This is the continuation of part I. If you havent read it, we suggest you start there for more attack types and fraud mitigation techniques.
Now, where were we? Right, we just talked about spotting human-driven attacks. Lets look at how to spot probing attacks that sneak in, to learn from your security parameters.
Some of the most potentially damaging attacks we see on the NuData network start extremely small. By probing your defenses with a hard-to-detect, low-volume attack, a cybercriminal can ferret out your vulnerabilities without setting off any alarms. Then they use that knowledge to launch a larger attack tailored to your systems specific weaknesses, hoping to overwhelm your defenses completely.
To prevent that from happening, early detection of probing is key. Think of those initial attacks as the first phase of a pest infestation. You might not notice or be bothered by the first ant scout who appears on a solo mission to find food in your kitchen. But you will definitely notice when theres a several-feet-long trail of ants to the leaky pot of jam in your cupboard a day later. Intercepting that first ant takes extra work, but it saves you a lot of trouble in the long run.
We recently mitigated a large multi-stage attack on a retail company in our network, in part by detecting the attackers initial probing. During this phase, which lasted one or two days, the attack was relatively small, just a small bump on a graph (youll see below). The attackers deployed human-like scripts that included realistic mouse movements and pauses between keystrokes to imitate human behavior. On an individual level, the probing attacks looked like legitimate traffic.
This was enough to fool the retailers bot-manager tool, which relied on comparing current data to known threats, such as IP addresses used in past attacks. However, NuData was able to detect the attack by looking at underlying patterns, such as anomalous behavior during the online interaction or an unusual number of login attempts within the same networks and IP addresses. After identifying the pattern, NuData blocked 99.8% of fraudulent login attempts, shutting down the first phase of the attack. (Unfortunately, there was more to come the attack kept evolving, as youll see below.)
Attacks that begin with probing rarely stop there. The most sophisticated attacks we see in our network evolve quickly as they search for ways around their targets defenses. Such attacks can change strategies in as little as a day, so companies need to keep their threat models agile and adapt swiftly.
The attack on the retail company we talked about earlier turned out to be an example of an evolving threat. After two days of probing, which NuData successfully mitigated, the attackers changed their strategy, refining their script to better mimic human behavior for example, by creating a more natural rhythm of keystrokes. They also increased their attack volume, using an eye-popping 18,500 different IP addresses and ensured attack velocity remained low.
Ironically, doubling down on attacks makes NuDatas defenses stronger. The more a bad actor interacts with our clients platform, , the more our solution learns. In this second phase of the assault on the retail company, NuData blocked 100% of attacks an even higher success rate than wed had during the initial probing.
We maintained this same mitigation rate even as the attack evolved into its third and final phase, with attackers doubling the number of IP addresses used in an attempt to evade detection. Despite the reduced velocity and fewer events per IP, NuData still identified patterns that revealed the attack, such as users holding their devices in ways that showed they werent human. All told, NuData blocked two million fraudulent logins in the last 48 hours of the attack ending the cybercriminals attempt once and for all.
Fraudulent traffic (red) vs. legitimate traffic (green) over the course of a six-day evolving attack on a retail company
Sophisticated attacks arent just growing more common theyre also growing more creative. And its impossible to predict how theyll continue to evolve. Cybercriminals are always dreaming up new ways to evade detection, and many standard bot-manager tools arent able to keep up, as we have seen in this article.
Ever-evolving attack strategies demand new, more agile defenses. By adopting multiple layers of security protection that can adapt alongside the threats you face, youll position your company to weather whatever challenges come its way.
More recent threat trends in our bi-annual report, Fraud Risk at a Glance.
The post Mitigating sophisticated attacks the NuData way (part II) appeared first on NuData Security.
*** This is a Security Bloggers Network syndicated blog from NuData Security authored by Tiffany Mark. Read the original post at: https://nudatasecurity.com/resources/blog/mitigating-sophisticated-attacks-the-nudata-way-part-ii/
View original post here:
Mitigating sophisticated attacks the NuData way (part II) - Security Boulevard
- How Smart Cities Are Redesigning Human Behavior - Lakeland Connect - June 10th, 2025 [June 10th, 2025]
- HUMAN TRAFFICKING | 'That was normal behavior': Victim recalls being 'sold' by her mother, then the aftermath of abuse - The Tribune-Democrat - June 10th, 2025 [June 10th, 2025]
- Tech company unveils eerie new way to map human behavior: 'We're tokenizing the invisible ones' - The Cool Down - June 1st, 2025 [June 1st, 2025]
- Simulating Human Behavior with AI Agents - Stanford HAI - May 21st, 2025 [May 21st, 2025]
- 'Human behavior is the basis of the energy transition' - ioplus.nl - May 21st, 2025 [May 21st, 2025]
- Driverless taxi ride surprises with human-like behavior - Alton Telegraph - May 21st, 2025 [May 21st, 2025]
- VeChains Bold Vision to Tokenize Human Behavior - 99Bitcoins - May 21st, 2025 [May 21st, 2025]
- Study links most alligator attacks to risky human behavior - Gulf Coast News and Weather - Southwest Florida News - April 27th, 2025 [April 27th, 2025]
- UF study finds risky human behavior is the cause for most alligator bites - The Palm Beach Post - April 19th, 2025 [April 19th, 2025]
- Study Finds 96% of Gator Bites Are the Result of Risky Human Behavior - Gizmodo - April 19th, 2025 [April 19th, 2025]
- A Growing Pathway to Understanding Human Behavior - University of Northern Colorado - April 19th, 2025 [April 19th, 2025]
- The Rehearsal S2: Nathan Fielder Explores Human Behavior - Hollywood.com - April 19th, 2025 [April 19th, 2025]
- A Bad Rap: Most alligator bites are caused by risky human behavior, UF researchers say - WCJB TV20 - April 19th, 2025 [April 19th, 2025]
- AI humanoid robot learns to mimic human emotions and behavior - Fox News - April 19th, 2025 [April 19th, 2025]
- INTERVIEW: Dying for Sex Director Shannon Murphy on Portraying Authentic Human Behavior by Blending Comedy & Drama - The Knockturnal - April 10th, 2025 [April 10th, 2025]
- 7 Must-Read Psychology Books That Will Help You Decode Human Behavior - Times Now - April 10th, 2025 [April 10th, 2025]
- Vet shares warning against common human behavior that gives dogs anxiety - The Mirror US - March 30th, 2025 [March 30th, 2025]
- BBVA Foundation awards the psychologists who changed the way we understand and predict human behavior - WebWire - March 15th, 2025 [March 15th, 2025]
- Human behavior is driven by fifteen key motives - Earth.com - February 25th, 2025 [February 25th, 2025]
- Nature Human Behavior is back, this time touting allyship - Why Evolution Is True - February 25th, 2025 [February 25th, 2025]
- 30 Times Courtrooms Became The Stage For The Strangest Human Behavior - Bored Panda - February 3rd, 2025 [February 3rd, 2025]
- The Impact of AI on Human Behavior: Insights and Implications - iTMunch - January 23rd, 2025 [January 23rd, 2025]
- Disturbing Wildlife Isnt Fun: IFS Parveen Kaswan Raises Concern Over Human Behavior in Viral Clip - Indian Masterminds - January 15th, 2025 [January 15th, 2025]
- The interplay of time and space in human behavior: a sociological perspective on the TSCH model - Nature.com - January 1st, 2025 [January 1st, 2025]
- Thinking Slowly: The Paradoxical Slowness of Human Behavior - Caltech - December 23rd, 2024 [December 23rd, 2024]
- From smog to crime: How air pollution is shaping human behavior and public safety - The Times of India - December 9th, 2024 [December 9th, 2024]
- The Smell Of Death Has A Strange Influence On Human Behavior - IFLScience - October 26th, 2024 [October 26th, 2024]
- "WEIRD" in psychology literature oversimplifies the global diversity of human behavior. - Psychology Today - October 2nd, 2024 [October 2nd, 2024]
- Scientists issue warning about increasingly alarming whale behavior due to human activity - Orcasonian - September 23rd, 2024 [September 23rd, 2024]
- Does AI adoption call for a change in human behavior? - Fast Company - July 26th, 2024 [July 26th, 2024]
- Dogs can smell human stress and it alters their own behavior, study reveals - New York Post - July 26th, 2024 [July 26th, 2024]
- Trajectories of brain and behaviour development in the womb, at birth and through infancy - Nature.com - June 18th, 2024 [June 18th, 2024]
- AI model predicts human behavior from our poor decision-making - Big Think - June 18th, 2024 [June 18th, 2024]
- ZkSync defends Sybil measures as Binance offers own ZK token airdrop - TradingView - June 18th, 2024 [June 18th, 2024]
- On TikTok, Goldendoodles Are People Trapped in Dog Bodies - The New York Times - June 18th, 2024 [June 18th, 2024]
- 10 things only introverts find irritating, according to psychology - Hack Spirit - June 18th, 2024 [June 18th, 2024]
- 32 animals that act weirdly human sometimes - Livescience.com - May 24th, 2024 [May 24th, 2024]
- NBC Is Using Animals To Push The LGBT Agenda. Here Are 5 Abhorrent Animal Behaviors Humans Shouldn't Emulate - The Daily Wire - May 24th, 2024 [May 24th, 2024]
- New study examines the dynamics of adaptive autonomy in human volition and behavior - PsyPost - May 24th, 2024 [May 24th, 2024]
- 30000 years of history reveals that hard times boost human societies' resilience - Livescience.com - May 12th, 2024 [May 12th, 2024]
- Kingdom of the Planet of the Apes Actors Had Trouble Reverting Back to Human - CBR - May 12th, 2024 [May 12th, 2024]
- The need to feel safe is a core driver of human behavior. - Psychology Today - April 15th, 2024 [April 15th, 2024]
- AI learned how to sway humans by watching a cooperative cooking game - Science News Magazine - March 29th, 2024 [March 29th, 2024]
- We can't combat climate change without changing minds. This psychology class explores how. - Northeastern University - March 11th, 2024 [March 11th, 2024]
- Bees Reveal a Human-Like Collective Intelligence We Never Knew Existed - ScienceAlert - March 11th, 2024 [March 11th, 2024]
- Franciscan AI expert warns of technology becoming a 'pseudo-religion' - Detroit Catholic - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - messenger-inquirer - March 11th, 2024 [March 11th, 2024]
- Astrocytes Play Critical Role in Regulating Behavior - Neuroscience News - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - Sunnyside Sun - March 11th, 2024 [March 11th, 2024]
- Freshwater resources at risk thanks to human behavior - Blue Mountain Eagle - March 11th, 2024 [March 11th, 2024]
- 7 Books on Human Behavior - Times Now - March 11th, 2024 [March 11th, 2024]
- Euphemisms increasingly used to soften behavior that would be questionable in direct language - Norfolk Daily News - February 29th, 2024 [February 29th, 2024]
- Linking environmental influences, genetic research to address concerns of genetic determinism of human behavior - Phys.org - February 29th, 2024 [February 29th, 2024]
- Emerson's Insight: Navigating the Three Fundamental Desires of Human Nature - The Good Men Project - February 29th, 2024 [February 29th, 2024]
- Dogs can recognize a bad person and there's science to prove it. - GOOD - February 29th, 2024 [February 29th, 2024]
- What Is Organizational Behavior? Everything You Need To Know - MarketWatch - February 4th, 2024 [February 4th, 2024]
- Overcoming 'Otherness' in Scientific Research Commentary in Nature Human Behavior USA - English - USA - PR Newswire - February 4th, 2024 [February 4th, 2024]
- "Reichman University's behavioral economics program: Navigating human be - The Jerusalem Post - January 19th, 2024 [January 19th, 2024]
- Of trees, symbols of humankind, on Tu BShevat - The Jewish Star - January 19th, 2024 [January 19th, 2024]
- Tapping Into The Power Of Positive Psychology With Acclaimed Expert Niyc Pidgeon - GirlTalkHQ - January 19th, 2024 [January 19th, 2024]
- Don't just make resolutions, 'be the architect of your future self,' says Stanford-trained human behavior expert - CNBC - December 31st, 2023 [December 31st, 2023]
- Never happy? Humans tend to imagine how life could be better : Short Wave - NPR - December 31st, 2023 [December 31st, 2023]
- People who feel unhappy but hide it well usually exhibit these 9 behaviors - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- If you display these 9 behaviors, you're being passive aggressive without realizing it - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- Men who are relationship-oriented by nature usually display these 9 behaviors - Hack Spirit - December 31st, 2023 [December 31st, 2023]
- A look at the curious 'winter break' behavior of ChatGPT-4 - ReadWrite - December 14th, 2023 [December 14th, 2023]
- Neuroscience and Behavior Major (B.S.) | College of Liberal Arts - UNH's College of Liberal Arts - December 14th, 2023 [December 14th, 2023]
- The positive health effects of prosocial behaviors | News | Harvard ... - HSPH News - October 27th, 2023 [October 27th, 2023]
- The valuable link between succession planning and skills - Human Resource Executive - October 27th, 2023 [October 27th, 2023]
- Okinawa's ants show reduced seasonal behavior in areas with more human development - Phys.org - October 27th, 2023 [October 27th, 2023]
- How humans use their sense of smell to find their way | Penn Today - Penn Today - October 27th, 2023 [October 27th, 2023]
- Wrestling With Evil in the World, or Is It Something Else? - Psychiatric Times - October 27th, 2023 [October 27th, 2023]
- Shimmying like electric fish is a universal movement across species - Earth.com - October 27th, 2023 [October 27th, 2023]
- Why do dogs get the zoomies? - Care.com - October 27th, 2023 [October 27th, 2023]
- How Stuart Robinson's misconduct went overlooked for years - Washington Square News - October 27th, 2023 [October 27th, 2023]
- Whatchamacolumn: Homeless camps back in the news - News-Register - October 27th, 2023 [October 27th, 2023]
- Stunted Growth in Infants Reshapes Brain Function and Cognitive ... - Neuroscience News - October 27th, 2023 [October 27th, 2023]
- Social medias role in modeling human behavior, societies - kuwaittimes - October 27th, 2023 [October 27th, 2023]
- The gift of reformation - Living Lutheran - October 27th, 2023 [October 27th, 2023]
- After pandemic, birds are surprisingly becoming less fearful of humans - Study Finds - October 27th, 2023 [October 27th, 2023]