Shielding Ticketing and Reservation Platforms from AI Bot Attacks
An international airline and its sister hotel-booking platform faced a surge of AI-driven bots that distorted demand data, hoarded inventory, hijacked loyalty accounts, and jeopardized compliance with PCI DSS, IATA NDC, and regional privacy laws.
The engagement started with a proof of concept in detect-only mode, instrumenting VisitorTag across search and booking flows to baseline human vs. bot behavior. AccuBot then generated policy recommendations, including rate-limit thresholds, challenge triggers, crawler permissions, and a WAF Rule Advisory, which were reviewed with the client’s infrastructure team.
Selected controls were implemented by the client on their CDN/WAF, while IntelliFend policies were activated gradually (monitor → challenge → block) within our enforcement layer. Throughout, Push Log was used to track each change and its impact, and thresholds were fine-tuned in real time based on live telemetry.
Shielding Ticketing and Reservation Platforms from AI Bot Attacks Read More »
