Skip to content
INTERNET INFRASTRUCTURE & NETWORKS

Cloudflare Expands Positive Security with Launch of Application Profiles to Counter AI-Driven Threats

Cloudflare has officially announced the launch of Application Profiles, a new capability designed to help organizations seamlessly enforce a positive security policy across their digital properties. By analyzing the structural format of incoming HTTP requests and identifying deviations from established baselines, the platform aims to significantly shrink the reachable attack surface for web applications and APIs.

The rollout arrives as cybersecurity professionals face mounting pressure to defend against sophisticated attacks powered by frontier artificial intelligence models. According to security teams across the industry, mitigating automated and AI-driven threats has become an absolute priority. Large language models (LLMs) have lowered the barrier to entry for malicious actors, allowing even non-technical individuals to launch complex attacks using simple text prompts. These language models can generate malicious payloads, test known vulnerabilities, and probe applications autonomously by dynamically mutating their strategies based on real-time feedback from the target application or its web application firewall.

Traditional security tools have evolved to keep pace, but practitioners increasingly recognize the limitations of a purely reactive posture. While managed WAF rules and machine learning-based detections remain indispensable for identifying classic attack vectors such as SQL injection, cross-site scripting, remote code execution, and newly disclosed CVEs, relying solely on patching vulnerabilities is unsustainable. Organizations often struggle to maintain this pace, particularly if they lack a complete inventory of their underlying vulnerabilities and application logic.

Application Profiles introduce a shift toward a positive security model. Instead of scanning exclusively for signatures that resemble known attacks, the system learns what legitimate, well-formed traffic looks like by observing the structure of normal requests. By permitting only traffic that conforms to expected formats, the tool dramatically curtails the potential attack surface. For example, if a search input field expects only standard alphanumeric characters rather than special symbols, the system can automatically reject non-conforming inputs, neutralizing entire categories of typical exploit payloads before they ever reach application handlers.

Beyond basic input filtering, the architecture goes a step further by evaluating the broader structure and format of HTTP requests to infer the underlying goal of each operation. This deep visibility enables organizations to identify and prioritize the most critical and sensitive operations and data fields within their architectures. While Cloudflare has previously offered positive security for APIs through Schema Learning and Schema Validation, this release extends those protective mechanisms to broader web applications under the banner of Application Schema Profiles. Once an application is onboarded, the system learns its characteristic profile and deploys an always-on detection layer to flag non-conforming requests, supported by comprehensive analytics.

The feature is currently rolling out through a closed beta program targeted at invited Enterprise customers who do not yet utilize API Security, while customers who already have API Security enabled receive immediate access.

Validating Requests Based on Learned Profiles

Under the hood, Schema Profiles periodically analyze observed traffic patterns to determine the expected structural layout of incoming requests. Once a profile has been generated, an always-on validation layer is automatically activated for live traffic. Every incoming request is evaluated against this profile, and the system appends the validation result as metadata, augmenting the contextual information already attached to the transaction.

Significantly, this evaluation signal does not take automated enforcement actions by itself upon deployment. Instead, customers can analyze historical traffic trends within Security Analytics, review how the validation behaves in practice, and subsequently configure Security Rules to block non-conforming requests where appropriate. Operations that lack a generated profile are left unclassified by this specific feature.

Unlike traditional managed rules, failing validation does not necessitate matching a pre-existing attack signature. Instead, an input value falling outside an expected numerical range, an unrecognized enumeration value, a malformed universally unique identifier, or unexpected character sets will trigger a flag simply because they diverge from the learned profile baseline.

For instance, consider a typical application path requesting inventory data using a path variable and a query parameter. Through observation of sufficient legitimate traffic, the system learns that the designated path component requires a valid UUID variable, while the query parameter requires an integer within specific boundaries. If an attacker substitutes a string where an integer is expected, the system flags the anomaly immediately. When enforcement rules are active, this prevents malformed input from reaching the application handler, effectively blocking common attack vectors without requiring a specific signature match.

Because application updates, new client integrations, or unusual valid requests can occasionally introduce variations, the platform recommends that teams operate in an initial observation mode. This allows administrators to review the real-world impact of a profile before shifting to active blocking policies.

Learning the Expected Structure of Requests

To establish an accurate baseline for web and API applications, Schema Profiles continuously process qualifying traffic streams, executing automated learning cycles on a weekly basis using recent successful traffic data. To construct reliable field definitions, an operation must record at least 1,000 requests yielding a successful 2xx response over a seven-day window, while data boundary learning requires a minimum of 10,000 successful requests. Because these successful traffic samples can occasionally include automated scanners or benign bots, administrators are advised to thoroughly inspect learned profiles prior to enforcement.

Enforce positive security with Cloudflare Application Profiles

For each data field, the system identifies underlying data types—such as integers, strings, booleans, arrays, UUIDs, or enums—alongside structural constraints including numeric ranges, string lengths, and specific character classes. Profiling applies to designated operations identified by their HTTP methods, hostname patterns, and path patterns. While manually created operations trigger profiling immediately, discovered operations listed within the Web Assets interface require administrators to explicitly select profile learning from the operation menu.

Once generated, profiles can be reviewed directly within the dashboard under the security overview panel, and administrators retain the ability to export the learned schemas as standard OpenAPI version 3 files. These profiles update dynamically week over week to reflect natural shifts in application usage, incorporating newly observed fields while deprecating those that disappear from traffic logs.

Review Before You Block

To facilitate safe adoption, the Security Analytics interface features a dedicated Profile Analysis tab. Here, security teams can inspect traffic trends, monitor the volume of non-conforming requests over the preceding week, and drill down into sampled logs to understand precisely where and why a validation failure occurred. Violations are categorized into distinct classes—such as type mismatches, out-of-range numerical values, and format errors—providing granular insight into application traffic.

Once teams evaluate these insights, they can construct flexible Security Rules to govern how the system responds. Rules can span an entire application or target specific paths, operations, or fields, allowing organizations to balance strict security postures with operational flexibility.

Positive Security for Web and API Traffic

Traditional web application firewall learning workflows often demand extensive manual oversight, requiring operators to review suggestions, stage policy updates, and maintain numerous individual policy entities. Cloudflare addresses this operational friction by exposing validation results directly through queryable request fields, enabling teams to combine schema validation status with existing signals such as Bot Scores and Attack Scores within unified Security Rules.

Specialized fields allow administrators to pinpoint exactly where violations occur within query parameters, path variables, headers, cookies, or request bodies. Additionally, auxiliary fields track the presence of undeclared parameters that were not captured during the initial learning phase. This capability proves particularly useful when deploying new application versions that introduce novel parameters, or alternatively, when enforcing a strict security posture that blocks any unexpected parameters entirely.

Upcoming Capabilities and Operational Context

Even with flexible enforcement mechanisms, security professionals frequently cite the operational complexity of rolling out positive security policies across large applications that feature thousands of operations and tens of thousands of individual data fields. Because not all operational fields carry equivalent risk, contextualization and prioritization are essential for confident deployment.

To alleviate this burden, the company is developing capabilities leveraging large language models hosted on Workers AI to analyze learned profiles and provide semantic insights. By evaluating path and field names, experimental models have successfully linked identifiers across disparate application endpoints and recognized common authentication patterns such as One-Time Password implementations. Surfacing this contextual awareness helps security teams prioritize critical defenses, such as deploying targeted rate-limiting rules against account takeover attempts.

These LLM-powered insights will integrate directly into the dashboard alongside Web Assets, offering rule recommendations backed by mitigation simulations derived from historical traffic. By combining semantic context with historical request trends, security teams will be able to sequence their hardening efforts around the most critical operations first.

The current feature release supports paths, query parameters, headers, cookies, JSON request bodies, and form-encoded bodies, handling basic data types including integers, strings, UUIDs, arrays, and small enumerations. More complex structures such as multipart forms, GraphQL, and XML are not currently supported, and while the profiles validate repeated parameter values, they do not enforce strict parameter uniqueness or mandate required fields by default.

Looking ahead, the development roadmap for Application Profiles extends beyond structural validation. Future iterations aim to learn broader behavioral characteristics—such as autonomous system numbers and JA4 cryptographic fingerprints—providing security teams with deeper visibility into anomalous traffic and reinforcing proactive workflows designed to neutralize zero-day threats before they can be exploited.

Leave a Reply

Your email address will not be published. Required fields are marked *