The State of Application Security q2 2023
The State of Application Security q2 2023
APPLICATION
SECURITY - Q2, 2023
INDEX
About Indusface 04
Executive Summary 05
Vulnerability Exploits 05
Necessary Definitions 12
Fully Managed WAF with Integrated Application Scanner (DAST), API Discovery & Security,
DDoS/Bot Protection, and CDN
Indusface, funded by Tata Capital Growth Fund II, is the only vendor to receive 100% customer recommendation rating
three years in a row and is a global customer choice in the Gartner Peer Insights™ Web Application and API Protection
(WAAP) Report 2023. Indusface is also a “Great Place to Work” 2022 Winner in the Mid-Size category in India and is PCI,
ISO27001, SOC 2, GDPR certified and has been the recipient of many prestigious start-up awards.
INSIGHTS™
OUR CUSTOMERS
VULNERABILITY EXPLOITS
Total no. of vulnerabilities found: 33K
and high vulnerabilities have been open for more than 180 days.
This includes 1729 critical vulnerabilities that have been open for 180+ days. With AppTrana, customers can ensure that
vulnerabilities are virtually patched immediately reducing the time to fix ensuring the security team becomes an enabler
Many of our customers leverage the risk-based protection of AppTrana to get vulnerabilities patched in WAF immediately
enabling rapid deployment. AppTrana also ensures the detection and protection of zero-day vulnerabilities with more than
Amidst known vulnerabilities, we have observed recent vulnerabilities like Moveit SQL 0-day and Adobe ColdFusion RCE.
The exploits targeting these vulnerabilities were mitigated out of the box on AppTrana WAAP.
1,155,890,271
We saw over 1.15 billion requests that got blocked across all sites protected by AppTrana. It's a 10% increase in attacks
when compared to the attacks in Q1, 2023.
UK.
41% of requests were blocked by AppTrana’s default rule set and 41%
59% of requests were blocked by custom rules created based on the
59%
specific need of applications - highlighting the value of managed
Custom Rules
As new attack trends of DDoS and bot attacks emerge against web applications and APIs, business continuity becomes
very important.
◦ AppTrana WAAP guarantees zero false positives and ensures 99.99% uptime against layer 3-7 DDoS
attacks with behavioural DDoS mitigation, AI-based rate-limiting based on URI, IP, host, and geo.
Click here to know more.
◦ Against bot attacks such as account takeover, credential stuffing, and scraping, AppTrana WAAP provides
protection from day zero with behavioural & real-time visibility and analysis of bot traffic, correlated risk
scoring & anomaly detection, and custom controls. Click here to know more.
The total number of sites where DDoS & bot Attack trends were observed in the last 180 days are:
557 872,105,826
1304 88,186,868
• There is a 75% increase in the number of DDoS attacks. 872M vs 498M (Q2, 2023 vs Q1, 2023)
• 38% sites witnessed DDoS attacks compared to 30% in the last quarter.
• There is a 48% increase in number of bot attacks. 88M vs 59M (Q2, 2023 vs Q1, 2023)
• 89% sites witnessed bot attacks compared to 86% in the last quarter.
947,830,022
• There is a 90% increase in the number of attacks in India compared to 500 million in Q1 2023
• Banking and insurance faced the highest number of attacks. Over 90% of banking and insurance sites witnessed
a bot attack
• The Banking and Insurance industry relies on custom rules. More than 60% of the attacks were blocked using
custom rules.
◦ XSS or CSS is a web application attack used to gain access to private information by delivering malicious
code to end-users via trusted Web sites. Typically, this type of attack is successful due to a web applica-
tion's lack of user input validation, allowing users to supply application code in HTML forms instead of
• HTML Injection -
◦ A type of injection vulnerability that occurs when a user is able to control an input point and is able to
inject arbitrary HTML code into a vulnerable web page. This vulnerability leads to many consequences,
like disclosure of a user’s session cookies that could be used to impersonate the victim, or it can allow
• DDoS Attack –
◦ A distributed denial of service (DDoS) is a type of cyber-attack where target web applications/ websites
are slowed down or made unavailable to legitimate users by overwhelming the application/ network/
• Bot Attack –
◦ A botnet is the collection of malware-infected computers and networked devices (IoT, smart devices,
etc.) that work together under the control of a single malicious actor or an attack group. Such a network
is also known as a zombie army and each infected device is called a bot/ zombie.
Mayuresh Purandare
Head – IT Infrastructure and Cyber Security, Marico
We do not have a special SOC for Application Security.
As our AppTrana product license includes managed
services, the Indusface team is the AppSec SOC for
us.
Dilip Panjwani
Global Head - Cybersecurity Practice & CoE, LTIMindtree
We were looking for a WAF that focuses on attacker
behaviour rather than variance signatures to mitigate
the risk from application vulnerabilities. We decided to
take the leap and partner with Indusface to protect
our enterprise application footprint.
INSIGHTS™
BENGALURU | VADODARA | MUMBAI | NEW DELHI | SAN FRANCISCO