Models & LabsUnited States

​Steelian Blocks AI Agent-Based Web Attacks in In-House Tests

Credited to TheElec · thelec.net

Useful

Steelian announced on Oct. 6 that it successfully blocked attacks in its in-house tests where artificial intelligence agents identified website APIs and automatically operated browsers. The company also stated that it defended against credential-stuffing attacks, which use stolen account credentials to gain unauthorized access to other services.

​The tests utilized WebSuit, Steelian's AI-based web security solution. The system blocked both API reconnaissance using the command-line tool cURL and access via the browser automation tool Playwright. Steelian noted that these tests were modeled after actual attacks recently observed in the financial sector.

​WebSuit randomizes the API addresses used during communications between websites and servers, while encrypting the data exchanged between them. These measures are designed to prevent attackers from inspecting communications and mimicking requests. The server accepts a request only after verifying that it contains a valid authentication token and that the data remains unaltered.

​To counter AI agent attacks, Steelian applied AI behavior analysis and proof-of-work (PoW) challenges. The system analyzes user behavior—including mouse movements, clicks, inputs, and scrolling—alongside the browser execution environment to distinguish human users from automated programs. Suspicious requests are required to solve computational problems before being accepted, an approach intended to increase the time and resources required by attackers.

​WebSuit mitigates credential stuffing through token verification and automation detection technologies. Depending on the customer's environment, these technologies can be applied in stages ranging from monitoring to verification and blocking, according to the company.

​"To effectively respond to AI agent attacks, we must verify defensive measures at every stage, from exploring the service structure to executing requests," said Kim Byung-chul, head of Steelian's solutions business division. "Based on research and validation from an attacker's perspective, we will continue to advance web and API protection technologies that customers can readily apply to real-world services."

Original · TheElec

FrontMethod