There are custom-built bots that use tools like CoreNLP. They tend to not use any framework.
But, most NLP-powered bots are using machine learning based NLP APIs rather than CoreNLP. These tend to do two functions: intent determination and slot detection.
Intent determination means finding the overall meaning of a message. Slot detection means locating and extracting important terms (not just standard NER) within a message. Both happen based on examples provided by training data that is used to train a machine learning model.
The difference intent determination and keyword-detection is that ML based intent determination is much more resistant to different ways of saying the same thing.
If you search the ML research for intent determination and slot filling you will find various techniques to do it, from CRFs to CNNs to RNNs.
Example:
"I want to find a flight from London to New York"
=> Intent: find_flight, City.Departure: London, City.Arrival: New York
That set of information will then be passed to program code to determine the response.
(generalization:)
Right now, most code will generally map intents and conversation state to a branch of code and will have code that takes specific action based on the current conversation state. Whenever slots are detected, those get stored to conversation state. As the user types each message, the process repeats.
The logic is generally either structured as a tree or as something that resembles a state machine.
Examples are Microsoft's Bot Framework, Wit.ai's SDK, Init.ai's conversation logic, etc.
(the future)
The machine learning model can be adapted to predict the next message type if it's trained on sequences of messages. At Init.ai we do that, where in addition to classifying the current message and extracting slots, the machine learning model predicts who (which person or computer) will send the next message and what type it will be. That enables the bot developer to not have to write code and let the prediction system select text to send as appropriate.
In the future you'll see other things that make it easier, where the machine learning system starts using more of the conversational content to make more accurate sophisticated predictions of what actions to take and messages to send. For example, some new ML research is around automatic question-answering based on a dataset, and that could be used to make bots respond automatically based on information.
So over time it will get easier for developers as the ML progresses.