Anti-automation
V2.4.1
Verify that anti-automation controls are in place to protect against excessive calls to application functions that could lead to data exfiltration, garbage-data creation, quota exhaustion, rate-limit breaches, denial-of-service, or overuse of costly resources.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 125, 130, 2, 212, 215, 227, 469
V2.4.2
Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.
Required for Level 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 125, 2, 212, 227, 26, 469
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.