Automated Threats (BOTQ)

Automated Threats
Q

Manchester Baby can add malicious or questionable information to content, databases or user messages

How to play?

This card is about mass information addition, commonly referred to as spamming.

Scenario: Manchester Baby's ham-spam scenario

Example

Manchester Baby is a mischievous bot set up to disrupt social media, discussion forums and blogs that refer to "ham". It automatically finds and posts replies with jokey and inappropriate comments to any mention of the word "ham" causing annoyance and sometimes offense.

Threat Modeling

STRIDE

This scenario falls into the Tampering category of STRIDE. Manchester Baby injects content into discussion threads.

What can go wrong?

Additional automated content can be an annoyance, mischievous, disruptive and even malicious. The effects depend both on the purpose of the application and the type of content added, and its frequency.

For further explanation, examples, possible symptoms, and other closely-related automation threats which target inherent intended functionality and related design flaws, rather than implementation bugs, see the OWASP Automated Threat (OAT) identifiers in the mapping section, and the reference OWASP Automated Threat Handbook.

What are we going to do about it?

  • Monitor and track trends for content addition by users.
  • Consider content moderation.
  • Consider requiring identification, re-authentication or some other increased authentication assurance for functionality allowing addition of content.
  • Actively remove spam content and block users.
  • Identify and block bots being used to access relevant functionality.
  • Detect anomalous automated behaviour and respond to detected attacks in real-time.

For detailed advice on relevant countermeasures, see further documentation in the OWASP Automated Threat Handbook.

Mappings

STRIDE: T

OWASP ASVS: 2.3.2

OWASP OAT: OAT-017

CWE: 799,837

CAPEC: 210

Attacks

No attacks registered!

OWASP Cornucopia

OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use. OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 4.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.

Ā© 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.