Forum Moderators: open

Message Too Old, No Replies

Convincing IP spoofing / user simulation

Pointers to detection of IP spoofing

         

Simon_H

4:20 pm on Jan 9, 2016 (gmt 0)

10+ Year Member Top Contributors Of The Month



Hi guys. I need some expert advice as this isn't my area...

Let's say a third party wants to do a very convincing job of using bots to make it appear that real users are navigating an ecommerce site. So that would mean spoofing IPs of real users and ensuring navigation patterns resemble that of real users. The obvious problem is the bidirectional issue with IP spoofing, i.e. the spoofer sends requests, but won't get a response. For example, if the spoofer wants to post forms, e.g. add to basket, they're working blind.

So, to deal with this, could the spoofer initially hit the page / add to basket / etc from a non-spoofed IP address and note the response. They then do the same thing from the spoofed IPs and ensure it matches what happened on the non-spoofed one. They could then do this multiple times from multiple spoofed IPs and it would look convincing in the server logs. They would presumably need to re-hit the page from the non-spoofed IP every now and then to ensure nothing has changed.

Is this approach plausible to make the bot more convincing or have I missed something that would preclude this, e.g. protocol handshaking issues?

BTW, I'm asking this because I'm fairly sure based on our stats that we're being intermittently hit by bots that are spoofing IPs and simulating user behaviour.

JS_Harris

7:29 am on Jan 28, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Simon, I don't have a full answer for you but just wanted to point out that Google doesn't actually navigate around your site. They record and visit all URLs directly over time if I remember a Matt Cutts video correctly. ie: googlebot will load up a page or set of pages but it is not interacting with your links in the traditional sense, no clicking is happening.

Given that fact it's highly unlikely that googlebot could be adding items to your basket, it sounds like someone has changed the UA to appear like Google, or perhaps it's an actual Google employee/rater?

markt211

1:46 pm on May 10, 2016 (gmt 0)

5+ Year Member



Help! I'm on the receiving end of this "bot" that is creating accounts all over the world. It's using a name like "my.name@gmail.com", where my email address is "myname@gmail.com". I've gotten *dozens* of accounts signed up with my email address. I'll often log into them and change the email address to spam@gmail.com, but I have yet to figure out where it's coming from. I'm hoping some site will log the IP address of the originator but I never see that.

Any advice?
This 62 message thread spans 3 pages: 62