9 Recommendations to Prevent Bad Bots on Your Website | Imperva (2024)

9 Recommendations to Prevent Bad Bots on Your Website | Imperva (1)

May 21, 2019 2 min read

Bots are on your website every day so how should you protect yourself? Every site is targeted for different reasons, and usually by different methods, so there is no one-size-fits-all bot defense solution. But there are some proactive steps you can take to start addressing the problem.

The 2022 Imperva Bad Bot Report: Evasive Bots Drive Online Fraud is now available for download. Get the report today.

Here are nine recommendations to help stop bot attacks.

1. Block or CAPTCHA outdated user agents/browsers

The default configurations for many tools and scripts contain user-agent string lists that are largely outdated. This step won’t stop the more advanced attackers, but it might catch and discourage some. The risk in blocking outdated user agents/browsers is very low; most modern browsers force auto-updates on users, making it more difficult to surf the web using an outdated version.

We recommend you block or CAPTCHA the following browser versions:

9 Recommendations to Prevent Bad Bots on Your Website | Imperva (3)

2. Block known hosting providers and proxy services

Even if the most advanced attackers move to other, more difficult-to-block networks, many less sophisticated perpetrators use easily accessible hosting and proxy services. Disallowing access from these sources might discourage attackers from coming after your site, API, and mobile apps.

Block these data centers:

9 Recommendations to Prevent Bad Bots on Your Website | Imperva (4)

CAPTCHA these data centers:

9 Recommendations to Prevent Bad Bots on Your Website | Imperva (5)

3. Protect every bad bot access point

Be sure to protect exposed APIs and mobile apps—not just your website—and share blocking information between systems wherever possible. Protecting your website does little good if backdoor paths remain open.

4. Carefully evaluate traffic sources

Monitor traffic sources carefully. Do any have high bounce rates? Do you see lower conversion rates from certain traffic sources? These can be signs of bot traffic.

5. Investigate traffic spikes

Traffic spikes appear to be a great win for your business. But can you find a clear, specific source for the spike? One that is unexplained can be a sign of bad bot activity.

6. Monitor for failed login attempts

Define your failed login attempt baseline, then monitor for anomalies or spikes. Set up alerts so you’re automatically notified if any occur. Advanced “low and slow” attacks don’t trigger user or session-level alerts, so be sure to set global thresholds.

7. Monitor increases in failed validation of gift card numbers

An increase in failures, or even traffic, to gift card validation pages can be a signal that bots such as GiftGhostBot are attempting to steal gift card balances.

8. Pay close attention to public data breaches

Newly stolen credentials are more likely to still be active. When large breaches occur anywhere, expect bad bots to run those credentials against your site with increased frequency.

9. Evaluate a Bot Mitigation solution

The bot problem is an arms race. Bad actors are working hard every day to attack websites across the globe. As the sheer volume, sophistication, and business damage caused by automated threats grows, bots put a costly strain on IT staff and resources. These days, bots mimic human behavior and slip by traditional security tools. Consider evaluating bot mitigation vendors that have the industry expertise and vigilant support you’ll need for full visibility and control over abusive traffic.

Try Imperva for Free

Protect your business for 30 days on Imperva.

Start Now

Try Imperva for Free

Protect your business for 30 days on Imperva.

Start Now

9 Recommendations to Prevent Bad Bots on Your Website | Imperva (2024)
Top Articles
How Much Yarn Do You Need for Arm Knitting Projects?
What is Net Profit Margin? | Definition
80 For Brady Showtimes Near Marcus Point Cinema
Limp Home Mode Maximum Derate
Byrn Funeral Home Mayfield Kentucky Obituaries
CA Kapil 🇦🇪 Talreja Dubai on LinkedIn: #businessethics #audit #pwc #evergrande #talrejaandtalreja #businesssetup…
41 annonces BMW Z3 occasion - ParuVendu.fr
Slay The Spire Red Mask
Savage X Fenty Wiki
Uvalde Topic
Craigslist Pets Sac
Tracking Your Shipments with Maher Terminal
Ts Lillydoll
Rhinotimes
Mills and Main Street Tour
Craigslist Malone New York
Scenes from Paradise: Where to Visit Filming Locations Around the World - Paradise
Eva Mastromatteo Erie Pa
Lazarillo De Tormes Summary and Study Guide | SuperSummary
St Maries Idaho Craigslist
Kamzz Llc
UPS Store #5038, The
PowerXL Smokeless Grill- Elektrische Grill - Rookloos & geurloos grillplezier - met... | bol
Phoebus uses last-second touchdown to stun Salem for Class 4 football title
Panola County Busted Newspaper
Fleet Farm Brainerd Mn Hours
D2L Brightspace Clc
Divina Rapsing
Dashboard Unt
Speedstepper
Tamil Movies - Ogomovies
Alternatieven - Acteamo - WebCatalog
Jeep Cherokee For Sale By Owner Craigslist
Average weekly earnings in Great Britain
O'reilly Auto Parts Ozark Distribution Center Stockton Photos
آدرس جدید بند موویز
Does Iherb Accept Ebt
Afspraak inzien
Ramsey County Recordease
Lima Crime Stoppers
Discover Things To Do In Lubbock
Sound Of Freedom Showtimes Near Lewisburg Cinema 8
The Wait Odotus 2021 Watch Online Free
Chr Pop Pulse
Pickwick Electric Power Outage
Ups Customer Center Locations
Motorcycles for Sale on Craigslist: The Ultimate Guide - First Republic Craigslist
Msatlantathickdream
Https://Eaxcis.allstate.com
Latest Posts
Article information

Author: Merrill Bechtelar CPA

Last Updated:

Views: 5765

Rating: 5 / 5 (50 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Merrill Bechtelar CPA

Birthday: 1996-05-19

Address: Apt. 114 873 White Lodge, Libbyfurt, CA 93006

Phone: +5983010455207

Job: Legacy Representative

Hobby: Blacksmithing, Urban exploration, Sudoku, Slacklining, Creative writing, Community, Letterboxing

Introduction: My name is Merrill Bechtelar CPA, I am a clean, agreeable, glorious, magnificent, witty, enchanting, comfortable person who loves writing and wants to share my knowledge and understanding with you.