Bot attacks severally damaging average session length

Reproduction Steps
We noticed bots going into one of the games I managed for a few days now, and ever since we first noticed the bots in the game our average session length has dropped dramatically.

We’ve done all we can to ensure that this is not due to any in-game bug (and it’s not…)

This is also occurring on several other games the studio owns, and games by other developers.

Our game: [NEW BOSS] 🧙‍♂️ Build to Survive Simulator - Roblox

Expected Behavior
Session length to be within the normal range for the game as it has been for months.

Actual Behavior
Session lengths dropped dramatically

Issue Area: Engine
Issue Type: Other
Impact: Very High
Frequency: Constantly
Date First Experienced: 2021-07-06 00:07:00 (+02:00)
Date Last Experienced: 2021-07-08 23:07:00 (+02:00)

8 Likes

This has severely impacted our game as well. We get a significant amount of players which should offset such attacks, yet we still see significant damage from this.

Our game: Warrior Cats: Ultimate Edition - Roblox

Our visit timeline clearly highlights a problem:

Here’s our average play time graph, where you can clearly map the damage to the spikes:

Our average visit length as a result:

1 Like

Roblox has been lacking in security for a while now and games on the platform are becoming more vulnerable to attacks.

I really hope Roblox is able to solve these security issues causing developers to loose out on play time, and therefore game expansion, and therefore profit.

Another long term security issue that has yet to be solved.
https://devforum.roblox.com/t/server-ddos-attacks-becoming-problematic/1072624
I would not be surprised if this bot issue takes a long time for it to be solved or is never solved at all.

I actually wrote a bot that is capable of getting IP addresses/ports for roblox game servers for education purposes.

Unfortunately, there is nothing much you can do other than a game hub solution. DDoS attacks are problematic worldwide, and generally people can save their servers with packet control services such as Cloudflare, which is not a solution in this case.

(This is just so Roblox admins could further identify how this problem is being exploited)