Akamai today unleashed several updates to its edge security platform that protect web applications, APIs, and user accounts from malicious human and bot activity and automates threat detection and response.

“We’re trying to help digital brands get out of the way of good users, while also protecting and supporting whatever flavor of attacker abuse they’re dealing with,” said Eric Graham, VP of product management for abuse and fraud protection products at Akamai.

The threats change daily, he added. “Whether it’s attacking the app and API, or its automations trying to scrape, scalp, hoard, stuff — whatever flavor bot attack you like. Or it’s malware extensions trying to hijack users, or it’s fraudsters trying to impersonate valid users, all of those are real-time decisions that our customers have to make.”

Akamai released four major updates to its Intelligent Edge platform that Graham said provides customers with the insights needed to make those decisions.

Account Protector

The first one, Account Protector, uses behavioral analytics to extend the Akamai Bot Manager service to also detect and prevent account takeover attacks by human threat actors in real time. “It is trying to help our customers recognize when the entity that’s presenting itself at login is, in fact, the authentic account holder, and conversely when it’s a fraudster trying to impersonate the authentic account holder,” Graham said.

Account Protector analyzes requests and generates a user-session risk score during authentication based on user behavior and population profiles, observes malicious activity across the network and IP, and Akamai’s own databases. It then generates risk and trust indicators to calculate the likelihood that a user is the legitimate account owner or an impersonator. “And based on that understanding, [customers can] either let the user interaction go, or adapt it and take action,” Graham explained.” Companies can choose from options such as allow, alert, or block the user.

Additionally, Account Protector provides both real-time and historical reporting on users’ behavioral activity, which can provide a better understanding of intent, and it uses machine learning to self-tunes as it analyzes subsequent logins for the same set of credentials.

Adaptive Security Engine

The second update, an Adaptive Security Engine for Akamai’s web application and API protection (WAAP), combines proprietary anomaly risk scoring with adaptive threat profiling to identify highly targeted attacks. It also self-tunes using machine learning and statistical models to analyze all triggers across each policy to accurately differentiate between true and false positives.

Graham describes it as a “next-generation” WAAP that makes securing web apps and APIs easy. “We view this as the foundational protection asset for the modern, web-facing brand,” he said. “If you’re going to put a digital business online that’s fundamentally an app or an API, you need to defend it from malicious attacks, and you need to do that at the pace that the adversary is innovating. That means it has to be current, every day.”

Akamai Bot Manager Gets a Bot Score

The third update adds Bot Score and JavaScript Obfuscation to Akamai Bot Manager, which lets companies take action against bots. Bot Score automatically learns unique traffic and bot patterns, and self-tunes. It continues the move toward threat-scoring and self-tuning that’s already in the other Akamai platform updates, Graham said. “That pattern is really important, and Bot Score is that pattern brought to the battle of the bots,” he explained. “It gets the individual web defenders out of the burden of managing individual rules and techniques and tactics, and instead puts them in a world where they’re saying, ‘I want to mitigate in this range.’”

Instead of manually mitigating every bot action, this lets security teams write policies to automatically take a set action for bot activity depending on its score.

Additionally, JavaScript Obfuscation dynamically changes detections to prevent bot operators from reverse engineering detections.

Audience Hijacking Protection

And finally, Akamai added Audience Hijacking Protection to its Page Integrity Manager to detect and block malicious activity in real time from client-side attacks using JavaScript, advertiser networks, browser plug-ins, and extensions that target web clients. This new capability uses machine learning to identify vulnerable resources, detect suspicious behavior, and block unwanted ads, pop-ups, affiliate fraud, and other malicious activities.

The security updates come a day after Akamai released a new version of its EdgeWorkers serverless edge compute platform. Updates include new resource tiers for developers deploying code at the edge that package CPU and memory with commensurate pricing options, a distributed key-value store that accelerates database functions for edge applications, and API acceleration using special-purpose hardware, reserved capacity, and prioritized routing.