Automated Threats (BOTA)

Automated Threats
A

You have identified an automated attack that misuses inherent web application functionality or a related design flaw

How to play?

Players can discuss any mis-use of valid functionality that can be automated and occurs at scale. Try to avoid simplistic denial of service threat events, because often the intent of an automated threat is something else, with denial of service an unintended side-effect. The key question is how can the application's functionality be used to an attacker's benefit through repeated use at machine speed?

Scenario: Invent your own automated threat scenario

You have identified an attack that misuses inherent functionality. Consider how an attacker might make money, utilise resources or gain goods or services in unfair or even criminal ways.

Threat Modeling

STRIDE

The appropriate STRIDE category depends on the specific threat you create and the way existing valid functionality is misused.

What can go wrong?

Automated threats are very diverse and can negatively affect application owners, service providers and other third parties, real application users, and even wider society.

What are we going to do about it?

For detailed advice on ideas for relevant countermeasures, see further documentation in the OWASP Automated Threat Handbook.

Mappings

ASVS (5.0): -

STRIDE: -

OWASP OAT: -

CWEā„¢: -

CAPECā„¢: -

No attacks registered!

OWASP Cornucopia

OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use. OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 4.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.

Ā© 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.