Full Report
Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate and vary payloads.
Analysis Summary
# Best Practices: Positive Security with Application Profiles
## Overview
These practices address the shift from reactive security (detecting known threats) to **Positive Security** (defining and allowing only known-good behavior). By learning the specific structure, data types, and parameters of HTTP requests, organizations can block deviations caused by AI-generated payloads, mutated attacks, and zero-day exploits that traditional signature-based WAFs might miss.
## Key Recommendations
### Immediate Actions
1. **Onboard Critical Applications:** Identify high-value web applications and onboard them to "Schema Profiles" to begin the learning phase.
2. **Enable Passive Detection:** Allow Cloudflare to analyze traffic patterns to baseline "normal" behavior for paths, query parameters, headers, and cookies.
3. **Monitor Security Analytics:** Review the metadata added to requests to identify non-conforming traffic without enabling blocking rules yet.
### Short-term Improvements (1-3 months)
1. **Define Enforcement Rules:** Create Security Rules to block non-conforming requests for high-confidence profiles (e.g., fields that should only ever be UUIDs or Integers).
2. **Audit Data Types:** Review learned schemas to ensure that boundaries (e.g., integer ranges, string formats) accurately reflect the application's backend requirements.
3. **Prioritize by Risk Label:** Use Cloudflare’s risk labels (Data Loss, Reconnaissance, Business Criticality) to focus mitigation efforts on the most sensitive operations first.
### Long-term Strategy (3+ months)
1. **Zero-Day Prevention Workflow:** Transition to a "Proactive Security" model where any request not matching the learned profile is treated as untrusted by default.
2. **Integration with CI/CD:** Align application updates with profile refreshes to prevent "false positives" during new feature releases.
3. **Advanced Signal Correlation:** Incorporate JA4 fingerprints and ASN reputation into the learned profiles to further harden the environment.
## Implementation Guidance
### For Small Organizations
- **Focus on Defaults:** Rely on the automated learning process. Use the "Always-on" detection to identify simple anomalies like unexpected characters in search fields.
- **Manual Review:** Periodically check Security Analytics to see if legitimate users are being flagged before moving to blocking mode.
### For Medium Organizations
- **Parameter Validation:** Specifically enforce data types for sensitive inputs like `product_id` or `user_id` (e.g., ensuring they remain Integers or UUIDs).
- **Segment Traffic:** Separate API traffic from standard web traffic to apply stricter Schema Validation on API endpoints.
### For Large Enterprises
- **Risk-Based Orchestration:** Use the API to export profile deviations into a SIEM for deeper analysis.
- **Phased Enforcement:** Deploy blocking rules in a "Log" or "Simulate" mode across different global regions before full enforcement.
- **Multi-Format Coverage:** Ensure JSON and form-encoded request bodies are included in the validation profiles.
## Configuration Examples
While specific code syntax is handled via the Cloudflare dashboard, the logical configuration follows this flow:
- **Learned Pattern:** `GET /shop/{uuid}/inventory?product_id={int}`
- **Security Rule Logic:**
- `If (Request.Path.Deviation == True) OR (Request.Query.product_id.Type != Integer)`
- `Then: Block (or Challenge)`
## Compliance Alignment
- **NIST SP 800-53:** Controls for Information Input Validation (SI-10).
- **OWASP Top 10:** Directly mitigates A03:2021-Injection by enforcing strict input schemas.
- **PCI DSS 4.0:** Supports requirement 6.4.1 by providing automated technical solutions to detect and prevent web-based attacks.
## Common Pitfalls to Avoid
- **Blocking too Early:** Avoid enabling "Block" actions immediately after onboarding; wait for the learning period to capture seasonal or unusual (but valid) traffic.
- **Ignoring Application Updates:** New application releases may change request structures. Ensure security teams are alerted to "Non-conforming" spikes after a deployment.
- **Over-reliance on Signatures:** Do not assume a "Clean" WAF log means the app is safe; AI-driven mutations can bypass signatures while still violating the Application Profile.
## Resources
- **Cloudflare Documentation:** [https://developers.cloudflare.com/waf/detections/application-profiles/](https://developers.cloudflare.com/waf/detections/application-profiles/)
- **API Shield Management:** [https://developers.cloudflare.com/api-shield/management-and-monitoring/](https://developers.cloudflare.com/api-shield/management-and-monitoring/)
- **JA4 Signals Info:** [https://blog.cloudflare.com/ja4-signals/](https://blog.cloudflare.com/ja4-signals/)