Security

Cloudflare Introduces Persistent Detection Engine for Bot Management, Says It Will Defend as Attack Patterns Change

TECHWORLD ·

[Photo: Cloudflare]

✦ AI Summary

Cloudflare announced on the 2nd that it will introduce a persistent detection engine, "Adaptive Intelligence," to its security platform, "Cloudflare Bot Management."

Adaptive Intelligence self-learns from real-time traffic signals based on trillions of requests processed across its global network and generates detection rules in real time to respond to new threats.

It also immediately adjusts the defense system when attack attempts occur, increasing the time and cost of automated attacks while supporting repeated attack blocking, real-time detection, and automatic security updates.

Cloudflare announced on the 2nd that it will introduce a persistent detection engine, "Adaptive Intelligence," to its security platform, "Cloudflare Bot Management." Cloudflare Bot Management is its security platform for detecting automated bot traffic and blocking malicious bots.

Adaptive Intelligence operates based on trillions of requests processed across Cloudflare's global network. The engine self-learns from various signals in real-time traffic and generates detection rules in real time to respond to new threats. It also immediately adjusts its defense system when automated attack attempts are detected.

Cloudflare said the purpose of the immediate adjustment to its defense system is to make attacks harder to carry out. The company said this structure increases the time and cost of automated attacks.

Cloudflare CTO Dane Knecht said traditional defense systems have fixed operating methods, allowing attackers to repeatedly analyze them and look for ways to bypass them. In contrast, Cloudflare Adaptive Intelligence continuously changes the defense system, quickly invalidating information attackers have learned and blocking attacks before they can spread at scale, he said.

Adaptive Intelligence supports the building of an always-on defense system and blocks repeated attack attempts by attackers. It also supports real-time attack detection based on time-of-day behavior pattern analysis, identification of malicious activity, and automatic deployment of security updates.

Based on Cloudflare ML models, continuous learning is carried out from real-time traffic, allowing the detection engine for new bot frameworks and evasion techniques to be reflected immediately. As a result, separate manual updates and waiting for regular updates are unnecessary, and new threats can be addressed in real time.

The technology works by automatically generating custom detection rules to block specific threats and continuously changing detection rules. At the same time, it analyzes how attacker systems operate and the defense system itself, aiming to make it harder to find ways to bypass it.

It also seeks to identify low-and-slow threats that are difficult to detect with existing defense systems by analyzing behavior patterns across multiple time zones at the same time. Cloudflare Precursor is a behavior-based bot defense solution that collects behavioral signals from browser sessions and combines them with telemetry data collected at the global edge.

Through the combination of browser session behavioral signals and global edge telemetry, the system makes a comprehensive judgment on whether activity is automated and whether it is abuse. Cloudflare CTO Dane Knecht said that when the cost of scaling up attacks is effectively close to zero, there are limits to what can be done by simply strengthening defenses, and explained that structural changes that increase attacker cost and effort are needed to respond to the latest bot threats.

Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406400

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.