인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

Akamai “Web Attack Manipulating Search Engine Rankings Discovered”

Google 우선 소스Published2016.01.14 17:41
Search engine ranking manipulation through attacks using SQL injection techniques
Damage to corporate profits and reputation


Akamai Korea identified a sophisticated Search Engine Optimization (SEO) attack using SQL Injection techniques on target websites and issued a related web security threat warning on the 14th. Websites infected with this attack distribute hidden HTML links that disrupt search engine bots and cause errors in page rankings.

Akamai announced that it analyzed data collected from the Akamai Intelligent Platform over a two-week period in the third quarter of 2015 to identify over 3,800 website attacks and 348 unique IP addresses involved in various attacks. Explaining that the findings revealed a significant number of websites had been compromised, the company stated that searching the internet for HTML links used in SEO attacks resulted in the discovery of hundreds of web applications containing malicious links.

It was reported that attacks manipulating search engine results were also discovered. When searching for combinations of commonly used words like 'Cheat' and 'Story,' an application called 'Cheating Stories' appeared on the first page of major search engines. Akamai reviewed Alexa Analytics and confirmed that the ranking of the 'Negative Stories' application had surged for three months.

SEO attacks involve the creation of a series of external links and the imitation of legitimate web content.
Impact on search algorithms


Search engines use specific algorithms to determine website page rankings and indexing, and the number of links sent to a web application and its reputation influence page rankings. SEO attacks generate a series of external links on the web that lead to stories of dishonesty and infidelity, mimicking legitimate web content and influencing search engine algorithms.

Stuart Skoly, Senior Vice President and General Manager of Akamai’s Security Business Unit, said, “Page Ranking Manipulation is an interesting business for attackers.” "If the attack is successful, it can damage the revenue and, above all, the reputation of many companies and organizations using the internet," he said.

SEO attackers are well aware of how search engines operate, so Akamai recommends the following security measures.

- Web application developers ensure that input validation is properly performed on all user-provided data to be used in backend database (DB) queries (Reference: https://www.owasp.org/index.php/Input_Validation_Cheat_Sheet).

- When generating SQL queries based on user-provided data, use only parameterized queries and 'prepared statements' (Reference: https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet).

Web application security managers implement a web application firewall configured to block SQL injection attacks. They consider profiling and monitoring the HTML response body format to check for significant changes, such as an increase in the number of web links.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
명세환 기자
명세환 기자