What we know

Cloudflare has launched a feature called Application Profiles, which enforces positive security by learning the typical structure of HTTP requests made to a web application. This feature blocks requests that deviate from the learned profile, aiming to reduce the attack surface. The motivation behind this development is the rise of AI-driven attacks, which can generate new and sophisticated attack payloads more easily. - This feature helps reduce the attack surface against AI-generated attacks. An excerpt from the source states: "Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate new attack payloads."

Why it matters

Traditional web application security often relies on negative security models, which block known malicious patterns. In contrast, positive security models allow only requests that match a known good profile. Cloudflare’s Application Profiles use machine learning to automatically build these profiles based on legitimate traffic and enforce them to block anomalous requests.

What is still unknown

Enforcement details, remaining product questions, and independent tests are not in the reporting.