Skip to content

SYSTEM Cited by 3 sources

Cloudflare WAF

Cloudflare WAF (Web Application Firewall) is Cloudflare's edge layer-7 request-filtering product — customer-configured and Cloudflare-managed rulesets that run on every request before the request reaches the origin or any paid product layer. Well-known outside this wiki; stub page here because it's a required reference point for downstream features.

Pipeline position (as surfaced by pay-per-crawl)

On a zone with pay-per-crawl enabled, the Cloudflare edge runs:

  1. WAF rules.
  2. Bot management / bot blocking.
  3. Pay-per-crawl rules engine.

Downstream features (like pay-per-crawl) explicitly run after WAF and bot-management so they never override an existing security decision — publishers keep their WAF posture unchanged and layer monetization / other policy on top, not through.

ML scoring layer: WAF Attack Score

Beyond signature-based managed rulesets, the WAF runs an ML model on every request that assigns a WAF Attack Score (1–99) based on structural similarity to historical attack traffic. Novel SQLi or RCE chains are caught because they rearrange shapes the model has already seen, even when the specific exploit is brand new. Lower score → more aggressive treatment. This implements the ml-anomaly-scoring-over-signature-matching pattern.

Same scoring methodology extended to AI prompts via "AI Security for Apps."

(Source: sources/2026-06-09-cloudflare-defend-against-frontier-cyber-models)

Operational numbers

  • Sub-30-second global rule deployment (managed rulesets reach entire network)
  • Traditional PoC-to-rule SLA: 12 hours (acknowledged as insufficient vs frontier models)
  • React2Shell: managed rule live before official CVE advisory

(Source: sources/2026-06-09-cloudflare-defend-against-frontier-cyber-models)

Threat intelligence integration

Cloudforce One threat intelligence can now be used directly within WAF rules to block high-risk traffic — closes the gap between threat discovery and mitigation without an intermediate feed-ingestion step.

(Source: sources/2026-06-09-cloudflare-defend-against-frontier-cyber-models)

The four-layer runtime approach (2026-09-29 framework)

The 2026-09-29 application-security-framework post frames the WAF reverse proxy's runtime protection as a layered approach — "a new layered approach is emerging to best filter traffic from malicious requests" — combining signature-based detection with ML:

  1. Enforce positive security — new Application Profiles automatically learns the structure of a web/API app, allows conforming requests, and flags non-conforming ones (plus a business-logic interpretation layer to prioritize which endpoints need scrutiny). Neutralizes an LLM attacker's ability to generate thousands of novel payload variants — none conform.
  2. Detect attacks / identify LLM tactics —
  3. Managed Rules hardened with frontier models: Cloudflare partnered with major model providers to use LLMs for adversarial validation, pentesting the WAF to uncover bypasses; all customers benefit automatically. (Canonical continuous-red-team-validation posture, first named 2026-06-09.)
  4. Attack Score ML — signatures give high-precision detection of known attacks; ML stops attacks before they are discovered and disclosed, catching the mutations and evasion techniques "often used by LLMs." Available to all Cloudflare customers.
  5. AI Security for Applications — chatbots and internet-facing LLMs face a new attack class (prompt injection, sensitive data exposure); AI Security for Apps deploys guardrails + detections against these. Same Attack-Score methodology extended to AI prompts.
  6. Protect business logic — attackers can craft legitimate-looking requests and abuse business logic (e.g. repeatedly using a valid password-reset flow to take over accounts). Fraud-detection tools — account-takeover + leaked-credential detection — prevent abuse where the request appears legitimate but the intent is malicious.
  7. Real-time threat intelligence — always-on detection (launched June 2026) from Cloudforce One feeds blocks requests from compromised infrastructure.

"Before AI, the time to disclose new vulnerabilities was measured in months and days. Not anymore: now we see vulnerabilities being exploited before they are disclosed, so the time to patch is nearing zero" — the argument for the ML + positive-security layers over pure signature rules.

(Source: sources/2026-09-29-cloudflare-adaptive-application-security-for-the-ai-era-how-cloudflare)

Seen in

Last updated · 766 distilled / 2,225 read