Business Wire

AZ-EDGIO

Share
Web Application Attacks Intensify in Fourth Quarter of 2023, According to New Edgio Quarterly Attack Trends Report

Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.

Edgio’s report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization’s infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.

“As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today,” said Tom Gorup, Vice President of Security for Edgio. “We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it’s critical this knowledge is shared to build a safer Internet.”

The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.

In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio’s Top 10 for the quarter.

Top countries by malicious request origin, making up nearly 62% of all requests denied, include:

  • United States – 26.3%
  • France – 17.4%
  • Germany – 9.4%
  • Russia – 8.8%

Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.

Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.

Best practices for digital asset protection: proactively stop threats against websites and applications

Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:

  • Ensure your WAF provides a layered defense to protect organizations against the known bad, application-specific, and emerging threats. A complete solution will show a distribution of enforcement across access control rules, managed rulesets, and custom signatures.
  • Blocklists are still an effective and low-cost part of a layered security approach to safeguard Internet-facing assets. Organizations should also take advantage of threat intelligence feeds to further harden their security posture against known bad actors.
  • While managed rules are often maintained and updated by your WAF provider, it is not advisable to use a ‘set it and forget’ approach. As an application evolves and new functionalities are developed, policy reviews and analysis of managed ruleset enforcement is recommended. It is best to ensure rules are closely aligned with business application needs.
  • Organizations should take the time to understand where they are doing business and where they aren’t allowed to do business. Block the countries or sub-regions that bring no value to a brand to reduce their attack surface. Blocking embargoed countries is a great starting point, but don’t rely on this approach as a catch all for bad actors.
  • Know the application and use this knowledge to inform security solutions, like a WAF, to limit the application request methods or content types based on application needs.

To obtain a full copy of the report, click here.

About Edgio

Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240222674952/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Transition Industries and Mitsubishi Gas Chemical Sign Agreement for the Purchase and Sale of Ultra-Low Carbon Methanol6.11.2025 05:00:00 CET | Press release

Transition Industries LLC, a developer of world-scale, net-zero carbon emissions methanol and hydrogen projects, signed a long-term methanol sales and purchase agreement with Mitsubishi Gas Chemical Company, Inc. (MGC) for the offtake of ultra-low carbon methanol. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251105695992/en/ Masahiko Naito, Division Director of Mitsubishi Gas Chemical and Rommel Gallo, CEO of Transition Industries sign agreement in Tokyo, November 6, 2025 Under the Agreement, which will become effective upon the Project’s Final Investment Decision (FID), Transition Industries will supply MGC approximately 1 million MT per annum of ultra-low carbon methanol from its Pacifico Mexinol project, a 6,130 MT per day methanol production facility near Topolobampo, Sinaloa, Mexico, expected to be in operation in 2029. Transition Industries is jointly developing Pacifico Mexinol with the International Finance Corpora

Kinaxis Announces Normal Course Issuer Bid5.11.2025 23:00:00 CET | Press release

Kinaxis® Inc. (“Kinaxis” or the “Company”) (TSX: KXS) is pleased to announce that the Toronto Stock Exchange (the “TSX”) has accepted a notice (the “Notice”) filed by the Company of its intention to make a normal course issuer bid (the “NCIB”). In connection with the NCIB, the Company has entered into an automatic share purchase plan (an “ASPP”) with its designated broker to allow for purchases of its common shares (the “Shares”). The Notice provides that the Company may, during the 12-month period commencing November 12, 2025 and ending November 11, 2026, or on such earlier date as Kinaxis completes its purchases or provides notice of termination, purchase up to 1,403,042 Shares in total, representing approximately 5% of the issued and outstanding Shares as at October 31, 2025. As of the close of business on October 31, 2025, the Company had 28,060,844 Shares issued and outstanding. Except for block purchases permitted under the rules of the TSX, the number of Shares to be purchased p

Hyper® Wins Dual CES 2026 Innovation Awards® for its Breakthrough Tech Accessories5.11.2025 22:45:00 CET | Press release

Hyper’s HyperSpace™ Trackpad Pro and HyperDrive® Next USB4 M.2 PCIe Enclosure named as CES Innovation Awards® 2026 Honorees Hyper®, a leader in mobile tech accessories for creators and power users, today announced it has been honored with two CES2026 Innovation Awards® in the Consumer Peripherals and Accessories category. These awards reflect Hyper’s mission to build breakthrough solutions that help users create, connect, and go beyond the limits of their devices. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251105297377/en/ CES Innovation Awards® 2026 Honorees: HyperSpace™ Trackpad Pro and HyperDrive® Next redefine haptics, personalization, and next-gen USB4 V2 speed. The CES Innovation Awards program is an annual competition that honors the most innovative, new products in consumer technology, recognizing top innovations across multiple categories. “For 20 years, Hyper has led the tech accessory space with industry-defin

CWAN Reports 800+ AI Agents Now Available for Deployment Across $10 Trillion in Client Assets5.11.2025 22:15:00 CET | Press release

Global institutions deploy CWAN GenAI agents that can scale to millions of daily tasks across reconciliation, reporting, and portfolio management Clearwater Analytics (NYSE: CWAN), the most comprehensive technology platform for investment management, today announced the global deployment of CWAN GenAI, a newly-launched, embedded generative AI platform that can be deployed to transform investment management, risk management, reporting and operations across more than $10 trillion in institutional assets. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251105092732/en/ What sets CWAN GenAI apart from the experimental AI tools flooding the market is its production-ready integration. Unlike copilots or chat tools layered onto legacy systems, CWAN GenAI is fully integrated and deployed into production on CWAN’s front-to-back platform, enabling clients to work alongside AI as collaborative partners in their investment operations. Th

IonQ and Swiss Consortium Launch First Citywide Dedicated Quantum Network in Geneva5.11.2025 22:04:00 CET | Press release

Landmark public-private initiative includes CERN, Rolex SA, Swiss government and academic institutionsDelivers world-class quantum infrastructure to support research, collaboration, and quantum tech awareness IonQ (NYSE: IONQ), the world’s leading quantum company, with luminary Swiss partners, successfully deployed a citywide quantum network in Geneva, Switzerland. This consortium of world-class academic, enterprise, and public institutions will advance quantum cybersecurity and communications research, collaboration, and innovation. The new infrastructure, named the Geneva Quantum Network (GQN), is the nation’s first dedicated quantum network connecting key institutions across the region. “Our involvement in the GQN alongside globally-renowned companies such as Rolex and research leaders like CERN, underscores our IP and pioneering leadership in quantum cybersecurity and communication,” said Niccolo de Masi, Chairman and CEO of IonQ. “IonQ is leveraging existing fiber optic infrastruc

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye