Automated Threats (BOTA)
You have identified an automated attack that misuses inherent web application functionality or a related design flaw
Players can discuss any mis-use of valid functionality that can be automated and occurs at scale. Try to avoid simplistic denial of service threat events, because often the intent of an automated threat is something else, with denial of service an unintended side-effect. The key question is how can the application's functionality be used to an attacker's benefit through repeated use at machine speed?
Scenario: Invent your own automated threat scenario
You have identified an attack that misuses inherent functionality. Consider how an attacker might make money, utilise resources or gain goods or services in unfair or even criminal ways.
Threat Modeling
STRIDE
The appropriate STRIDE category depends on the specific threat you create and the way existing valid functionality is misused.
What can go wrong?
Automated threats are very diverse and can negatively affect application owners, service providers and other third parties, real application users, and even wider society.
What are we going to do about it?
For detailed advice on ideas for relevant countermeasures, see further documentation in the OWASP Automated Threat Handbook.
Mappings
ASVS (5.0): -
STRIDE: -
OWASP OAT: -
CWEā¢: -
CAPECā¢: -
No attacks registered!