← All stories
● Covered by 1 source · 2 reportsMedium impact2 neutral

Cloudflare Introduces Application Profiles and Tests WAF Against AI-Generated Attacks

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Cloudflare launched Application Profiles for positive security enforcement.
  • Application Profiles analyze HTTP request structures to identify deviations.
  • Cloudflare tested its WAF against AI-generated attack payloads.
  • Testing revealed areas for WAF improvement and led to new detection rules.
  • The goal is to reduce attack surface and counter AI-driven attack mutations.

Cloudflare Introduces Application Profiles

Cloudflare has introduced Application Profiles, a new feature designed to enforce positive security policies for web applications. This system works by analyzing the structure and format of HTTP requests. By understanding what 'good' traffic looks like, it can identify and block deviations, thereby reducing the potential attack surface.

The introduction of Application Profiles addresses a growing concern among customers regarding protection from attacks leveraging frontier AI models. These models enable even non-technical individuals to generate malicious payloads and autonomously probe applications, mutating tactics based on application feedback or Web Application Firewall (WAF) responses.

Testing WAF Against AI Models

In parallel with the launch of Application Profiles, Cloudflare conducted tests on its existing Web Application Firewall (WAF) using attack payloads generated by frontier AI models. This dynamic testing approach involved making the AI act as a hacker, with no access to source code or WAF rules, only observing selected HTTP response data.

The objective was to evaluate the WAF's performance against the rapid iteration and mutation capabilities of AI-driven attacks. AI models can quickly test different encodings, send payloads in various parts of HTTP requests, and move to new vulnerabilities, surpassing human attacker speeds.

Improved Security Measures

The testing process revealed areas where the WAF could be improved. As a direct result of these findings, Cloudflare developed new detection rules. These enhancements benefit Cloudflare customers by providing better protection against sophisticated, AI-generated attack techniques.

Managed WAF rules and machine learning-based detections remain crucial for identifying common attack types such as SQL injection, cross-site scripting, remote code execution, and new CVEs. The new Application Profiles complement these existing tools by focusing on preventing attacks that deviate from expected application behavior.

Addressing Evolving Threats

The development of Application Profiles and the WAF testing against AI models reflect Cloudflare's strategy to stay ahead of evolving threats. The company acknowledges that simply patching vulnerabilities faster is not a sustainable solution, especially when applications may have unmapped vulnerabilities.

By understanding and enforcing what constitutes legitimate application traffic, Cloudflare aims to provide a more proactive security posture against the increasingly sophisticated and automated attacks facilitated by advanced AI models.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Cloudflare introduced Application Profiles, a new feature that enforces positive security policies by analyzing HTTP request structures and identifying deviations. This aims to reduce attack surface area by allowing only expected request formats, extending existing API security to web applications.

Cloudflare tested its Web Application Firewall (WAF) against attack payloads generated by frontier AI models to identify potential bypasses. The testing revealed areas where the WAF could be improved, leading to new detection rules that benefit Cloudflare customers.