UPDATED 10:02 EDT / MARCH 14 2012

Incapsula Report: More than Half of Website Visitors are Machines

Incapsula, a provider of cloud-based security for web sites, released a study today showing that 51% of web site traffic is automated software programs, and the majority is potentially damaging, — automated exploits from hackers, spies, scrapers, and spammers.

The company says that typically, only 49% of a web site’s visitors are actual humans and that the non-human traffic is mostly invisible because it is not shown by analytics software.

This means that web sites are carrying a large hidden cost burden in terms of bandwidth, increased risk of business disruption, and worse.

Here’s a breakdown of an average web site’s traffic:

– 5% is hacking tools searching for an unpatched or new vulnerability in a web site.

– 5% is scrapers.

– 2% is automated comment spammers.

– 19% is from “spies” collecting competitive intelligence.

– 20% is from search engines – which is non-human traffic but benign.

– 49% is from people browsing the Internet.

The data was collected from a sample of 1,000 websites that are enrolled in the Incapsula service.

I spoke with Marc Gaffan, co-founder of Incapsula. “Few people realize how much of their traffic is non-human, and that much of it is potentially harmful.”

Incapsula offers a service aimed at securing small and medium sized businesses. It has a global network of nine data centers that analyze all traffic to a customer’s site and blocking harmful exploits in real-time, while also speeding up page loading times through cached content closer to users.

“Because we have thousands of web sites as customers, we spot exploits way ahead of others and we can then block them for all our customers. That’s the benefit of scale. We also maintain a virtual patch service that prevents harmful exploits days and sometimes weeks before a patch is ready.”

There is no software or hardware installation required by the customer, a small change in a web site’s DNS records directs traffic through Incapsula’s data centers. And all analytics, and search engine rankings, are unaffected by the change.

Web sites are significantly faster because the company caches content and keeps it close to where users are located.

An important aspect of the service is that it is in compliance with the Payment Card Industry data security standard (PCI) which is essential for online merchants. They risk losing their ability to process credit card payments if they don’t meet strict PCI requirements.

The company offers a free service for sites with less than 25 GB of monthly bandwidth, and premium plans start at $49 a month.

Foremski’s Take: I’m curious to try this service because looking at my server logs I get hit by about 28 ‘robots’ daily, and while some are from legitimate sources such as Google, Yahoo, Microsoft, the majority are unidentified and together, they use as much as one-third of my bandwidth.

This means that the human user experience suffers because my server is trying to deal with all the ‘non-human’ traffic generated by software programs hitting the site.

Incapsula’s ability to block exploits before a patch is available is another attractive feature. I don’t have time to keep up with the many security patches sent out, and then installing and upgrading multiple programs is a chore I’d rather do without.

 

[Cross-posted at Silicon Valley Watcher]


A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.