Troy “R8DIO” JohnsonStream the Single HERE For approved imagery, please download HERE Today marks the official release of “Something Special,” the highly anticipated cross-market collaboration from international star Ahn Hyo-seop and multi-platinum recording artist Khalid, available now via FANDOM on all major streaming platforms. Stream the single HERE. Musicow will also release an official music video in June, highlighting the unique chemistry between Ahn Hyo-seop and Khalid while bringing the song’s cross-cultural collaboration to life on screen. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260522928365/en/ Ahn Hyo-seop, globally recognized for his breakout role as “Jinu,” the leader of demon boy band Saja Boys in Netflix’s animated phenomenon KPop Demon Hunters, joins forces with Grammy-nominated artist Khalid for a genre-blending release that bridges t

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye