CrowdHandler’s Security Features
CrowdHandler offers optional security features focused on preventing queue bypassing, queue flooding and other fraudulent activity related to high-demand access management. These protections aim to provide an additional layer of security, but should not replace traditional web security solutions. Our security features include:
Firewall Rules
CrowdHandler allows setting firewall rules to:
- Block - End user met with block screen
- Ignore - End user treated as normal but rule overrides others
- Bypass - End user skips all waiting room queues
- Prioritize - End user moved to queue front
Rules can be based on individual IPs, IP ranges or countries using our IP databse.
IP Session Limiting
Limit the number of simultaneous sessions (tokens) allowed from a single IP address. Prevents queue flooding from a single source.
IP Intelligence
Screen all sessions against a database of known malicious IPs (TOR nodes, data centers, attackers). Connections from dangerous IPs can be immediately blocked.
Rule Recommendations
CrowdHandler recommends IP range block rules for repeat offenders or security risks detected through anomalous activity monitoring.
Anomaly Detection
Sessions are scored from 0-100% risk based on factors like:
- IP reputation
- Associated IP reputation
- Geolocation
- IP rotation
- User agent popularity
- User agent rotation
- Session length
- Velocity
- URL focus
- URL count
High risk scores can trigger instant IP blocks or be used to generate firewall rule recommendations when in "warning" mode.
Global Block List
Access to an aggregated blocklist of IP ranges/netblocks identified as generating anomalous activity across CrowdHandler's clients. Currently 600+ entries covering 200K+ IPs.
ReCaptcha
Waiting rooms integrate Google reCAPTCHA to require visitors confirm "I'm not a robot" before joining the queue. reCAPTCHA presents an image challenge if the visitor does not pass the initial checkbox. Only visitors completing the challenge can enter the queue. reCAPTCHA can be set to challenge users even when no queue present.
Device Fingerprinting
Generate a device fingerprint from IP, geo-location, agent and language data to prevent sessions (tokens) being shared across multiple devices.
Session Fingerprinting
Analyze and log or block sessions for anomalous activity based on factors like inconsistent IP, agent or language information which could indicate token sharing.
CrowdHandler's security features aim to provide an additional layer of protection for queue management solutions. Features help prevent unauthorized queue access, abuse and malicious activity through multiple detection and blocking mechanisms, but should be used to complement rather than replace traditional web security controls.