2025³â 05¿ù 23ÀÏ ±Ý¿äÀÏ
 
 
  ÇöÀçÀ§Ä¡ > ´º½ºÁö´åÄÄ > Science & Technology

·£¼¶¿þ¾îºÎÅÍ µÅÁöµµ»ì±îÁö... ³ë·ÃÇØÁø »ç±âÇà°¢

 

Á¤Ä¡

 

°æÁ¦

 

»çȸ

 

»ýȰ

 

¹®È­

 

±¹Á¦

 

°úÇбâ¼ú

 

¿¬¿¹

 

½ºÆ÷Ã÷

 

ÀÚµ¿Â÷

 

ºÎµ¿»ê

 

°æ¿µ

 

¿µ¾÷

 

¹Ìµð¾î

 

½Å»óǰ

 

±³À°

 

ÇÐȸ

 

½Å°£

 

°øÁö»çÇ×

 

Ä®·³

 

Ä·ÆäÀÎ
Çѻ츲 ¡®¿ì¸®´Â ÇѽҸ²¡¯ ½Ò ¼Òºñ Ä·ÆäÀÎ ½Ã...
1000¸¸¿øÂ¥¸® Àΰø¿Í¿ì, °Ç°­º¸Çè Áö¿ø ¡®Æò...
- - - - - - -
 

AI advances drive the surge of elusive bots, now accounting for over half of global web traffic, as revealed in the 2025 Imperva Bad Bot Report

Rise in accessible AI tools significantly lowered the barrier to entry for cyber attackers, enabling them to create and deploy malicious bots at scale
´º½ºÀÏÀÚ: 2025-05-23

MEUDON, FRANCE -- Thales, the leading global technology and security provider, announced the release of the 2025 Imperva Bad Bot Report, a global analysis of automated bot traffic across the internet. This year’s report, the 12th annual research study, reveals that generative artificial intelligence (AI) is revolutionizing the development of bots, allowing less sophisticated actors to launch a higher volume of bot attacks with increased frequency. Today’s attackers are also leveraging AI to scrutinize their unsuccessful attempts and refine techniques to evade security measures with heightened efficiency, amidst a growing Bots-As-A-Service (BaaS) ecosystem of commercialized bot services.

Automated bot traffic surpassed human-generated traffic for the first time in a decade, constituting 51% of all web traffic in 2024. This shift is largely attributed to the rise of AI and Large Language Models (LLMs), which have simplified the creation and scaling of bots for malicious purposes. As AI tools become more accessible, cyber criminals are increasingly leveraging these technologies to create and deploy malicious bots which now account for 37% of all internet traffic - a significant increase from 32% in 2023. This is the sixth consecutive year of growth in bad bot activity, posing security challenges for organizations striving to safeguard their digital assets.

Both the Travel and the Retail sectors face an advanced bot problem, with bad bots making up 41% and 59% of their traffic respectively. In 2024, the travel industry became the most attacked sector, accounting for 27% of all bot attacks, up from 21% in 2023. The most notable shift in 2024 is the decline in advanced bot attacks targeting the travel industry (41%, down from 61% in 2023) and the sharp increase in simple bot attacks (52%, up from 34%). This shift indicates that AI-powered automation tools have lowered the barriers to entry for attackers, allowing less sophisticated actors to initiate more basic bot attacks. Rather than relying exclusively on sophisticated techniques, cybercriminals are increasingly utilizing high volumes of simpler bots to inundate travel sites, resulting in more frequent and widespread attacks.

The Rise of AI-Driven Bots: A New Era of Cybersecurity Challenges


The emergence of advanced AI tools, including ChatGPT, ByteSpider Bot, ClaudeBot, Google Gemini, Perplexity AI, and Cohere AI, are transforming not just user interactions but also the methods by which attackers execute cyber threats. According to the Imperva Threat Research team, widely used AI tools are being leveraged for cyberattacks, with ByteSpider Bot alone responsible for 54% of all AI-enabled attacks. Other significant contributors include AppleBot at 26%, ClaudeBot at 13%, and ChatGPT User Bot at 6%.

“The surge in AI-driven bot creation has serious implications for businesses worldwide,” said Tim Chang, General Manager of Application Security at Thales. “As automated traffic accounts for more than half of all web activity, organizations face heightened risks from bad bots, which are becoming more prolific every day.”

As attackers become more adept at utilizing AI, they can execute a variety of cyber threats—ranging from DDoS attacks to custom rules exploitation and API violations. While bot-driven attacks have become increasingly sophisticated, they pose significant challenges for detection efforts.

“This year’s report sheds light on the evolving tactics and techniques utilized by bot attackers. What were once deemed advanced evasion methods have now become standard practice for many malicious bots,” Chang said. “In this rapidly changing environment, businesses must evolve their strategies. It’s crucial to adopt an adaptive and proactive approach, leveraging sophisticated bot detection tools and comprehensive cybersecurity management solutions to build a resilient defense against the ever-shifting landscape of bot-related threats.”

Bad Bots Targeting API Business Logic Pose Increased Threat to Modern Enterprises

Recent findings from the Imperva Threat Research team reveal a significant surge in API-directed attacks, with 44% of advanced bot traffic targeting APIs. These attacks aren’t just limited to overwhelming API endpoints; rather, they target the intricate business logic that defines how APIs operate. Attackers deploy bots specifically designed to exploit vulnerabilities in API workflows, engaging in automated payment fraud, account hijacking, and data exfiltration.

Analysis in the report reveals a deliberate strategy by cyber attackers to exploit API endpoints that manage sensitive and high-value data. Implications of this trend are especially impactful for industries that rely on APIs for their critical operations and transactions. Financial services, healthcare, and e-commerce sectors are bearing the brunt of these sophisticated bot attacks, making them prime targets for malicious actors seeking to breach sensitive information.

APIs serve as the backbone of modern applications, enabling connectivity across services, streamlining operations, and delivering personalized customer experiences at scale. They underpin essential functions such as payment processing, supply chain management, and AI-driven analytics, making them indispensable for enhancing efficiency, accelerating product development, and unlocking new revenue streams.

“The business logic inherent to APIs is powerful, but it also creates unique vulnerabilities that malicious actors are eager to exploit,” Chang said. “As organizations embrace cloud-based services and microservices architectures, it’s vital to understand that the very features that make APIs essential can also leave them susceptible to risk of fraud and data breaches.”

Financial Services, Healthcare, and E-commerce Industries Face Heightened Risk

The 2025 Imperva Bad Bot Report provides an in-depth analysis highlighting the industries most at risk. Financial services, healthcare, and e-commerce are the most affected sectors, industries that rely on APIs for critical operations and sensitive transactions, making them attractive targets for sophisticated bot attacks.

The financial services sector was the most targeted industry for account takeover (ATO) attacks, accounting for 22% of all incidents, followed by Telecoms and ISPs with 18%, and Computing & IT with 17%. Financial Services has long been a prime target for ATO attacks due to the high value of accounts and the sensitive nature of the data at stake. Banks, credit card companies, and fintech platforms possess vast amounts of Personally Identifiable Information (PII), including credit card and bank account details, which can be profitably sold on the dark web. Additionally, the growing proliferation of APIs within the industry has broadened the attack surface, allowing cyber criminals to exploit vulnerabilities such as weak authentication and authorization methods, thereby facilitating account takeovers and data theft.



 Àüü´º½º¸ñ·ÏÀ¸·Î

NetApp and Intel Partner to Redefine AI for Enterprises
AI advances drive the surge of elusive bots, now accounting for over half of global web traffic, as revealed in the 2025 Imperva Bad Bot Report
WHOOP Unveils WHOOP¢ç 5.0 and WHOOP¢ç MG: Powerful New Devices with Breakthrough Health and Longevity Features
Boomi and AWS Announce Strategic Collaboration to Transform Enterprise AI Integration, Automation, and SAP Cloud Migration
Novotech Analysis Highlights Rising Clinical Development Efforts for Obesity Treatments
GIGABYTE at COMPUTEX 2025: Accelerating the AI Future With Total Infrastructure and Computing Solutions
CSG and NetLync Drive MNO and MVNO eSIM Transformation

 

Quectel, Giesecke+Devrient and Vodafone IoT collaborate to drive iSIM ...
VirTus Respiratory Research¡¯s Rhinovirus Model Results Propel Altesa ...
NetApp Builds AI Infrastructure on NVIDIA AI Data Platform
Data Infrastructure Company Terminal 3 Raises US$8M Seed Round to Scal...
Codethink Limited Announces World¡¯s First Baseline Safety Assessment ...
TriLink BioTechnologies¢ç and the International Vaccine Institute sign...
GSK acquires efimosfermin, a Phase III-ready FGF21 analog, to treat an...

 


°øÁö»çÇ×
¹Ìµð¾î¾Æ¿ì¾î Mediaour ØÚ体ä²们 ØÚô÷ä²Ùú MO ¿¥¿À ØÚä² ØÚä²
¾Ë¸®¿ìºê Alliuv ä¹备: ä¹联êó备, ¾Ë¶ã Althle ä¹÷åìÌ
¾Ë¸®¾Ë Allial Áß¹® Ç¥±â ä¹××尔 ä¹××ì³
´ºÆÛ½ºÆ® New1st Áß¹® Ç¥±â 纽ììãæ(¹øÃ¼ Òïììãæ), N1 纽1
¿£ÄÚ½º¸ð½º : À̾¾ 'EnCosmos : EC' Áß¹® Ç¥±â ì¤ñµ
¾ÆÀ̵ð¾î·Ð Idearon Áß¹® Ç¥±â ì¤îè论 ì¤îèÖå
¹ÙÀÌ¿ÀÀÌ´Ï Bioini Áß¹® Ç¥±â ù±药研 ù±å·æÚ
¿À½ºÇÁ·Ò Ausfrom 奥ÞÙÜØÙÌ, À£ÇÁ·Ò Welfrom 卫ÜØÙÌ
¿¡³ÊÇÁ·Ò Enerfrom 额ÒöÜØÙÌ ¿¡³ÊÀ¯ºñ Eneruv 额Òöêó备
º£³×ÇÁ·Ò º£³×ÀÎÅõ Áß¹® Ç¥±â 宝Ò¬ÜØÙÌ 宝Ò¬ì×öõ(ÜÄÒ¬ÜØÙÌ ÜÄ...
¾ËÇÁ·Ò Alfrom Áß¹® Ç¥±â ä¹尔ÜØÙÌ ä¹ì³ÜØÙÌ
´º½ºÁö ÇÑÀÚ Ç¥±â¿¡ ´ë¸¸½Ä À½Â÷ Ç¥±â '纽ÞÙó¢ ´Ï¿ì½ÃÁö' º´±â

 

ȸ»ç¼Ò°³ | ÀÎÀçä¿ë | ÀÌ¿ë¾à°ü | °³ÀÎÁ¤º¸Ãë±Þ¹æÄ§ | û¼Ò³âº¸È£Á¤Ã¥ | Ã¥ÀÓÇѰè¿Í ¹ýÀû°íÁö | À̸ÞÀÏÁÖ¼Ò¹«´Ü¼öÁý°ÅºÎ | °í°´¼¾ÅÍ

±â»çÁ¦º¸ À̸ÞÀÏ news@newsji.com, ÀüÈ­ 050 2222 0002, ÆÑ½º 050 2222 0111, ÁÖ¼Ò : ¼­¿ï ±¸·Î±¸ °¡¸¶»ê·Î 27±æ 60 1-37È£

ÀÎÅͳݴº½º¼­ºñ½º»ç¾÷µî·Ï : ¼­¿ï ÀÚ00447, µî·ÏÀÏÀÚ : 2013.12.23., ´º½º¹è¿­ ¹× û¼Ò³âº¸È£ÀÇ Ã¥ÀÓ : ´ëÇ¥ CEO

Copyright ¨Ï All rights reserved..