La Redoute Protects its Sites & Applications Against Malicious Traffic & Ensures GDPR Compliance

No more web scraping
No more account takeover attempts
GDPR compliance
DataDome
Table of contents
5 Jun, 2019
|
min

La Redoute was founded in 1837. Today, the La Redoute group serves more than 10 million customers in France and abroad, generates 90 percent of its turnover online, and has a significant presence in the United Kingdom, Belgium, Switzerland, Russia, Spain and Portugal.

La Redoute’s IT teams had always been aware that bots came to visit and scan their sites.

“Before DataDome was introduced, we were addressing the issue in incident response mode. For example, whenever we noticed that an automated scan was starting to have a serious impact on our infrastructure, or when the SOC’s analysis flagged the activity as being malicious, we would temporarily block the bot’s IP address,” says Dominique Capelle, IT Operations Manager, who leads a team in charge of information security among other responsibilities.

Even though the approach proved effective, two significant events prompted La Redoute’s teams to change their practices and start looking for an artificial intelligence-based solution for protection against automated traffic.

First, the number of bots has substantially increased over the past couple of years, resulting in ever more frequent alerts and constant interventions:

“We had more and more IPs to block, and we started to see attacks coming from several hundred different IPs simultaneously. We also had to deal with a host of new bots, each one more complex than the last,” says Capelle.

Secondly, the GDPR taking effect in 2018 prompted La Redoute to tighten its security policy and strengthen its capacity to protect customer data.

Before turning to specialized anti-bot software, La Redoute’s IT teams first tested a WAF-like solution, but the results were not convincing: “We did a proof of concept with one of the market-leading WAF solutions. Unfortunately, most of the bots attacking our sites were never detected by the solution, due to their complexity.”

The team concluded that it was necessary to look beyond manually managed access rules, which are typical of WAFs, and to rely on an artificial intelligence-based solution able to take up the challenge of modern bot complexity.

Recommended by several partners and market studies, and distinguished by the International Cybersecurity Forum as cybersecurity solution of the year, DataDome quickly stood out as the best choice for La Redoute’s teams.

“Working with DataDome’s integration team was critical to the project’s success. The team’s knowledge of bot traffic and its impact on our business provided real added value during the pre-sales and POC phase,” says Mr. Capelle.

DataDome’s artificial intelligence-powered solution was first installed on the Portuguese site. The pilot phase initially allowed the teams to measure and assess the solution’s impact on applications and customers: bot identification and analysis, response times, implementation and customization of rules … This phase was crucial for enabling everyone to become familiar with the solution, and helped reassure the teams that needed to test the solution in order to trust it completely.

The full deployment of the DataDome solution was subsequently completed in less than three weeks on all La Redoute sites and applications, just ahead of Black Friday, a commercial operation that attracts significant traffic.

DataDome integrates easily into applications without requiring major changes to their architecture, allowing for a simple, short implementation and progressive activation of the protection. In addition, we appreciate that the traffic to our sites isn’t diverted, which could have been an additional risk factor.
Dominique Capelle, IT Operations Manager at La Redoute

The Results: 100% of Bot Visits Processed Upon Entering La Redoute’s Sites & Applications

Before DataDome was installed on their servers, it took La Redoute’s team about an hour to block an attack. Front-end server logs must be analyzed by the SIEM system, an alert must be issued and action must be taken to block the bot activity. An hour can be very short … and also very long, when you consider the consequences such attacks may have on an e-commerce site of this size.

“Since the DataDome solution was deployed, we no longer see any malicious activity on our sites related to bot traffic. This type of activity is automatically mitigated with a Captcha page. Nevertheless, we continue to analyze the logs in our SIEM to verify that DataDome is 100% effective and so far, it’s been the case,” says Capelle.

He adds: “The precise identification, classification and referencing of the bots is quite amazing.”

DataDome
dd product home overview

Still exploring?

Start with an on-demand demo.