how shape connect works connec… · of your website’s origin 1. all requests are proxied through...

2
How Shape Connect Works connect.shapesecurity.com 1 2 yourdomain.com Dedicated Connect IP Request Connect Admin Console Response Origin Server 5 cloud 4 Advanced Aack Protecon Autoscaling Secure CDN DDoS Protection 3 Application Control DNS returns your dedicated Connect IP instead of the IP address of your website’s origin 1. All requests are proxied through Connect: responses cached in CDN are returned immediately 2. Connect cloud absorbs even the largest infrastructure DDoS attacks 3. Connect detects if a request was automated. If malicious, Connect blocks the attack. 4. Your website’s origin responds only to valid requests from your actual users 5. With Connect DNS Cached Response DNS 1 2 3 4 yourdomain.com Origin IP Request Response There’s nothing between your website and your user’s browser... ...but what if it’s not a user behind the browser? ! Origin Server Browser queries DNS using your website’s domain 1. DNS returns the IP address of your website’s origin server to the browser 2. Browser sends a request directly to your website’s origin server using its IP address 3. Your website’s origin server returns a response to the browser 4. Without Connect Easy to Setup Step 1 Sign up on connect.shapesecurity.com Step 2 Receive email with dedicated IP address Step 3 Change DNS settings Step 4 Monitor clean traffic via your dashboard

Upload: others

Post on 13-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: How Shape Connect Works Connec… · of your website’s origin 1. All requests are proxied through Connect: responses cached in CDN are returned immediately 2. Connect cloud absorbs

How Shape Connect Worksconnect.shapesecurity.com

1

2

yourdomain.comDedicated Connect IP

Request

ConnectAdmin Console

Response

Origin Server

5

cloud

4

Advanced Attack ProtectionAutoscaling

SecureCDN

DDoS Protection

3

Application Control

DNS returns your dedicated Connect IP instead of the IP address of your website’s origin

1. All requests are proxied through Connect: responses cached in CDN are returned immediately

2. Connect cloud absorbs even the largest infrastructure DDoS attacks

3. Connect detects if a request was automated. If malicious, Connect blocks the attack.

4. Your website’s origin responds only to valid requests from your actual users

5.

With Connect

DNS

Cached Response

DNS

1 2

3

4

yourdomain.com Origin IP

Request

Response

There’s nothing between your website and your user’s browser...

...but what if it’s not a user behind the browser?

!

Origin Server

Browser queries DNS using your website’s domain

1. DNS returns the IP address of your website’s origin server to the browser

2. Browser sends a request directly to your website’s origin server using its IP address

3. Your website’s origin server returns a response to the browser

4.

Without Connect

Easy to SetupStep 1 Sign up on connect.shapesecurity.com

Step 2 Receive email with dedicated IP address

Step 3 Change DNS settings

Step 4 Monitor clean traffic via your dashboard

Page 2: How Shape Connect Works Connec… · of your website’s origin 1. All requests are proxied through Connect: responses cached in CDN are returned immediately 2. Connect cloud absorbs

connect.shapesecurity.com

Use Casesconnect.shapesecurity.com

Account Takeover

Criminals use stolen usernames andpasswords from other data breaches, e.g., Yahoo or LinkedIn, to log in to your customers’ accounts. They then commit all types of fraud, from making unauthorized purchases with the stored credit card information to stealing reward points.

Connect stops fraudsters from rapidly testing stolen credentials on your login applications, which means they can’t take over accounts in the first place.

Competitive Scraping

Third parties use bots to scrape your websites for information on products and pricing without your permission. They then take this data, package it up, and resell it to competitors. Not only does this activity interfere with your ecommerce strategies, but it also can create a serious infrastructure burden and hamper with customer experience.

Connect blocks unwanted scrapers, allowing you to better predict both revenue and infrastructure costs.

Credit Card Chargebacks

We all know fraud is the cost of doing business, but if you are seeing an uptick in credit card chargebacks with generic fraud reason codes - 10.4 (Visa), 4387 (MasterCard), F29 (American Express), or UA02 (Discover) - bots might be to blame.

Connect prevents fraudsters from using automation to validate stolen credit cards on your checkout pages, which not only prevents fraud, but also reduces the number of transactions that have to undergo automatic or manual review.

Gift Card Attacks

Criminals take advantage of your gift card balance check / look-up features to identify gift card numbers with a positive balance. Once the fraudster identifies card numbers and associated PINs with positive balances, he uses or sells the gift card before the actual customer has had a chance to use it.

Connect prevents carding attacks, which rely on automation to succeed, ensuring that gift cards remain in your customers hands.

Inexplicable Spikes in Website Traffic

Your website traffic should follow a predictable pattern - peaking in the day during business hours, and declining at night when your customers are asleep. If you are experiencing spiky traffic that doesn’t map to marketing campaigns or your conversion rates are suddenly abysmal, it might be a case of artificial users.

Connect tells you exactly where users are coming from and whether they are fake or real. Plus, by preventing bots from adding items to carts and browsing your website, you will stop wasting your retargeting spend on them.

Slow Load Times

You have upgraded your web hosting, reduced image sizes, and implemented all of Google Analytics’ optimization recommendations. Yet customers are still complaining that your website is loading slowly and that they are having trouble logging in and checking out. It’s likely that you have an automation problem.

Connect identifies in real-time whether a visitor to your website is human or bot, and only allows good, wanted bots, like search crawlers, while preventing all malicious automation from interacting with your site.

Connect stops unwanted bots from accessing your website while allowing customersand good bots to go about their business.