Back
Cloudflare Application Profiles enforces positive security on web traffic
SiTech AI Team3 წთ. საკითხავი

Cloudflare Application Profiles enforces positive security on web traffic

Cloudflare launched Application Profiles, a feature that learns the expected structure of HTTP requests and flags deviations. It extends Schema Learning and Schema Validation from APIs to web applications.

Cloudflare has introduced Application Profiles, a detection layer that learns the expected structure and format of HTTP requests and flags deviations. It enforces positive security: only requests matching a learned profile are conforming. It extends Cloudflare's Schema Learning and Schema Validation from APIs to web applications.

Why the approach changed

Cloudflare says customers increasingly ask how to defend against attacks built with frontier AI models. LLMs let even non-technical people launch an attack from a single prompt, generate malicious payloads and probe applications autonomously. Managed WAF rules and machine learning detections remain essential against SQL injection, cross-site scripting, remote code execution and new CVEs, but the vendor argues that patching faster is not a sustainable answer.

How profiles are learned and validated

Schema Profiles periodically analyze observed traffic to determine the expected structure. A profile covers path variables, query parameters, headers, cookies and the body structure. For each field it learns the data type (integer, string, boolean, array, UUID or enum) and constraints such as numeric ranges, string lengths and character classes. Learning runs once a week per zone: an operation needs at least 1,000 requests with a 2xx response in the previous seven days to learn fields, and at least 10,000 to learn data boundaries.

Review before blocking

An always-on validation layer classifies live traffic and attaches the result to each request as metadata. The signal does not block anything by itself: customers create Security Rules to block non-conforming requests. Unlike Managed Rules, failing validation does not require a request to match a known attack signature. A value outside an expected range, an unknown enum or an invalid UUID can all be flagged. Cloudflare notes that non-conforming does not always mean malicious and recommends starting in observation mode.

Security Analytics adds a Profile Analysis tab showing how many requests did not conform in the previous seven days, with ten violation reasons. The detection is exposed as the field cf.schema_validation.learned.violated, usable alongside Bot Score and Attack Score.

Availability and limits

Customers with API Security already have access, since the feature extends their Schema Learning and Schema Validation. A closed beta is opening to other Enterprise customers by invitation. It supports paths, query parameters, headers, cookies, JSON and form-encoded bodies, and validates integers, strings, UUIDs, arrays and enums of up to three values. Multipart forms, GraphQL and XML are not supported. Profiles validate every value when a parameter name repeats but do not enforce parameter uniqueness, and they do not block a request solely for carrying a new parameter. The same workflow could later learn other characteristics such as ASNs and JA4 fingerprints.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.