Website Security & Threat Management
Holistic web protection: industry recognition for a prolific 2020

Holistic web protection: industry recognition for a prolific 2020

1/14/2021 · Patrick R. Donahue

What this post added

This post details several advancements in Cloudflare's web security offerings during 2020, focusing on WAF, Bot Management, and DDoS mitigation. Key technical contributions include: - WAF: Decoupling configuration from the zone/domain model for granular control, introduction of IP Lists for rule creation, upgrade of edge-logging framework for real-time security logs to SIEMs, encryption of sensitive log payloads using HPKE, and the Data Localization Suite. A new Rate Limiting engine implemented in Rust for performance and memory safety, with added HMAC functions and regex-based HTTP header/body inspection. - Bot Management: Complete rewrite of the Machine Learning engine with an increased number of features, enhanced behavioral analysis engine with histogram-based outlier scoring, development of a lightweight JavaScript element for browser fingerprinting and User Agent misrepresentation detection, and a rewrite of the CAPTCHA challenge platform. Introduction of dedicated Bot Management analytics. Deprecation of the __cfduid cookie.

Read the original post ↗