Back to articles
Technology Insight

Mitigating Bad Bots: Building an Automated Scraping Protection System with CrowdSec and OpenResty

May 30, 2026

The Escalating Threat of Automated Scrapers and Bad Bots

In the modern digital economy, data has become one of the most valuable corporate assets. However, this value has also made enterprise web applications the prime target of automated scraping campaigns. While legitimate bots like search engine crawlers provide immense SEO value, “Bad Bots” account for a massive percentage of global web traffic, causing severe operational disruptions.

Uncontrolled data scraping leads to several critical business challenges:

  • Infrastructure Degradation: Aggressive scraping scripts can saturate bandwidth, spike CPU utilization, and cause application downtime.
  • Intellectual Property Theft: Competitors can systematically harvest proprietary pricing models, product descriptions, and unique content datasets.
  • Data Skewing: Automated traffic pollutes marketing analytics, leading to inaccurate business intelligence and flawed decision-making.

Standard rate-limiting tools often fall short against sophisticated modern scrapers that leverage distributed residential proxies. To effectively combat this, modern infrastructure requires an adaptive, real-time, and collaborative security architecture. By combining OpenResty and CrowdSec, enterprises can deploy a highly scalable, crowd-sourced defense system capable of stopping malicious bots directly at the network edge.


Architectural Overview: Why OpenResty and CrowdSec?

Traditional Web Application Firewalls (WAFs) can be resource-intensive and complex to manage. A combined OpenResty and CrowdSec architecture solves this by separating high-performance traffic handling from intelligent threat evaluation.

OpenResty: The High-Performance Edge Gatekeeper

OpenResty is a full-fledged web platform that integrates the standard Nginx core with enhanced LuaJIT capabilities. This allows developers to inject custom Lua scripts directly into the Nginx request-processing lifecycle. Because it runs asynchronously at the edge, OpenResty can evaluate, log, or block incoming requests with sub-millisecond latency, making it the perfect enforcement point for bot mitigation.

CrowdSec: The Cyber-Security Revolution

CrowdSec is a modern, open-source, and lightweight threat intelligence engine. Unlike legacy static firewalls, CrowdSec analyzes application logs locally using declarative YAML scenarios to detect anomalous behaviors—such as aggressive scraping, brute-force attacks, or layer-7 DDoS.

Crucially, CrowdSec operates on a collaborative model. When an instance detects a malicious IP, that threat intelligence is anonymized and shared globally across the entire CrowdSec network. This ensures your infrastructure is proactively protected against bad bots before they ever target your specific servers.


Step-by-Step Integration: Turning Telemetry into Defense

Building an automated protection system requires setting up a continuous feedback loop: OpenResty handles the traffic and generates logs, the CrowdSec Agent analyzes those logs for bad bot behavior, and an OpenResty Remediation Component (Bouncer) drops the connection if a threat is validated.

1. Deploying the CrowdSec Security Engine

The first step involves installing the CrowdSec agent on your server layer. Once installed, CrowdSec automatically detects existing log files and configures the appropriate collection parsers. To specifically target data scrapers, administrators can install specialized bot-detection collections from the CrowdSec Hub:

cscli collections install crowdsecurity/http-cve
cscli collections install crowdsecurity/base-http-scenarios

These scenarios continuously monitor HTTP request patterns, looking for high-frequency traversal, missing or spoofed User-Agents, and non-standard behavioral anomalies.

2. Configuring OpenResty as the Log Provider

For CrowdSec to detect malicious behavior, OpenResty must generate structured telemetry. Configuring Nginx to output logs in a clean JSON format ensures optimal parsing performance and minimizes CPU overhead:

log_format crowdsec_json escape=json '{"time_local":"$time_local","remote_addr":"$remote_addr","request":"$request","status": "$status","body_bytes_sent":"$body_bytes_sent","http_referer":"$http_referer","http_user_agent":"$http_user_agent","http_x_forwarded_for":"$http_x_forwarded_for"}';
access_log /var/log/nginx/access_json.log crowdsec_json;

The CrowdSec daemon tracks this log file in real-time. If a specific IP triggers a threshold—for instance, requesting 200 distinct product pages within 5 seconds—CrowdSec instantly registers a new alert and generates a local decisions block.

3. Installing the OpenResty Lua Remediation Component

To enforce the decisions made by the CrowdSec engine, we utilize the official CrowdSec Lua Bouncer within OpenResty. This plugin hooks into the Nginx access_by_lua phase. When a new request arrives, the Lua script executes a non-blocking lookup against a local memory cache (using OpenResty's lua_shared_dict) to check if the incoming IP address is flagged as a bad bot.

If the IP is clean, the request passes through seamlessly with zero perceptible delay. If the IP is blacklisted, the bouncer immediately rejects the request, returning a 403 Forbidden or a customizable CAPTCHA challenge page to verify legitimacy.


Key Benefits of the Combined Architecture

Implementing this unified defense paradigm offers several distinct advantages for enterprise environments:

  • Sub-Millisecond Enforcement: By utilizing OpenResty’s shared memory zones, IP lookups happen completely in-memory. This prevents the security layer from becoming a performance bottleneck.
  • Proactive, Crowd-Sourced Threat Intel: Your system doesn't just learn from your own traffic. It automatically inherits the collective intelligence of hundreds of thousands of servers worldwide, blocking known scraping networks out-of-the-box.
  • Resource Efficiency: The decoupled nature of CrowdSec ensures that heavy log analysis happens asynchronously, freeing up OpenResty to dedicate maximum system resources to serving legitimate users.
  • Flexible Remediation: Instead of flatly blocking traffic, organizations can configure adaptive responses, such as presenting CAPTCHAs, applying strict rate limiting, or sending alternative, dummy datasets to identified scrapers.

Conclusion: Future-Proofing Your Enterprise Against Bots

Data scraping tactics are becoming increasingly sophisticated, evolving far beyond simple curl scripts. Relying on outdated signature matching or basic rate-limiting is no longer sufficient to protect proprietary enterprise platforms.

By pairing the raw execution speed of OpenResty with the collaborative intelligence of CrowdSec, businesses can establish a resilient, self-healing security posture. This integration effectively mitigates the operational risks posed by bad bots, safeguarding corporate intellectual property, optimizing server expenditures, and ensuring a fast, dependable experience for legitimate customers.

Mitigating Bad Bots: Building an Automated Scraping Protection System with CrowdSec and OpenResty | DPTCloud