SlideShare une entreprise Scribd logo
1  sur  47
▪ Introduction
▪ Bots 101
▪ BOTS Act and what it covers (and doesn’t cover)
▪ How bots can impact your major onsales and associated
mitigation strategies
▪ StubHub case study
▪ Q&A
Rami Essaid
CEO & Co-founder,
Distil Networks
Niels Sodemann
CEO & Co-founder,
Queue-it
Distil Networks is the only proactive
and precise bot mitigation solution for
web applications, mobile, and APIs.
▪ Founded in 2011
▪ 180 employees
▪ 5 offices
▪ $65 million in funding
The use of Queue-it has ensured online
fairness during high-demand online events
for more than 1.5 billion consumers
worldwide.
▪ Founded in 2010
▪ 63 employees
▪ 2016 TTA winner of Supplier of the Year
DenmarkSilicon Valley
Awards and Analyst Recognition
The only anti-bot solution to be included
in Gartner’s Online Fraud Detection
Market Guide 2-years running
“Distil’s ability to analyze behavior provides
the best chance of detecting and blocking
bot-driven attacks.”
“Clear innovation compared to
similar services.”
2017 WINNER: Best Fraud Prevention
Solution
Telling the story together
Bots 101
Good bots
▪ Search engine crawling
▪ Power APIs
▪ Check system connectivity & status
A ‘bot’ is an automated program that runs on the internet
Bad bots
▪ Steal content
▪ Scan for vulnerabilities
▪ Perform fraud etc.
Traffic Distribution by Type, 2016
What concerns you most about the impact of bots on your
organization’s website(s)?
▪ Website Security
▪ Transaction Fraud
▪ Lost Revenue to Scalpers
▪ Poor Customer Experience
Survey
How are you addressing your bot concerns?
▪ Addressing now
▪ Plan to address this year
▪ Plan to address next year
▪ No plans to address
▪ Don’t know
Survey
The BOTS Act explained
▪ Prohibits the circumvention of a
security measure used to enforce ticket
purchasing limits for an event with an
attendance capacity > 200 pers.
▪ Prohibits the sale of an event ticket
obtained through such a circumvention
violation if the seller participated in, had
the ability to control, or should have
known about it
BOTS Act key prohibitions
▪ Scalping
▪ Sniping
▪ Spinning
20% of traffic bad bots
OWASP Automated Threats relevant to BOTS Act
Ticketing Bots Sophistication
Other legislation
▪ Must Have Protections
Prohibits the circumvention of a security
measure used to enforce ticket purchasing
limits for an event with an attendance
capacity > 200 pers.
Who does it impact? Primary Ticketing.
▪ Federal Trade Commission Audits:
Treats violations as unfair or deceptive acts
under the FTC Act. The bill provides authority
to the FTC and states to enforce against such
violations
▪ Must Have Protections
Prohibits the circumvention of a security
measure used to enforce ticket
purchasing limits for an event with an
attendance capacity > 200 pers.
Who does it impact? Secondary Ticketing.
▪ FTC Audits
Treats violations as unfair or deceptive
acts under the FTC Act, provides
authority to the FTC and states to
enforce against such violations
Prohibits the sale of an event ticket
obtained through such a circumvention
violation if the seller participated in,
had the ability to control, or should
have known about it
Can you enforce?
Who does this impact? Venues.
Can you comply? Can you cooperate?
If you aren’t bypassing security measures on a website in order to get
tickets, you aren’t breaking the law.
▪ Doesn’t eliminate the ability to buy & resell tickets obtained legally
▪ Doesn’t address historical relationships between sellers and reseller
▪ Doesn’t make the 40% of tickets not on public sale magically
reappear
What the BOTS Act does not address
▪ Bots: scapegoat for a bigger problem in ticketing
▪ Humans + scripts: Cubefarm of people operating
bots with industry experts managing them
▪ 7 years + $25M later, FBI cracks down in 2010
▪ Ken Lowson now a wiseguy turned good
…and then there’s Wiseguys
Source: https://motherboard.vice.com/en_us/article/the-
man-who-broke-ticketmaster
▪ Precise log in, processing thousands of
purchases faster than any human
▪ Fooling CAPTCHA, with huge database
of combinations + operating at
lightning speed
▪ Securing best seats & selling them at a
steep markup for resale to the public
How they did it
Source: U.S. Attorney Office, The Star Ledger
Other ‘wiseguys’ like ShowsOnSale continue to pop up,
historically hard & expensive to prosecute
Why you can’t sell out in 20 minutes
Ticket onsales timeline
It’s not possible to sell out in less
than 2x basket/cart timeout time
More info: https://queue-
it.com/presentation-can-you-sell-out-in-
2-minutes-no-learn-why/
In other words, as a venue, organization or ticketing
software platform, it is still on you to defend against
this fraudulent activity during your major onsales
How bots abuse the logic of online ticket sales
Distil Networks Queue-it Distil Networks
Before onsale: Account Creation
Distil Networks Queue-it Distil Networks
Before onsale: Account Takeover
Distil Networks Queue-it Distil Networks
Account Takeover Attacks
Financial fraud
Targets are accounts at financial
or e-commerce services that store
users’ banking details. The
attackers perform unauthorized
withdrawal from bank accounts
or fraudulent transactions using
the credit/debit cards on file.
This includes virtual currency
such as bitcoin, in-game currency,
and rewards programs. This is all
worth real money.
Account Takeover Attacks: Why?
Spam
Spam can appear in any
service feature that accepts
user-generated content,
including discussion forums,
direct messages, and
reviews/ratings, degrading
platform integrity and brand
reputation.
Phishing
Attackers can assume a
compromised user’s identity
and launch phishing attacks on
others in his/her social circle to
steal their credentials,
personal information, or
sensitive data.
“Over 50% of web applications attacks use
stolen credentials.”
“An attack on one company is a potential
threat to all companies.”
“Mitigating these types of account takeovers is
critical to maintaining customer loyalty.”
Breaches in the News
Image: Verizon
Sources: Krebsonsecurity.com, Bankinfosecurity.com, Bloomberg.com, & Privacyandsecuritymatters.com,
Verizon Data Breach Incident Report
Hotmail - 33M Logins/Pwds - May 2016
LinkedIn - 167M Logins/Pwds - Nov 2012
VK.com - 100M Logins/Pwds - June 2016
Mail.ru - 57M Logins/Pwds- May 2016
Yahoo! - 40M Logins/Pwds - May 2015
Tumblr - 65M Logins/Pwds - June 2016
Account Takeover Bots Sophistication
Day of onsale / During onsale
Distil Networks Queue-it Distil Networks
Volume
Distil Networks Queue-it Distil Networks
Volume
▪ To achieve this, spinner bots
create many hits
▪ Queue-it can recognize this as
coming from same device and will
block
▪ 50% of blocking during a major
onsale is due to spinner bots
Speed
Distil Networks Queue-it Distil Networks
Speed
▪ Any speed scripted
bots arriving before
the event are placed
in the randomized
pre-event waiting
room before the
event launches
Pre-event queue page Live event queue page
During ticket purchase
Distil Networks Queue-it Distil Networks
Credit card fraud
Multiple purchases, exceeding limits
Distil Networks Queue-it Distil Networks
IP Address
Header & User Agent Information
Cookie Browser
200+ Attributes of data
Navigator, WebGL, Plugins, Audio, Video, etc.
Tamper proofing layer
Distil Hi-Def Fingerprint
Identification Must Go Beyond the IP Address...
StubHub Case Study
StubHub Case Study
Account Takeover and Fraud
“Distil helped us greatly reduce
transaction fraud and account
takeovers.”
Marty Boos
CIO, StubHub
StubHub Case Study
Ticket Scraping
“Competitive data mining for
ticket prices and inventory
information was a constant
threat.”
Marty Boos
CIO, StubHub
StubHub Case Study
Skewed Conversion Tracking
“The number of conversions were
greatly deflated because of bad
bot traffic. Now that we’re filtering
bad bot traffic out, we’re able to
see what the real data is and
make decisions based on real
visitors.”
Marty Boos
CIO, StubHub
StubHub Case Study Conclusions
In reference to the before, wait and buyer journey:
“I like this multi-layered approach”
George Loyer, Director
Technical Operations, StubHub
Distil Networks Queue-it Distil Networks
Q&A
Rami Essaid
CEO & Co-founder,
Distil Networks
Niels Sodemann
CEO & Co-founder,
Queue-it
Free trial Free trial
www.distilnetworks.com/trial www.queue-it.com/free-trial

Contenu connexe

Tendances

2013.05.16 cfaa powerpoint for ima.v1
2013.05.16 cfaa powerpoint for ima.v12013.05.16 cfaa powerpoint for ima.v1
2013.05.16 cfaa powerpoint for ima.v1
Shawn Tuma
 

Tendances (10)

Ways to Beat Vendor and Procurement Fraudsters Using Data Analysis
Ways to Beat Vendor and Procurement Fraudsters Using Data AnalysisWays to Beat Vendor and Procurement Fraudsters Using Data Analysis
Ways to Beat Vendor and Procurement Fraudsters Using Data Analysis
 
Case Study on Property Portal Data Security
Case Study on Property Portal Data SecurityCase Study on Property Portal Data Security
Case Study on Property Portal Data Security
 
17 00 distil rami
17 00 distil rami17 00 distil rami
17 00 distil rami
 
2013.05.16 cfaa powerpoint for ima.v1
2013.05.16 cfaa powerpoint for ima.v12013.05.16 cfaa powerpoint for ima.v1
2013.05.16 cfaa powerpoint for ima.v1
 
Big data analytical driven fraud detection for finance; banks and insurance
Big data analytical driven fraud detection for finance; banks and insuranceBig data analytical driven fraud detection for finance; banks and insurance
Big data analytical driven fraud detection for finance; banks and insurance
 
New! Omni-Channel Fraud Prevention
New! Omni-Channel Fraud Prevention New! Omni-Channel Fraud Prevention
New! Omni-Channel Fraud Prevention
 
Better Metrics, Less Hacks: Online Travel and The Future of Web Security
Better Metrics, Less Hacks: Online Travel and The Future of Web SecurityBetter Metrics, Less Hacks: Online Travel and The Future of Web Security
Better Metrics, Less Hacks: Online Travel and The Future of Web Security
 
Bitcoin payments innovation by pervees faisal islam
Bitcoin payments innovation by pervees faisal islam Bitcoin payments innovation by pervees faisal islam
Bitcoin payments innovation by pervees faisal islam
 
Falcon 012009
Falcon 012009Falcon 012009
Falcon 012009
 
Paybefore bitcoin hater lover
Paybefore bitcoin hater loverPaybefore bitcoin hater lover
Paybefore bitcoin hater lover
 

En vedette

Aumenta valor en el ciclo de compra de tu cliente - Juan Carlos Rendón
Aumenta valor en el ciclo de compra de tu cliente - Juan Carlos RendónAumenta valor en el ciclo de compra de tu cliente - Juan Carlos Rendón
Aumenta valor en el ciclo de compra de tu cliente - Juan Carlos Rendón
BusinessConnect2017
 
Simplificando el uso de los datos para la era cognitiva - Daniel González
Simplificando el uso de los datos para la era cognitiva - Daniel GonzálezSimplificando el uso de los datos para la era cognitiva - Daniel González
Simplificando el uso de los datos para la era cognitiva - Daniel González
BusinessConnect2017
 
La Transformación Digital en la Era Cognitiva - Eduardo Gutiérrez
La Transformación Digital en la Era Cognitiva - Eduardo GutiérrezLa Transformación Digital en la Era Cognitiva - Eduardo Gutiérrez
La Transformación Digital en la Era Cognitiva - Eduardo Gutiérrez
BusinessConnect2017
 

En vedette (20)

¿QUÉ ES AMEICAH?
¿QUÉ ES AMEICAH?¿QUÉ ES AMEICAH?
¿QUÉ ES AMEICAH?
 
Sales Performance Management
Sales Performance ManagementSales Performance Management
Sales Performance Management
 
ICS - Guty Cárdenas
ICS - Guty CárdenasICS - Guty Cárdenas
ICS - Guty Cárdenas
 
Rompiendo los paradigmas del Cloud Computing - Baltazar Rodríguez
Rompiendo los paradigmas del Cloud Computing - Baltazar RodríguezRompiendo los paradigmas del Cloud Computing - Baltazar Rodríguez
Rompiendo los paradigmas del Cloud Computing - Baltazar Rodríguez
 
Security Business Connect 2017 - Paul Rangel
Security Business Connect 2017 - Paul RangelSecurity Business Connect 2017 - Paul Rangel
Security Business Connect 2017 - Paul Rangel
 
Aumenta valor en el ciclo de compra de tu cliente - Juan Carlos Rendón
Aumenta valor en el ciclo de compra de tu cliente - Juan Carlos RendónAumenta valor en el ciclo de compra de tu cliente - Juan Carlos Rendón
Aumenta valor en el ciclo de compra de tu cliente - Juan Carlos Rendón
 
Simplificando el uso de los datos para la era cognitiva - Daniel González
Simplificando el uso de los datos para la era cognitiva - Daniel GonzálezSimplificando el uso de los datos para la era cognitiva - Daniel González
Simplificando el uso de los datos para la era cognitiva - Daniel González
 
Escucha a tu cliente - Carlos Gutiérrez
Escucha a tu cliente - Carlos GutiérrezEscucha a tu cliente - Carlos Gutiérrez
Escucha a tu cliente - Carlos Gutiérrez
 
Vive una experiencia digital diferenciada - Guillermo Martínez
Vive una experiencia digital diferenciada - Guillermo Martínez Vive una experiencia digital diferenciada - Guillermo Martínez
Vive una experiencia digital diferenciada - Guillermo Martínez
 
La Transformación Digital en la Era Cognitiva - Eduardo Gutiérrez
La Transformación Digital en la Era Cognitiva - Eduardo GutiérrezLa Transformación Digital en la Era Cognitiva - Eduardo Gutiérrez
La Transformación Digital en la Era Cognitiva - Eduardo Gutiérrez
 
3 hard facts shaping higher education thinking and behavior
3 hard facts shaping higher education thinking and behavior3 hard facts shaping higher education thinking and behavior
3 hard facts shaping higher education thinking and behavior
 
What's Trending in Talent and Learning for 2016?
What's Trending in Talent and Learning for 2016?What's Trending in Talent and Learning for 2016?
What's Trending in Talent and Learning for 2016?
 
SXSW 2016: The Need To Knows
SXSW 2016: The Need To KnowsSXSW 2016: The Need To Knows
SXSW 2016: The Need To Knows
 
The French Revolution of 1789
The French Revolution of 1789The French Revolution of 1789
The French Revolution of 1789
 
Digitized Student Development, Social Media, and Identity
Digitized Student Development, Social Media, and IdentityDigitized Student Development, Social Media, and Identity
Digitized Student Development, Social Media, and Identity
 
8 Tips for Scaling Mobile Users in China by Edith Yeung
8 Tips for Scaling Mobile Users in China by Edith Yeung8 Tips for Scaling Mobile Users in China by Edith Yeung
8 Tips for Scaling Mobile Users in China by Edith Yeung
 
GAME ON! Integrating Games and Simulations in the Classroom
GAME ON! Integrating Games and Simulations in the Classroom GAME ON! Integrating Games and Simulations in the Classroom
GAME ON! Integrating Games and Simulations in the Classroom
 
Connecting With the Disconnected
Connecting With the DisconnectedConnecting With the Disconnected
Connecting With the Disconnected
 
Creative Traction Methodology - For Early Stage Startups
Creative Traction Methodology - For Early Stage StartupsCreative Traction Methodology - For Early Stage Startups
Creative Traction Methodology - For Early Stage Startups
 
Bill Aulet GEC2016 keynote speech March 16 2016 Medellin Colombia
Bill Aulet GEC2016 keynote speech March 16 2016 Medellin ColombiaBill Aulet GEC2016 keynote speech March 16 2016 Medellin Colombia
Bill Aulet GEC2016 keynote speech March 16 2016 Medellin Colombia
 

Similaire à How the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem

Smart card emv for dummies
Smart card emv for dummiesSmart card emv for dummies
Smart card emv for dummies
BACKSEATRIDER
 

Similaire à How the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem (20)

Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상
Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상
Debunking Myths about Malicious Bots / 악성 봇의 허상과 실상
 
Ensuring Property Portal Listing Data Security
Ensuring Property Portal Listing Data SecurityEnsuring Property Portal Listing Data Security
Ensuring Property Portal Listing Data Security
 
Rtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deckRtp rsp16-distil networks-final-deck
Rtp rsp16-distil networks-final-deck
 
Are Bot Operators Eating Your Lunch?
Are Bot Operators Eating Your Lunch?Are Bot Operators Eating Your Lunch?
Are Bot Operators Eating Your Lunch?
 
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
 
Life As A Fraudster: Carding 101
Life As A Fraudster: Carding 101Life As A Fraudster: Carding 101
Life As A Fraudster: Carding 101
 
Are Bad Bots Destroying Your Conversion Rate and Costing You Money?
Are Bad Bots Destroying Your Conversion Rate and Costing You Money?Are Bad Bots Destroying Your Conversion Rate and Costing You Money?
Are Bad Bots Destroying Your Conversion Rate and Costing You Money?
 
AI_finance_Module-3.pptx
AI_finance_Module-3.pptxAI_finance_Module-3.pptx
AI_finance_Module-3.pptx
 
AI for optimizing customer journeys in online betting
AI for optimizing customer journeys in online bettingAI for optimizing customer journeys in online betting
AI for optimizing customer journeys in online betting
 
How to Create 80% of a Big Data Pilot Project
How to Create 80% of a Big Data Pilot ProjectHow to Create 80% of a Big Data Pilot Project
How to Create 80% of a Big Data Pilot Project
 
Data Breach Prevention - Start with your POS Terminal!
Data Breach Prevention - Start with your POS Terminal!Data Breach Prevention - Start with your POS Terminal!
Data Breach Prevention - Start with your POS Terminal!
 
DLT - AML & CFT - Risks & Opportunites
DLT - AML & CFT - Risks & Opportunites DLT - AML & CFT - Risks & Opportunites
DLT - AML & CFT - Risks & Opportunites
 
Smart card emv for dummies
Smart card emv for dummiesSmart card emv for dummies
Smart card emv for dummies
 
Blockchain & Cryptocurrency - Part II (Jose Paul Martin)
Blockchain & Cryptocurrency - Part II (Jose Paul Martin)Blockchain & Cryptocurrency - Part II (Jose Paul Martin)
Blockchain & Cryptocurrency - Part II (Jose Paul Martin)
 
Super data-charging your corruption reviews with integrated analytics
Super data-charging your corruption reviews with integrated analyticsSuper data-charging your corruption reviews with integrated analytics
Super data-charging your corruption reviews with integrated analytics
 
Big data
Big dataBig data
Big data
 
PPPT0005.pptx
PPPT0005.pptxPPPT0005.pptx
PPPT0005.pptx
 
RChain Developer Conference pithia investments 04-2018
RChain Developer Conference   pithia investments 04-2018RChain Developer Conference   pithia investments 04-2018
RChain Developer Conference pithia investments 04-2018
 
Using Data Analytics to Detect and Prevent Corporate and P-Card Fraud
Using Data Analytics to Detect and Prevent Corporate and P-Card FraudUsing Data Analytics to Detect and Prevent Corporate and P-Card Fraud
Using Data Analytics to Detect and Prevent Corporate and P-Card Fraud
 
The thieves
The thievesThe thieves
The thieves
 

Plus de Distil Networks

The Website Resiliency Imperative
The Website Resiliency ImperativeThe Website Resiliency Imperative
The Website Resiliency Imperative
Distil Networks
 
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website DefendersDistil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
Distil Networks
 

Plus de Distil Networks (8)

The Website Resiliency Imperative
The Website Resiliency ImperativeThe Website Resiliency Imperative
The Website Resiliency Imperative
 
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website DefendersDistil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
Distil Networks 2017 Bad Bot Report: 6 High Risk Lessons for Website Defenders
 
The Inconvenient Truth About API Security
The Inconvenient Truth About API SecurityThe Inconvenient Truth About API Security
The Inconvenient Truth About API Security
 
2016 Bad Bot Report: Quantifying the Risk and Economic Impact of Bad Bots
2016 Bad Bot Report: Quantifying the Risk and Economic Impact of Bad Bots2016 Bad Bot Report: Quantifying the Risk and Economic Impact of Bad Bots
2016 Bad Bot Report: Quantifying the Risk and Economic Impact of Bad Bots
 
Using Permaculture to Cultivate a Sustainable Security Program
Using Permaculture to Cultivate a Sustainable Security ProgramUsing Permaculture to Cultivate a Sustainable Security Program
Using Permaculture to Cultivate a Sustainable Security Program
 
Keeping up with the Revolution in IT Security
Keeping up with the Revolution in IT SecurityKeeping up with the Revolution in IT Security
Keeping up with the Revolution in IT Security
 
Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!
 
Cleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammersCleaning up website traffic from bots & spammers
Cleaning up website traffic from bots & spammers
 

Dernier

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 

Dernier (20)

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 

How the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem

  • 1.
  • 2. ▪ Introduction ▪ Bots 101 ▪ BOTS Act and what it covers (and doesn’t cover) ▪ How bots can impact your major onsales and associated mitigation strategies ▪ StubHub case study ▪ Q&A
  • 3. Rami Essaid CEO & Co-founder, Distil Networks Niels Sodemann CEO & Co-founder, Queue-it Distil Networks is the only proactive and precise bot mitigation solution for web applications, mobile, and APIs. ▪ Founded in 2011 ▪ 180 employees ▪ 5 offices ▪ $65 million in funding The use of Queue-it has ensured online fairness during high-demand online events for more than 1.5 billion consumers worldwide. ▪ Founded in 2010 ▪ 63 employees ▪ 2016 TTA winner of Supplier of the Year DenmarkSilicon Valley
  • 4. Awards and Analyst Recognition The only anti-bot solution to be included in Gartner’s Online Fraud Detection Market Guide 2-years running “Distil’s ability to analyze behavior provides the best chance of detecting and blocking bot-driven attacks.” “Clear innovation compared to similar services.” 2017 WINNER: Best Fraud Prevention Solution
  • 5. Telling the story together
  • 7. Good bots ▪ Search engine crawling ▪ Power APIs ▪ Check system connectivity & status A ‘bot’ is an automated program that runs on the internet Bad bots ▪ Steal content ▪ Scan for vulnerabilities ▪ Perform fraud etc. Traffic Distribution by Type, 2016
  • 8. What concerns you most about the impact of bots on your organization’s website(s)? ▪ Website Security ▪ Transaction Fraud ▪ Lost Revenue to Scalpers ▪ Poor Customer Experience Survey
  • 9. How are you addressing your bot concerns? ▪ Addressing now ▪ Plan to address this year ▪ Plan to address next year ▪ No plans to address ▪ Don’t know Survey
  • 10. The BOTS Act explained
  • 11. ▪ Prohibits the circumvention of a security measure used to enforce ticket purchasing limits for an event with an attendance capacity > 200 pers. ▪ Prohibits the sale of an event ticket obtained through such a circumvention violation if the seller participated in, had the ability to control, or should have known about it BOTS Act key prohibitions
  • 12. ▪ Scalping ▪ Sniping ▪ Spinning 20% of traffic bad bots OWASP Automated Threats relevant to BOTS Act
  • 15. ▪ Must Have Protections Prohibits the circumvention of a security measure used to enforce ticket purchasing limits for an event with an attendance capacity > 200 pers. Who does it impact? Primary Ticketing. ▪ Federal Trade Commission Audits: Treats violations as unfair or deceptive acts under the FTC Act. The bill provides authority to the FTC and states to enforce against such violations
  • 16. ▪ Must Have Protections Prohibits the circumvention of a security measure used to enforce ticket purchasing limits for an event with an attendance capacity > 200 pers. Who does it impact? Secondary Ticketing. ▪ FTC Audits Treats violations as unfair or deceptive acts under the FTC Act, provides authority to the FTC and states to enforce against such violations Prohibits the sale of an event ticket obtained through such a circumvention violation if the seller participated in, had the ability to control, or should have known about it
  • 17. Can you enforce? Who does this impact? Venues. Can you comply? Can you cooperate?
  • 18. If you aren’t bypassing security measures on a website in order to get tickets, you aren’t breaking the law. ▪ Doesn’t eliminate the ability to buy & resell tickets obtained legally ▪ Doesn’t address historical relationships between sellers and reseller ▪ Doesn’t make the 40% of tickets not on public sale magically reappear What the BOTS Act does not address
  • 19. ▪ Bots: scapegoat for a bigger problem in ticketing ▪ Humans + scripts: Cubefarm of people operating bots with industry experts managing them ▪ 7 years + $25M later, FBI cracks down in 2010 ▪ Ken Lowson now a wiseguy turned good …and then there’s Wiseguys Source: https://motherboard.vice.com/en_us/article/the- man-who-broke-ticketmaster
  • 20. ▪ Precise log in, processing thousands of purchases faster than any human ▪ Fooling CAPTCHA, with huge database of combinations + operating at lightning speed ▪ Securing best seats & selling them at a steep markup for resale to the public How they did it Source: U.S. Attorney Office, The Star Ledger
  • 21. Other ‘wiseguys’ like ShowsOnSale continue to pop up, historically hard & expensive to prosecute
  • 22. Why you can’t sell out in 20 minutes Ticket onsales timeline It’s not possible to sell out in less than 2x basket/cart timeout time More info: https://queue- it.com/presentation-can-you-sell-out-in- 2-minutes-no-learn-why/
  • 23.
  • 24. In other words, as a venue, organization or ticketing software platform, it is still on you to defend against this fraudulent activity during your major onsales
  • 25. How bots abuse the logic of online ticket sales Distil Networks Queue-it Distil Networks
  • 26. Before onsale: Account Creation Distil Networks Queue-it Distil Networks
  • 27. Before onsale: Account Takeover Distil Networks Queue-it Distil Networks
  • 29. Financial fraud Targets are accounts at financial or e-commerce services that store users’ banking details. The attackers perform unauthorized withdrawal from bank accounts or fraudulent transactions using the credit/debit cards on file. This includes virtual currency such as bitcoin, in-game currency, and rewards programs. This is all worth real money. Account Takeover Attacks: Why? Spam Spam can appear in any service feature that accepts user-generated content, including discussion forums, direct messages, and reviews/ratings, degrading platform integrity and brand reputation. Phishing Attackers can assume a compromised user’s identity and launch phishing attacks on others in his/her social circle to steal their credentials, personal information, or sensitive data.
  • 30. “Over 50% of web applications attacks use stolen credentials.” “An attack on one company is a potential threat to all companies.” “Mitigating these types of account takeovers is critical to maintaining customer loyalty.” Breaches in the News Image: Verizon Sources: Krebsonsecurity.com, Bankinfosecurity.com, Bloomberg.com, & Privacyandsecuritymatters.com, Verizon Data Breach Incident Report Hotmail - 33M Logins/Pwds - May 2016 LinkedIn - 167M Logins/Pwds - Nov 2012 VK.com - 100M Logins/Pwds - June 2016 Mail.ru - 57M Logins/Pwds- May 2016 Yahoo! - 40M Logins/Pwds - May 2015 Tumblr - 65M Logins/Pwds - June 2016
  • 31. Account Takeover Bots Sophistication
  • 32. Day of onsale / During onsale Distil Networks Queue-it Distil Networks
  • 34. Volume ▪ To achieve this, spinner bots create many hits ▪ Queue-it can recognize this as coming from same device and will block ▪ 50% of blocking during a major onsale is due to spinner bots
  • 36. Speed ▪ Any speed scripted bots arriving before the event are placed in the randomized pre-event waiting room before the event launches Pre-event queue page Live event queue page
  • 37. During ticket purchase Distil Networks Queue-it Distil Networks
  • 39. Multiple purchases, exceeding limits Distil Networks Queue-it Distil Networks
  • 40. IP Address Header & User Agent Information Cookie Browser 200+ Attributes of data Navigator, WebGL, Plugins, Audio, Video, etc. Tamper proofing layer Distil Hi-Def Fingerprint Identification Must Go Beyond the IP Address...
  • 42. StubHub Case Study Account Takeover and Fraud “Distil helped us greatly reduce transaction fraud and account takeovers.” Marty Boos CIO, StubHub
  • 43. StubHub Case Study Ticket Scraping “Competitive data mining for ticket prices and inventory information was a constant threat.” Marty Boos CIO, StubHub
  • 44. StubHub Case Study Skewed Conversion Tracking “The number of conversions were greatly deflated because of bad bot traffic. Now that we’re filtering bad bot traffic out, we’re able to see what the real data is and make decisions based on real visitors.” Marty Boos CIO, StubHub
  • 45. StubHub Case Study Conclusions In reference to the before, wait and buyer journey: “I like this multi-layered approach” George Loyer, Director Technical Operations, StubHub Distil Networks Queue-it Distil Networks
  • 46. Q&A Rami Essaid CEO & Co-founder, Distil Networks Niels Sodemann CEO & Co-founder, Queue-it
  • 47. Free trial Free trial www.distilnetworks.com/trial www.queue-it.com/free-trial