Your Digital Identity’s Evil Shadow – Dark Reading


In the wrong hands, these shady shadows are stealthy means to bypass security systems by hiding behind a proxy with legitimate IP addresses and user agents.

When digital identity is mentioned, most people think about attributes related to a person, such as login credentials, Social Security numbers, and biometrics. While these are critical aspects of identity theft and online fraud, there’s another element that’s not as widely recognized. I call it your digital identity’s evil shadow. It follows you around wherever you go. It looks like you. It acts like you. Yet its attributes can’t be directly traced back to you. This shadow is shady, as it is harvested and used without your knowledge to conduct automated attacks against online businesses.

Looks Like You
Recently, it has been reported that proxy service companies are offering compensation to developers to insert code into a browser extension so that it can route Web traffic on behalf of an unsuspecting user. It essentially acts as a residential proxy where people can remain anonymous — at the expense of others. As a result, the traffic appears as though it is coming from the victim’s Internet address and not the actual user.

Other proxy services such as Luminati (now Bright Data) and MonkeySocks also offer residential and commercial proxy services and have similar backdoor ways of harvesting information, such as by inserting their code into virtual private network (VPN) software. Some residential proxy networks even let you purchase IPs for specific countries or historical website visitors to help them blend in with normal traffic.

To be fair, these services do offer legitimate purposes for enterprise companies, such as website testing and fraud protection. But when in the wrong hands, they are stealthy means to bypass security systems by hiding behind a proxy with legitimate IP addresses and user agents. There’s a high likelihood that your digital identity’s evil shadow is unknowingly being harvested and made available for purchase — along with hundreds of millions of others — for both good and nefarious purposes.

Acts Like You
To fly beneath the radar of modern security defenses, it’s not enough just to look like you; your shadow must also act like you.

Combined with a residential proxy service, open source and free scripting tools, such as Puppeteer and Playwright, are applied to mimic human behavior. These types of tools are loved by developers because they provide a way to automate test scripts to do quality assurance (QA) for Web applications. But they are also loved by bot operators because they provide a means to emulate human behavior while leveraging the benefits of automation at scale.

In fact, it is now easy to record testing scripts with a simple Chrome plugin, where the tool records the user’s activity and thereby eliminates the need for code to generate scripts. Meanwhile, the open source community has developed its own plugins that provide stealth evasion techniques, including automated and manual CAPTCHA solving, so the benefits of using familiar headless browser automation tools can be applied at scale while acting as human as possible.

Ease of Access
It’s easy to gain access to residential proxy networks (and turnkey bot tools that leverage them) from hundreds of options to choose from online. I downloaded one of the free bots, and in just two minutes of running it, I observed:

  • Geographically distributed IP addresses: I found 150 different IP addresses — only one of which issued more than one request. It would take several hours before any IP address was reused.
IP Address Distribution ProxyEgg Your Digital Identity's Evil Shadow - Dark Reading
  • Legitimate-looking user agents: In the next few minutes, roughly 518 unique user agents were generated and used. Most of these agents presented themselves as legitimate, modern devices able to mask their true identity by appearing normal.

The rotation of user agents and proxies creates a nearly unrecognizable, invisible effect to prevent detection.

What You Can Do
Applying security controls that can accurately detect requests that look and act like you can seem like an impossible challenge because you must determine whether it is the human (good) or its evil shadow (bad). Looking at attributes such as IP address, user agents, validated CAPTCHAs, and even machine learning algorithms tuned to identify suspicious behavior yields inconsistent detection and false positives. After all, the last thing you want to do is block your legitimate users.

There are two approaches to ridding yourself of the impact of digital shadows. The first is to better control the availability of such tools and, in some cases, challenge their legality. This seems highly unlikely to work because history has taught us that when there is profit to be made, such tools and services will continue to prevail. They also serve legitimate purposes because developers will always need to test their applications in as realistic an environment as possible.

The second is a fundamentally different approach to detection. In contrast to traditional security controls, new methods don’t make decisions based on how a request looks and acts. Instead, they detect the presence of automation. For example, if you can determine how a request presents itself in the context of a legitimate browser or mobile app, you can identify evidence to determine whether it is a human or not.

This is very much analogous to what happened with endpoint security, whereby rules and signatures became ineffective and new ruleless methods were developed to identify vulnerabilities and malware. This paradigm shift is necessary for Web and mobile application security to sustain its effectiveness against modern, evolving automated threats.

Sam Crowther is the founder of Kasada. Sam’s passion for the security industry began as a high school student when he worked with the team at Australia’s Signals Intelligence Agency. From there, he moved to a red team role at Macquarie Group, an experience that inspired him … View Full Bio

Recommended Reading:

More Insights

Source of this news: https://www.darkreading.com/operations/your-digital-identitys-evil-shadow/a/d-id/1340766

Related posts:

Raging SEO: Leading the Investment Proxies Industry Through Ethically Sourced IP Addresses help Digi...
The company offers the most trusted residential proxy service on the planet. Fortune 500, travel conglomerates, search engines, e-commerce companies, gov departments and many other highly-re...
Ranking: Sift Uncovers and Chunks Fraud Ring Swarming Elektronischer geschäftsverkehr Merchants with...
SAN FRANCISCO, Sept. 30, 2021 (GLOBE NEWSWIRE) -- Sift , the leader in Electronic digital Trust & Safety, times released its Q3 2021 Digital Trust & Basic Index, which details the mo...
Bye Google: 7 privacy-first search engines everyone should try - Fast Company
advertisementadvertisementEven if you have nothing to hide, searching the web with Google can sometimes feel unnerving.advertisementadvertisementMaybe you’ve got a medical question or financial conce...
Top 7 Tips To Make Your WordPress Site Fast & Secure - Search Engine Journal
Ready to build your first website? Are you shopping for affordable WordPress web hosting?There are multiple types of web hosting solutions to choose from: shared hosting, dedicated hosting, cloud hos...
UMass Memorial notifies 209K patients 8 months after data breach discovery - SC Magazine
When a breach attack affects one or two organizations — especially financial institutions or other businesses in highly regulated industries, which hold oodles of sensitive information — it can be ba...
What is a VPN and how to get one? - techPresident
VPNs are becoming increasingly popular on today’s internet, but many people still don’t know what they do or how to use them. This guide will walk you through the basics of VPNs and some reasons why ...
Dallas Invents: 129 Patents Granted for Week of March 2 » Dallas Innovates - dallasinnovates.com
Dallas Invents is a weekly look at U.S. patents granted with a connection to the Dallas-Fort Worth-Arlington metro area. Listings include patents granted to local assignees and/or those with a N...
Genuine Proxy Phantom ATO Deception Ring Haunts eCommerce Company - Threatpost
The administrator on your personal data will be Threatpost, Inc., 500 Unicorn School yard, Woburn, MA 01801. Detailed information on the processing of private data can be found in the privacy p...
Specialised Lead at Sabenza UNDERSTAND IT - IT-Online
Our client wants a Technical lead , for coordination and observance of technical projects applying server engineer, networking, EUC background. Requirements Virtual Server Founding Complete t...
A 3D structural SARS-CoV-2–human interactome to explore genetic and drug perturbations - Nature.com
Generation and validation of SARS-CoV-2 homology modelsHomology-based modeling of all 29 SARS-CoV-2 proteins was performed in Modeller95 using a multiple template modeling procedure consistent with p...
Free Proxy List 2020 [Proxy Server List To Hide Your IP Address] - Fossbytes
With the internet becoming a hotbed for tracking activities and an ever-growing race to collect data, it has become essential to find a means to hide your digital footprints, especially if you are a ...
Eagles Schedule Released - GCOBB. COM - Garry Cobb
Their NFL finally released their unique 2021 schedule last night. You see, the opponents list has been famous for some time know, meaning a number of us knew who and and the Eagles were laying o...
Asustor Drivestor 2 Pro AS3302T - Review 2021 - PCMag India
Designed for use as a personal cloud server, the Asustor Drivestor 2 Pro ($249) is a reasonably priced two-bay NAS that offers multi-gig connectivity and numerous USB ports. It also has a generous ca...
Waikato cyberattack: Servers in question not culprit, DHB says - RNZ
A set of Waikato District Health Board servers were at end-of-life and unpatched when hackers struck in the early hours of 18 May, a source claims. A sign at Waikato Hospital in May. Photo: RNZ /...
Network Server Management: LogicMonitor vs. ManageEngine OpManager | ENP - EnterpriseNetworkingPlane...
A server is a computer or system that is designed to behave as a repository and provide computing resources, services, data and programs to other computers (clients) connected to the network. Technic...
Contender Analysis Via Proxies knowledge Aviation Analysis Wing
They say one sure method thrive in business is by dwelling ahead of your competitors. However , find out how to stay ahead of your competitors should you not what they are doing? Competitor ...
New ZE Loader Targets Online Banking Users - Security Intelligence
New ZE Loader Targets Online Banking Users <!-- --> IBM Trusteer closely follows developments in th...
Something's wrong with the proxy server, or the adress is incorrect. - Service Providers - BleepingC...
As the title may suggest, i have problems with my internet connection, everytime i open a website that's all i see.I have already looked for many solutions on the internet and tried anything i can f...

IP Rotating Proxy Onsale

SPECIAL LIMITED TIME OFFER

00
Months
00
Days
00
Hours
00
Minutes
00
Seconds
First month free with coupon code FREE30