Detecting Bot Traffic: What Your Logs Reveal
Unusual bot activity detected in traffic logs as AI crawlers shift to POST requests, according to Akamai.
Unusual Bot Activity Detected in Traffic Logs
Akamai has observed verified AI-driven bots, including ChatGPT, transitioning from passive web page scanning to executing high-frequency POST requests. A 30-day analysis of its global client base revealed that e-commerce platforms accounted for 44.8% of these AI bot-generated POST transactions, while the travel sector saw a 30% increase in such activity within a single month.
POST Requests vs. GET Requests
POST requests differ from GET requests in that they instruct servers to perform actions such as user authentication, cart additions, or checkout completions. This shift places AI bots in direct interaction with the transactional mechanisms used by online retailers and travel services.
Expanding Attack Surface
The expansion of AI adoption and the proliferation of APIs have broadened the potential attack surface, according to Akamai. When questioned about the specific actions associated with these POST requests, Steve Winterfeld, Akamai’s Advisory CISO, noted that the range of transaction types is growing. Verified AI crawlers are increasingly engaging in non-GET activities, such as training processes and data searches.
Differentiating Legitimate AI Agents from Malicious Bots
Ryan Gao, head of Akamai Threat Intelligence Services, outlined methods for identifying genuine AI shopping agents versus deceptive bots. These include combining generative engine optimization (GEO) with specialized bot tracking, monitoring shifts in transactional behavior (e.g., GET vs. POST patterns), and employing adaptive behavioral analytics to detect evasion tactics.
Methods for Identification
These strategies must evolve alongside emerging threats. The Model Context Protocol (MCP), which enables AI models to connect with external databases, code, and APIs, has become a focal point. MCP traffic represented 4.1% of AI bot POST transactions in Akamai’s 30-day dataset. The company has implemented a rule to track MCP traffic across its protected systems.
Detected Vulnerabilities
When asked about detected vulnerabilities, Gao highlighted the risks of unauthenticated MCP endpoints, including potential exposure of personally identifiable information (PII) and the emergence of unsanctioned services.
Confidential Findings from AI Security Testing
Akamai participated in Anthropic’s Project Glasswing, gaining early access to the Mythos model to identify critical software vulnerabilities. However, details about specific findings, their severity, and resolution timelines remain undisclosed due to confidentiality agreements.
Project Glasswing and Mythos Model
Winterfeld emphasized that while the data is not public, Akamai continues to address vulnerabilities proactively. Boaz Gelbord, Akamai’s chief security officer, stated that the company is testing critical code components to uncover previously unknown flaws. He stressed the need for enterprises to reassess security strategies in light of evolving AI-driven threats.
Proactive Vulnerability Management
Akamai argues that AI can significantly accelerate vulnerability detection, but patch cycles often lag, leaving systems exposed. Until updates are deployed, the firm recommends runtime protection, edge controls, or network segmentation to mitigate risks.
Additional Security Considerations
The growing reliance on AI agents has introduced new challenges, including the potential for tool poisoning and cross-server attacks. Akamai’s analysis underscores the importance of proactive measures to safeguard infrastructure against unauthorized access. As AI technologies continue to mature, organizations must adapt their security postures to address emerging threats.
“Retailers are advised to prioritize AI bot visibility and implement robust security frameworks to manage risks while optimizing user experiences for Answer Engine Optimization (AEO) and Generative Engine Optimization (GEO), particularly as the holiday season approaches.”
“The company has implemented a rule to track MCP traffic across its protected systems.”
“Until updates are deployed, the firm recommends runtime protection, edge controls, or network segmentation to mitigate risks.”
