Silver Tail Blog

Fighting against business logic abuse.

First White Paper on Business Logic Abuse

paper-and-penThe next big thing in website attacks is business logic abuse. This is the use of legitimate business logic (including sound business logic and business logic flaws) to commit online fraud. It’s getting a lot of recognition, from Wikipedia articles (as highlighted in a recent post) to Black Hat presentations like the one from Jeremiah Grossman at Black Hat 2008.

Silver Tail has released the first white paper defining business logic abuse – including methods for detecting, investigating and stopping malicious behavior (including hijack threats, velocity attacks and gaming schemes) as they occur.

Online fraud is on the rise and no one predicts it will decline. The number of fraudsters is increasing and the attacks are evolving from theft through hacking into more sophisticated attacks targeting the business logic of the website itself.

Given that business logic exploits can be live for weeks or months, it is no wonder bad actors are constantly finding new ways to exploit websites. Combine this with the significant income from online fraud and the lack of fear of law enforcement and one can see why this problem is on the rise. The return on investment (ROI) for bad guys is just too compelling! What websites need is a potent response: namely, the same automation and ability to innovate as the bad guys.

Silver Tail has published the first white paper on business logic abuse.  The paper defines business logic abuse and the significant impacts it can have on an organization.  Definitely comment here or contact us privately with any feedback you have relating to the paper.  It would be great to hear your thoughts!

January 22, 2009 - Posted by Sherrick Murdoff | Business Logic Flaw, Detection, General, Investigation, Online Fraud, Prevention, business logic abuse | , , | No Comments Yet

No comments yet.

Leave a comment