SlideShare a Scribd company logo
Securing Property Portals
Lamudi Case Study
Platforms
Portals
Brokerages
MLS Customers
Premium Brands
Distil in Real Estate and Premium Brands
The New Threat Landscape of APBs
Advanced Persistent Bots (APBs)...
Advanced
Mimick human behavior
Load JavaScript
Load external resources
Support cookies
Browser automation (Selenium, PhantomJS)
Persistent
Dynamic IP rotation
Distribute attacks across IP addresses
Hide behind anonymous and peer-to-peer proxies 2015 Distil Bad Bot Report
Homegrown Solutions Are Ineffective
Creates a poor user experience Bots appear human in logs Defeated by distributed IP attacks
Defeated by advanced bots Labor intensive Defeated by low and slow crawlers
Defeated by CAPTCHA farms Distributed attacks hard to pinpoint Defeated by peer-to-peer / proxies
Reduces conversions by up to 27% Reactive in nature Reactive in nature
Web App Security Requires Complementary Solutions
l
DDoS Mitigation Firewall WAF Distil Bot Protection
Core
Competency
Volumetric attacks
on infrastructure
Network layer attacks Application coding exploits
Automated abuse, misuse, and attacks
(scraping, fraud, account takeover, etc.)
Techniques Scrubbing centers,
Large pipes
Access Control Lists
(ACLs),
Rules-Based
App layer understanding,
ACLs, Rules-Based
Real-time Analysis, Fingerprinting,
Honeypotting, Machine learning,
Behavioral modeling
Survey Respondents
100 real estate executives representing
over 600,000 realtors
14 real estate portal operators running
400,000 real estate websites
2015 Real Estate Web Scraping Survey
β—‹ 50% - 75% of bot traffic is from Consumer ISPs
β—‹ 7 of top 10 sources of bad bots are Consumer ISPs
β—‹ Most Consumer ISPs had 1,500+ IPs with bots
Highlights of Bot Sources on Real Estate Websites
The Facts on Scraping Real Estate Data
Top 7 Consumer ISPs
with Bot Traffic
1 Comcast
2 Time Warner Cable
3 Verizon FIOS
4 Charter
5 Cox
6 CenturyLink
7 AT&T Uverse
Highlights of Bot Sophistication
β—‹ 18-45% Automated browsers - mimicking humans
β—‹ 14-25% Already in bot database - fingerprinted, known bots
β—‹ 16-42% Slow crawlers - recycling IPs and user agents
About Lamudi
30+ Countries
900,000+ Listings
660+ Employees
Property portal focused exclusively
on emerging markets
Lamudi Bad Bot Challenges
Bad Bot Challenges
Bad guys scraped listing data to duplicate
listings, impact SEO, and compete w/Lamudi
Bots are spamming listing agent/owner contact
forms & reducing agent retention & satisfaction
15,000 bad bot requests per minute (15x
human traffic) caused slowdowns
WAF-based IP blocking system used
enginering time and was ineffective
Lamudi Selection Criteria
Bot Detection and Mitigation Solution Requirements
Support a complex deployment across several AWS instances with Akamai
Block web scrapers and spammers without impacting human visitors
Accurately identify good bots vs. bad bots
Increase website availability and speed
Detect automated browsing tools
Simple setup for 30+ domains
Little or no maintenance, β€œself-optimizing” solution
Lamudi Results with Distil
Results with ROI
No more scraping data β†’ unique listings = better SEO
No more form spam to agents β†’ higher value leads = $$
Less time addressing agent complaints β†’ Rev. Retention = $$
Increased website performance β†’ Faster site = better SEO
Save 100 engineering hours/mo. β†’ More resources! Save $$
β€œDistil is the best anti-bot and anti-scraper protection solution
available, hands down.” Oliver Fiege, CTO, Lamudi
How the Distil Bot Detection Solution Works
As web traffic passes through Distil, the system
1. Fingerprints each incoming connection and
compares it to our Known Violators Database
1. If it’s a new fingerprint, validates the browser
to determine if it’s a Bot or Not
1. β€œNo Silver Bullet” - Distil randomizes a battery
of challenges to find bots and remain spoof-
proof from the bot coders
1. Based on your settings, Distil automatically
tags, challenges, or blocks the bot
Sticky Bot Tracking With No Impact On Real Users
Device Fingerprinting
Fingerprints stick to the bot even if it
attempts to reconnect from random IP
addresses or hide behind an anonymous
proxy or peer-to-peer network
Tracks distributed attacks that would
normally fly under the radar
Without Distil With Distil
Without Impacting Users Sharing the Same IP
Avoids blocking residential users or organizations
that might share the same NAT as the bot or botnet
Browser Validation
Detects all known browser automation tools, such as Selenium and Phantom JS
Protects against browser spoofing by validating each incoming request as self
reported
Advanced Bot Detection Increases Accuracy
Behavioral Modeling and Machine Learning
Machine-learning algorithms pinpoint behavioral anomalies specific to your
site’s unique traffic patterns
Self optimizing algorithms improve bot detection and mitigation without
manual configuration
Awards and Analyst Recognition
β€œAnalyzing behavior provides the best
chance of detecting and blocking bot-
driven attacks.”
5 Stars across the board.β€œ
Verdict: For monitoring the impact of bots on
a network this is the tool one needs.”
The only anti-bot solution to be included
in Gartner’s Online Fraud Detection
Market Guide
Ovum puts Distil Networks On The Radar.
β€œClear innovation compared to similar
services.”
www.distilnetworks.com
QUESTIONS….COMMENTS?
C H A R L I E @ D I S T I L N E T W O R K S . C O M
1.703.962.1614
OR CALL CHARLIE ON

More Related Content

PPTX
17 00 distil rami
PPTX
Better Metrics, Less Hacks: Online Travel and The Future of Web Security
PPTX
Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, B...
PPTX
2016 Bad Bot Report: Quantifying the Risk and Economic Impact of Bad Bots
PPTX
Field Guide for Validating Premium Ad Inventory
PPTX
Tune in for the Ultimate WAF Torture Test: Bots Attack!
PDF
easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...
Β 
PPTX
Presentation - How to do Fraud like Vietnamese
17 00 distil rami
Better Metrics, Less Hacks: Online Travel and The Future of Web Security
Field Guide To Preventing Competitor Price Scraping, Unwanted Transactions, B...
2016 Bad Bot Report: Quantifying the Risk and Economic Impact of Bad Bots
Field Guide for Validating Premium Ad Inventory
Tune in for the Ultimate WAF Torture Test: Bots Attack!
easyjet’s journey to protect its booking engine - the slides for the Tnooz / ...
Β 
Presentation - How to do Fraud like Vietnamese

What's hot (13)

PDF
Rtp rsp16-distil networks-final-deck
PDF
Ias guide ad fraud essentials_2017 (1)
PDF
StubHub's Field Guide To Preventing Competitor Price Scraping, Unwanted Trans...
PPTX
Digital ad fraud superheroes the good guys by augustine fou
PPTX
Bp Corp Pres Short
PDF
ComplianceBrief
PPTX
How to find a legal network marketting company
PDF
IAB Best Practices Traffic Fraud Final
PDF
The Wrong Impression | Adfraud
PPTX
Identity theft pp presentation
PPTX
How the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem
PDF
How bots impact major onsales [Webinar]
PPTX
Fraud in digital advertising industry
Rtp rsp16-distil networks-final-deck
Ias guide ad fraud essentials_2017 (1)
StubHub's Field Guide To Preventing Competitor Price Scraping, Unwanted Trans...
Digital ad fraud superheroes the good guys by augustine fou
Bp Corp Pres Short
ComplianceBrief
How to find a legal network marketting company
IAB Best Practices Traffic Fraud Final
The Wrong Impression | Adfraud
Identity theft pp presentation
How the BOTS Act Impacts Premium Onsales and the Ticketing Industry Ecosystem
How bots impact major onsales [Webinar]
Fraud in digital advertising industry
Ad

Viewers also liked (20)

DOCX
Property Portal Watch Conference Agenda - AMS 2015
PDF
Inventing a Niche - Bankruptcy Listings
PDF
Attacking in an Emerging Market - Lessons from the Ukraine - Presentation by ...
PDF
Consumer Insights - Presentation at the Property Portal Watch Conference - AM...
PDF
Using Big data to Create New Business Opportunities - Presentation by Hemnet ...
PDF
Using Social Media to Market Houses
PPTX
Day 2: Georg Chmiel
PPTX
Day 2: Alberto Santos Estevez - Urban Data Analytics
PDF
Draft property portal watch conference agenda nyc 2016 - version 4
PDF
HouseLens Promo
PDF
Opportunties Created by the Greek Crisis - Presentation by xe.gr at the Prope...
DOCX
Property Portal Watch Conference NYC 2016 Final Agenda
PDF
Building Real Estate Market Indices for the Brazilian Market
PDF
ListGlobally Promo
PPTX
Changing Nature of the Online Real Estate Market and Who to Watch and Learn From
PDF
Attacking in an Emerging Marketing - Lessons from the Ukraine
PDF
Horizontals Versus Verticals – Who Wins
PPTX
RoofRing Revenue Model Analysis
PPTX
Making Use of Big Data
PDF
Portal watch may 2015 final
Property Portal Watch Conference Agenda - AMS 2015
Inventing a Niche - Bankruptcy Listings
Attacking in an Emerging Market - Lessons from the Ukraine - Presentation by ...
Consumer Insights - Presentation at the Property Portal Watch Conference - AM...
Using Big data to Create New Business Opportunities - Presentation by Hemnet ...
Using Social Media to Market Houses
Day 2: Georg Chmiel
Day 2: Alberto Santos Estevez - Urban Data Analytics
Draft property portal watch conference agenda nyc 2016 - version 4
HouseLens Promo
Opportunties Created by the Greek Crisis - Presentation by xe.gr at the Prope...
Property Portal Watch Conference NYC 2016 Final Agenda
Building Real Estate Market Indices for the Brazilian Market
ListGlobally Promo
Changing Nature of the Online Real Estate Market and Who to Watch and Learn From
Attacking in an Emerging Marketing - Lessons from the Ukraine
Horizontals Versus Verticals – Who Wins
RoofRing Revenue Model Analysis
Making Use of Big Data
Portal watch may 2015 final
Ad

Similar to Case Study on Property Portal Data Security (8)

PPTX
Are Bot Operators Eating Your Lunch?
PPTX
Cleaning up website traffic from bots & spammers
PPTX
How to clean up travel website traffic from bots and spammers?
Β 
PDF
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
PPTX
Ensuring Property Portal Listing Data Security
PPTX
Are Bad Bots Destroying Your Conversion Rate and Costing You Money?
PDF
Distil Networks Protecting the Telephony Industry
PDF
HTTP Brute Force Mitigation Playbook Bot Profile for Brute Force Mitigations ...
Are Bot Operators Eating Your Lunch?
Cleaning up website traffic from bots & spammers
How to clean up travel website traffic from bots and spammers?
Β 
Distil Network Sponsor Presentation at the Property Portal Watch Conference -...
Ensuring Property Portal Listing Data Security
Are Bad Bots Destroying Your Conversion Rate and Costing You Money?
Distil Networks Protecting the Telephony Industry
HTTP Brute Force Mitigation Playbook Bot Profile for Brute Force Mitigations ...

More from Property Portal Watch (11)

PDF
Ingatlan - Market Leader in Hungary - Presentation by Ingatlan at the Propert...
PDF
8 Property Portals to Watch and Learn From - Presentation by Simon Baker at t...
PDF
Creating a Global MLS for New Developments - Presentation by Investorist at t...
PDF
Making Your Listings Social Proof - Presentation by Placeit at the Property P...
PDF
Using New Technology to Create a Better Consumer Experience - Presentation by...
PDF
Growing Importance of Business Intelligence on Property Portal Growth - Prese...
PDF
Challenges and Opportunities for the Online Marketing of Commercial Property ...
PDF
Floorplanner Sponsor Presentation at the Property Portal Watch Conference - A...
PDF
RENT Sponsor Presentation at the Property Portal Watch Conference - AMS 2015
PDF
Ubiflow Sponsor Presentation at the Property Portal Watch Conference - AMS 2015
PDF
Global Trends in the Property Portal Industry - Presentation at the Property ...
Ingatlan - Market Leader in Hungary - Presentation by Ingatlan at the Propert...
8 Property Portals to Watch and Learn From - Presentation by Simon Baker at t...
Creating a Global MLS for New Developments - Presentation by Investorist at t...
Making Your Listings Social Proof - Presentation by Placeit at the Property P...
Using New Technology to Create a Better Consumer Experience - Presentation by...
Growing Importance of Business Intelligence on Property Portal Growth - Prese...
Challenges and Opportunities for the Online Marketing of Commercial Property ...
Floorplanner Sponsor Presentation at the Property Portal Watch Conference - A...
RENT Sponsor Presentation at the Property Portal Watch Conference - AMS 2015
Ubiflow Sponsor Presentation at the Property Portal Watch Conference - AMS 2015
Global Trends in the Property Portal Industry - Presentation at the Property ...

Recently uploaded (20)

PDF
Sims 4 Historia para lo sims 4 para jugar
PDF
Slides PDF The World Game (s) Eco Economic Epochs.pdf
PPTX
E -tech empowerment technologies PowerPoint
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
Β 
PPTX
Power Point - Lesson 3_2.pptx grad school presentation
Β 
PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PPTX
Funds Management Learning Material for Beg
PDF
How to Ensure Data Integrity During Shopify Migration_ Best Practices for Sec...
PPTX
artificial intelligence overview of it and more
PPT
tcp ip networks nd ip layering assotred slides
PPTX
Module 1 - Cyber Law and Ethics 101.pptx
PDF
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PPTX
innovation process that make everything different.pptx
PPT
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
PDF
Paper PDF World Game (s) Great Redesign.pdf
PPTX
INTERNET------BASICS-------UPDATED PPT PRESENTATION
PPTX
522797556-Unit-2-Temperature-measurement-1-1.pptx
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PPTX
international classification of diseases ICD-10 review PPT.pptx
Sims 4 Historia para lo sims 4 para jugar
Slides PDF The World Game (s) Eco Economic Epochs.pdf
E -tech empowerment technologies PowerPoint
RPKI Status Update, presented by Makito Lay at IDNOG 10
Β 
Power Point - Lesson 3_2.pptx grad school presentation
Β 
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
Funds Management Learning Material for Beg
How to Ensure Data Integrity During Shopify Migration_ Best Practices for Sec...
artificial intelligence overview of it and more
tcp ip networks nd ip layering assotred slides
Module 1 - Cyber Law and Ethics 101.pptx
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
SASE Traffic Flow - ZTNA Connector-1.pdf
innovation process that make everything different.pptx
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
Paper PDF World Game (s) Great Redesign.pdf
INTERNET------BASICS-------UPDATED PPT PRESENTATION
522797556-Unit-2-Temperature-measurement-1-1.pptx
Job_Card_System_Styled_lorem_ipsum_.pptx
international classification of diseases ICD-10 review PPT.pptx

Case Study on Property Portal Data Security

  • 3. The New Threat Landscape of APBs Advanced Persistent Bots (APBs)... Advanced Mimick human behavior Load JavaScript Load external resources Support cookies Browser automation (Selenium, PhantomJS) Persistent Dynamic IP rotation Distribute attacks across IP addresses Hide behind anonymous and peer-to-peer proxies 2015 Distil Bad Bot Report
  • 4. Homegrown Solutions Are Ineffective Creates a poor user experience Bots appear human in logs Defeated by distributed IP attacks Defeated by advanced bots Labor intensive Defeated by low and slow crawlers Defeated by CAPTCHA farms Distributed attacks hard to pinpoint Defeated by peer-to-peer / proxies Reduces conversions by up to 27% Reactive in nature Reactive in nature
  • 5. Web App Security Requires Complementary Solutions l DDoS Mitigation Firewall WAF Distil Bot Protection Core Competency Volumetric attacks on infrastructure Network layer attacks Application coding exploits Automated abuse, misuse, and attacks (scraping, fraud, account takeover, etc.) Techniques Scrubbing centers, Large pipes Access Control Lists (ACLs), Rules-Based App layer understanding, ACLs, Rules-Based Real-time Analysis, Fingerprinting, Honeypotting, Machine learning, Behavioral modeling
  • 6. Survey Respondents 100 real estate executives representing over 600,000 realtors 14 real estate portal operators running 400,000 real estate websites 2015 Real Estate Web Scraping Survey
  • 7. β—‹ 50% - 75% of bot traffic is from Consumer ISPs β—‹ 7 of top 10 sources of bad bots are Consumer ISPs β—‹ Most Consumer ISPs had 1,500+ IPs with bots Highlights of Bot Sources on Real Estate Websites The Facts on Scraping Real Estate Data Top 7 Consumer ISPs with Bot Traffic 1 Comcast 2 Time Warner Cable 3 Verizon FIOS 4 Charter 5 Cox 6 CenturyLink 7 AT&T Uverse Highlights of Bot Sophistication β—‹ 18-45% Automated browsers - mimicking humans β—‹ 14-25% Already in bot database - fingerprinted, known bots β—‹ 16-42% Slow crawlers - recycling IPs and user agents
  • 8. About Lamudi 30+ Countries 900,000+ Listings 660+ Employees Property portal focused exclusively on emerging markets
  • 9. Lamudi Bad Bot Challenges Bad Bot Challenges Bad guys scraped listing data to duplicate listings, impact SEO, and compete w/Lamudi Bots are spamming listing agent/owner contact forms & reducing agent retention & satisfaction 15,000 bad bot requests per minute (15x human traffic) caused slowdowns WAF-based IP blocking system used enginering time and was ineffective
  • 10. Lamudi Selection Criteria Bot Detection and Mitigation Solution Requirements Support a complex deployment across several AWS instances with Akamai Block web scrapers and spammers without impacting human visitors Accurately identify good bots vs. bad bots Increase website availability and speed Detect automated browsing tools Simple setup for 30+ domains Little or no maintenance, β€œself-optimizing” solution
  • 11. Lamudi Results with Distil Results with ROI No more scraping data β†’ unique listings = better SEO No more form spam to agents β†’ higher value leads = $$ Less time addressing agent complaints β†’ Rev. Retention = $$ Increased website performance β†’ Faster site = better SEO Save 100 engineering hours/mo. β†’ More resources! Save $$ β€œDistil is the best anti-bot and anti-scraper protection solution available, hands down.” Oliver Fiege, CTO, Lamudi
  • 12. How the Distil Bot Detection Solution Works As web traffic passes through Distil, the system 1. Fingerprints each incoming connection and compares it to our Known Violators Database 1. If it’s a new fingerprint, validates the browser to determine if it’s a Bot or Not 1. β€œNo Silver Bullet” - Distil randomizes a battery of challenges to find bots and remain spoof- proof from the bot coders 1. Based on your settings, Distil automatically tags, challenges, or blocks the bot
  • 13. Sticky Bot Tracking With No Impact On Real Users Device Fingerprinting Fingerprints stick to the bot even if it attempts to reconnect from random IP addresses or hide behind an anonymous proxy or peer-to-peer network Tracks distributed attacks that would normally fly under the radar Without Distil With Distil Without Impacting Users Sharing the Same IP Avoids blocking residential users or organizations that might share the same NAT as the bot or botnet
  • 14. Browser Validation Detects all known browser automation tools, such as Selenium and Phantom JS Protects against browser spoofing by validating each incoming request as self reported Advanced Bot Detection Increases Accuracy Behavioral Modeling and Machine Learning Machine-learning algorithms pinpoint behavioral anomalies specific to your site’s unique traffic patterns Self optimizing algorithms improve bot detection and mitigation without manual configuration
  • 15. Awards and Analyst Recognition β€œAnalyzing behavior provides the best chance of detecting and blocking bot- driven attacks.” 5 Stars across the board.β€œ Verdict: For monitoring the impact of bots on a network this is the tool one needs.” The only anti-bot solution to be included in Gartner’s Online Fraud Detection Market Guide Ovum puts Distil Networks On The Radar. β€œClear innovation compared to similar services.”
  • 16. www.distilnetworks.com QUESTIONS….COMMENTS? C H A R L I E @ D I S T I L N E T W O R K S . C O M 1.703.962.1614 OR CALL CHARLIE ON