Website Security & Threat Management
Application security: Cloudflare’s view

Application security: Cloudflare’s view

3/21/2022 · Michael Tremante, Sabina Zejnilovic, David Belson

What this post added

This post provides a data-driven overview of application security trends observed on the Cloudflare network between December 2021 and March 2022. It quantifies the volume of mitigated traffic (8% of total HTTP requests), breaking down mitigation sources by feature (Layer 7 DDoS, Custom WAF Rules, Rate Limiting, IP Threat Reputation, Managed WAF Rules). It details the most common attack vectors blocked by Managed WAF Rules, with HTTP anomalies being the most prevalent. The post also analyzes the fields used in custom WAF rules, highlighting the continued prevalence of IP addresses and standard HTTP request fields, while noting the shift towards Zero Trust approaches.

Read the original post ↗