Automated Threats (BOT9)

Automated Threats
9

CSIRAC can alter a metric by using repeated link clicks, page requests or form submissions

How to play?

This card is about altering some metric through automated use at scale, known as skewing.

Scenario: CSIRAC's number-bumper scenario

Example

CSIRAC helps influencers by automating the bumping-up of follows, likes and re-posts. This boosts the influencers' exposure and in turn increases the number of real people who are followers. These contribute to greater income for the influencer through platform advertising commission payments and product promotion offers. All of this is undertaken by automating the use of existing functionality - no implementation bugs are needed for the exploitation.

Threat Modeling

STRIDE

This scenario falls into the Tampering category of STRIDE. CSIRAC alters social media metrics of the influencers' accounts.

What can go wrong?

Side-effects of altering social media metrics can be altered reputation, viewpoint amplification, incite violence, increased sharing of illegal or dubious content, and the ability to influence others more. Skewing metrics may also affect other users such as undermining someone's reputation or leading them to scams, and skewing can impact content providers, and the application owners.

For further explanation, examples, possible symptoms, and other closely-related automation threats which target inherent intended functionality and related design flaws, rather than implementation bugs, see the OWASP Automated Threat (OAT) identifiers in the mapping section, and the reference OWASP Automated Threat Handbook.

What are we going to do about it?

  • Monitor impression/click to outcome ratios, significant changes to relevant metrics, compare metrics across applications/sectors, and track changes to related costs/awards.
  • Consider requiring identification, re-authentication or some other increased authentication assurance for relevant functionality.
  • Identify and block bots being used to access relevant functionality.
  • Detect anomalous automated behaviour and respond to detected attacks in real-time.

For detailed advice on relevant countermeasures, see further documentation in the OWASP Automated Threat Handbook.

Mappings

STRIDE: T

OWASP ASVS: 2.3.2

OWASP OAT: OAT-016

CWE: 799,837

CAPEC: 210

Attacks

No attacks registered!

OWASP Cornucopia

OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use. OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 4.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.

Ā© 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.