Skip to content

SYSTEM Cited by 1 source

Cloudflare Application Profiles

Application Profiles is Cloudflare's runtime-protection feature (announced 2026-09-29) that automates deploying a positive security model: it automatically learns the structure of a web or API application from observed traffic and detects non-conforming requests, allowing what matches the learned profile and flagging what does not.

What it adds over a hand-built positive model

Two things distinguish Application Profiles from manually authoring a schema (as with API Shield, which imports an OpenAPI spec or learns per-endpoint):

  1. Automated learning. It "automates the learning process" — the operator doesn't have to describe every valid request shape; the profile is inferred from real traffic.
  2. A layer of interpretation. "Based on the learned profile, we can understand the business logic of different endpoints and request parameters and help you prioritize what endpoints require more scrutiny and attention." The profile is not just an allow-list — it's a map of the application's endpoints and parameters that feeds prioritization.

Why it matters for the AI era

You can "dramatically reduce the attack surface by learning what legitimate traffic looks like, allowing conforming requests and blocking everything else." Against an LLM attacker that generates thousands of novel payload variants, a positive model neutralizes the volume advantage — a request only passes if it conforms, and none of the generated variants do. This is the same positive-security logic API Shield applies to structured API endpoints, now generalized and automated across web + API applications.

Position in the runtime-protection stack

Application Profiles is layer 1 ("enforce positive security") in the 2026-09-29 four-layer runtime approach on the WAF reverse proxy:

  1. Enforce positive security — Application Profiles (this page).
  2. Detect attacks / identify LLM tactics — Managed Rules + Attack Score ML + AI Security for Apps.
  3. Protect business logic — account-takeover + leaked-credential/fraud detection.
  4. Real-time threat intelligence — Cloudforce One detection.

Seen in

  • systems/cloudflare-waf — the reverse proxy this runs on; positive security is layer 1 of the runtime stack.
  • systems/cloudflare-api-shield — the schema-driven positive-security sibling for structured APIs; Application Profiles automates the learning half.
  • positive-security-model — the concept it instantiates (allow-only-valid vs block-known-bad).
  • companies/cloudflare.
Last updated · 766 distilled / 2,225 read