What we know

Cloudflare has launched a feature called Application Profiles, which enforces positive security by learning the typical structure of HTTP requests made to a web application. This feature blocks requests that deviate from the learned profile, aiming to reduce the attack surface. The motivation behind this development is the rise of AI-driven attacks, which can generate new and sophisticated attack payloads more easily.

According to the research package, the following claims are made but remain unverified:

  • Cloudflare Application Profiles enforce positive security by learning and enforcing the structure of legitimate HTTP requests.
  • This feature helps reduce the attack surface against AI-generated attacks.

An excerpt from the source states:
"Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate new attack payloads."

Why it matters

This topic is currently assigned to the TECHNOLOGY desk as an explainer. The Intel Brief is not presenting the vendor’s claims as established fact. Descriptions such as "smarter" or "stronger" reflect the source’s framing unless a claim is explicitly verified. Readers should await independent corroboration before accepting product or security claims as confirmed.

Traditional web application security often relies on negative security models, which block known malicious patterns. In contrast, positive security models allow only requests that match a known good profile. Cloudflare’s Application Profiles use machine learning to automatically build these profiles based on legitimate traffic and enforce them to block anomalous requests. This approach is intended to address the evolving threat landscape, where attackers increasingly use AI to create novel attack payloads that can evade traditional security rules.

What is still unknown

  • The package includes fewer than two independent sources, so the information is not independently verified.
  • The Intel Brief has not independently tested the product, patch, or attack described.
  • Any details about technical effects, timelines, or customer impact that are not included in the excerpts remain UNKNOWN.

Sources