Slide 18 of 28
Part 4 · PreventionSlide 18
PART 4
Prevention
Slides 18–26 · Seven mitigations + the full picture
Slide 18 · Prevention Overview
Seven ways to protect sensitive business flows.
Business rules. Verification gates. Bot detection. All enforced at the API.
🔢
MIT 01 — Server-Side Business Flow Limits
Purchase caps, cart limits, and action quotas enforced in the API — not the UI. Per account, per identity.
⏱️
MIT 02 — Cart and Reservation Timeouts
Inventory held in a cart is released after a short window (5–15 minutes). Prevents indefinite hold-and-abandon tactics.
🧬
MIT 03 — Device Fingerprinting and Bot Detection
Identify bot clients by behavioral signals: missing browser APIs, unrealistic mouse patterns, headless browser indicators.
🤖
MIT 04 — CAPTCHA on Sensitive Flow Steps
Challenge-response verification at high-value steps: checkout, account creation, referral redemption. Not at every step — only where abuse is likely.
MIT 05 — Human-Speed Pattern Detection
Flag flows completed faster than humanly possible. A checkout completed in 300ms has no legitimate human explanation.
📞
MIT 06 — Identity Verification Gates
Require phone or email verification before high-value flows. Each real person has a finite number of phone numbers; bot operators can’t scale infinitely.
🚨
MIT 07 — Business Metric Monitoring
Monitor inventory depletion rate, referral redemption velocity, and account creation spikes. Security logs don’t reveal API6 — business metrics do.
← Back MIT 01: Business flow limits →