"Advanced Bots and Security Evasion Techniques" - David Warburton

Опубликовано: 30 Июнь 2026
на канале: OWASP London
218
3

APOLOGIES FOR POOR QUALITY VIDEO - THIS WAS CAUSED BY TECHNICAL ISSUES DURING THE LIVE STREAM RECORDING: THE LINK TO THE SLIDE DECK IS IN THE DESCRIPTION:

Bots are generally seen as a bit of a nuisance and widely regarded as the weapon of choice for DDoS attacks. However, modern bots are capable of much more and are claimed to be behind three quarters of all attacks that hit web sites and APIs. Techniques such as rate limiting, IP blacklisting and even CAPTCHAs often do little to prevent the attacks as they evolve, evading controls which try to differentiate between bots and humans. In this session we’re going to look at what bots are and how they’re created, what they’re now capable of, which industries are most affected by them and how they are evolving to avoid our current defences.


Speaker bio:David Warburton is an information security threat researcher and evangelist for F5 Labs and frequently speaks at conferences and with customers all over the world. His focus areas of research are on SSL/TLS and other cryptographic protocols and certificates, digital identity, web application security, information risk management and compliance & regulation. A recent alumni of Royal Holloway University where he wrote his MSc dissertation on IoT Security, he now works on identifying emerging cyber threats, producing actionable intelligence reports and consulting on cyber security strategy within public sector, retail and financial organisations.

The slide deck can be downloaded as PDF here: https://www.owasp.org/images/8/89/OWA...

This talk was presented at the OWASP London Chapter Meeting on July 18th, 2019