Website Security & Threat Management
Making Page Shield malicious code alerts more actionable

Making Page Shield malicious code alerts more actionable

7/5/2022 · Simon Wijckmans

What this post added

Introduced script status categorization (active, infrequent, inactive, cdn-cgi) to filter and prioritize scripts. Enhanced alert metadata for security analysts by integrating Cloudflare Radar insights, breaking down ML classifier scores (obfuscation, data exfiltration), displaying threat feed categorization, and including script change history. Added WHOIS information and SSL certificate transparency data to alerts for further validation. Improved dashboard linking to specific script details pages. Future work includes developing new detection mechanisms for data endpoints, CSP policy generation, and blocking scripts from accessing sensitive user hardware.

Read the original post ↗