
3/21/2022 · Michael Tremante, Sabina Zejnilovic, David Belson
What this post added
This post provides a data-driven overview of application security trends observed on the Cloudflare network between December 2021 and March 2022. It quantifies the volume of mitigated traffic (8% of total HTTP requests), breaking down mitigation sources by feature (Layer 7 DDoS, Custom WAF Rules, Rate Limiting, IP Threat Reputation, Managed WAF Rules). It details the most common attack vectors blocked by Managed WAF Rules, with HTTP anomalies being the most prevalent. The post also analyzes the fields used in custom WAF rules, highlighting the continued prevalence of IP addresses and standard HTTP request fields, while noting the shift towards Zero Trust approaches.