{"id":4941,"date":"2026-03-31T17:13:37","date_gmt":"2026-03-31T15:13:37","guid":{"rendered":"https:\/\/oep.hypotheses.org\/?p=4941"},"modified":"2026-05-04T17:16:00","modified_gmt":"2026-05-04T15:16:00","slug":"spotlight-on-openedition-rolls-out-anubis-across-its-platforms","status":"publish","type":"post","link":"https:\/\/oep.hypotheses.org\/4941","title":{"rendered":"Spotlight on: OpenEdition rolls out Anubis across its platforms"},"content":{"rendered":"\n<p>In response to an increasing number of automated requests, OpenEdition, like several of its partners, has rolled out the open-source software program Anubis across all its platforms. OpenEdition System Administration manager Bruno C\u00e9nou talks about the data protection issues affecting an open science infrastructure like OpenEdition.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"https:\/\/oep.hypotheses.org\/files\/2026\/05\/1834213621_web.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"563\" src=\"https:\/\/oep.hypotheses.org\/files\/2026\/05\/1834213621_web.png\" alt=\"\" class=\"wp-image-4966\" srcset=\"https:\/\/oep.hypotheses.org\/files\/2026\/05\/1834213621_web.png 1000w, https:\/\/oep.hypotheses.org\/files\/2026\/05\/1834213621_web-300x169.png 300w, https:\/\/oep.hypotheses.org\/files\/2026\/05\/1834213621_web-500x282.png 500w, https:\/\/oep.hypotheses.org\/files\/2026\/05\/1834213621_web-768x432.png 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/a><figcaption class=\"wp-element-caption\">\u00a9 Krot_Studio \u2013 stock.adobe.com<\/figcaption><\/figure>\n<\/div>\n\n\n<ul class=\"wp-block-list\">\n<li>Anubis was rolled out following a cyber attack on the Calenda platform. What kind of attack was it? Is Calenda more exposed to this sort of attack than OpenEdition\u2019s other platforms?<\/li>\n<\/ul>\n\n\n\n<p>Using attack in the singular is an understatement for the wave of simultaneous requests sent from tens of thousands of different IP addresses, which ended up flooding our resources. The incident qualified as a DDoS (distributed denial of service attack). However, we weren\u2019t able to find out why it took place or who was behind it.<br>Calenda is more vulnerable to this type of issue as its search engine offers a wealth of possible filter combinations, resulting in tens of thousands of URLs for bots to crawl through.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Was it the first time this kind of attack took place? What are the risks associated with such attacks?<\/li>\n<\/ul>\n\n\n\n<p>Over the last two years, we have regularly been targeted by similar attacks, but the intensity and frequency have significantly increased over the last six months.<br>The main risk is that platforms become unavailable because our system resources are saturated.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What was the strategy applied previously to counter the rising number of illegitimate automated requests while ensuring continued open access to content?<\/li>\n<\/ul>\n\n\n\n<p>Until recently, our stance had been not to regard any automated request as illegitimate. All our open access content was available to any type of device. The different cache levels and the gradual scaling up of our system resources allowed us to handle this type of usage by expanding at a relatively reasonable pace.<br>However, over the last few months, we have come up against a form of extractivism that completely ignores the viability of the resources exploited.<br>The difficulty lies in the fact that most of the abusive automated requests we deal with are browser requests \u2013 with random user agents selected from those most commonly used \u2013&nbsp; sent from tens of thousands of different IP addresses. It is therefore almost impossible to differentiate between this type of traffic and human user traffic.<br>Before all of that, we used to be able to identify abusive IP ranges impersonating human traffic and trace them back to companies such as copyright trolls, which we would then blacklist.<br>Also, there was once an understanding that bots were supposed to identify themselves as such, via their user agent, and take account of robots.txt files, but that no longer holds at all.<br>The bottom line is that we now have to deal with two main categories of abusive requests:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Requests disguised as human searches, which we think are probably coming from scrapers installed on infected personal computers, with IPs generally linked to home internet service providers.<\/li>\n\n\n\n<li>Requests from AI scrapers, for training purposes, which identify themselves via their user agent and for which only part of the IP is available.<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What are the advantages of rolling out Anubis?<\/li>\n<\/ul>\n\n\n\n<p>Anubis is rolled out as a reverse proxy on our platforms. It reacts to requests by submitting a computational puzzle to the client browser\u2019s JavaScript engine. The puzzle takes a few seconds for regular browsers to solve and, if all goes well, the user barely notices the process. However, a bot that can\u2019t execute JavaScript or doesn\u2019t manage cookies will not pass the test and be prevented from accessing site content. This simple test denies entry to over 90% of automated requests disguised as human activity \u2013 it\u2019s simple and effective.<br>As for long-standing indexing engines and trustworthy partners, they don\u2019t have to pass the challenge. Filtering rules are clear and fully configurable to meet our needs.<br>The benefits are immediately apparent as the load imposed on our platforms has been reduced threefold.<br>We owe a big thank you to Anubis developer Xe Iaso, who generously explains <a href=\"https:\/\/www.youtube.com\/watch?v=Evs_e_-vh8A\">how Anubis works<\/a>.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Is it possible to tell the difference between requests from malicious bots and those from legitimate bots used to analyse corpora automatically on our platforms?<\/li>\n<\/ul>\n\n\n\n<p>I would call them pesky bots, as we don\u2019t know the intentions and interests that lie behind them.<br>We can, of course, identify bots belonging to partners or indexing engines thanks to their IP addresses and\/or user agents, and it\u2019s something we already do.<br>There\u2019s no denying that by setting up Anubis we\u2019re potentially refusing entry to numerous legitimate bots we don\u2019t know about, but for now, we deal with each case as and when.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Contact information<\/h2>\n\n\n\n<p>If you\u2019re having difficulty accessing our platforms because of Anubis, please let the OpenEdition Team know: contact[at]openedition[dot]org.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Good news<\/h2>\n\n\n\n<p>You\u2019ll soon be able to customize the page generated by Anubis when you connect to platform websites. We\u2019re working on it right now!<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>In response to an increasing number of automated requests, OpenEdition, like several of its partners, has rolled out the open-source software program Anubis across all its platforms. OpenEdition System Administration manager Bruno C\u00e9nou talks about the&#46;&#46;&#46;<\/p>\n","protected":false},"author":19802,"featured_media":4966,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_license":"CC-BY-4.0","publish_to_discourse":"","publish_post_category":"","wpdc_auto_publish_overridden":"","wpdc_topic_tags":"","wpdc_pin_topic":"","wpdc_pin_until":"","discourse_post_id":"","discourse_permalink":"","wpdc_publishing_response":"","wpdc_publishing_error":"","footnotes":""},"categories":[4,6562,133680,508105,2285634,130413],"tags":[],"ppma_author":[2494429,2494432],"class_list":["post-4941","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-calenda","category-hypotheses","category-openedition-platforms","category-openedition-books","category-openedition-journals","category-social-media"],"authors":[{"term_id":2494429,"user_id":0,"is_guest":1,"slug":"bruno-cenou","display_name":"Bruno C\u00e9nou","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=blank&r=g","1":"","2":"","3":"","4":"","5":"","6":"","7":"","8":""},{"term_id":2494432,"user_id":0,"is_guest":1,"slug":"christina-cantrel","display_name":"Christina Cantrel","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=blank&r=g","1":"","2":"","3":"","4":"","5":"","6":"","7":"","8":""}],"_links":{"self":[{"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/posts\/4941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/users\/19802"}],"replies":[{"embeddable":true,"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/comments?post=4941"}],"version-history":[{"count":7,"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/posts\/4941\/revisions"}],"predecessor-version":[{"id":4971,"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/posts\/4941\/revisions\/4971"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/media\/4966"}],"wp:attachment":[{"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/media?parent=4941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/categories?post=4941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/tags?post=4941"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/oep.hypotheses.org\/wp-json\/wp\/v2\/ppma_author?post=4941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}