Enforce positive security with Cloudflare Application Profiles
Cloudflare introduces Application Profiles to enforce positive security by analyzing HTTP request structures, reducing attack surfaces without relying solely on patching vulnerabilities.
Cloudflare has launched Application Profiles, a feature designed to enforce positive security policies by analyzing the structure and format of HTTP requests. Instead of only detecting known attack patterns, the tool learns what constitutes valid traffic for an application and flags deviations. This approach aims to significantly reduce the attack surface area by allowing only requests that conform to expected formats, such as rejecting special characters in search fields or validating UUID formats.
The new feature extends Cloudflare’s existing positive security capabilities, previously available for APIs through Schema Learning and Schema Validation, to web applications. Customers can onboard an application, and Cloudflare will automatically learn its request profile from observed traffic. An always-on validation layer then evaluates live traffic against this profile, adding metadata to each request without taking immediate action. Customers can review non-conforming requests in Security Analytics and decide where to enforce blocking rules.
Application Profiles learn the expected request structure by analyzing successful traffic, including data types, numeric ranges, string lengths, and character classes. Profiling requires at least 1,000 successful requests for field learning and 10,000 for data boundary learning within a seven-day window. Customers can manually trigger profiling for specific operations or review learned schemas before enforcement. Profiles update weekly to reflect changes in application traffic, and customers can export them as OpenAPI v3 schema files.
Security Analytics now includes a Profile Analysis tab to help teams review traffic trends, violations, and reasons for non-conformance, such as type mismatches or invalid formats. Teams can create Security Rules to block non-conforming requests based on the validation signal, combining it with other signals like Bot Score or Attack Score. The feature is initially available in closed beta to invited Enterprise customers without API Security, while those with API Security already have access.