Industry NewsAI Business & Ecosystem

Cloudflare Introduces Adaptive Intelligence to Make Automated Cyberattacks Harder and More Expensive to Scale

By Ash Kate
Cloudflare Introduces Adaptive Intelligence to Make Automated Cyberattacks Harder and More Expensive to Scale

Article content

Cloudflare has introduced Adaptive Intelligence, a new continuous detection engine built into its Bot Management platform and designed to respond to evolving automated cyberattacks in real time.

The technology uses signals from traffic moving across Cloudflare's global network to identify emerging attack patterns and automatically generate short-lived rules targeting specific threats.

The approach is designed around a simple objective: make automated attacks more difficult and expensive for threat actors to sustain by continuously changing the defensive response.

Moving Beyond Static Bot Defenses

Automated attacks have become easier to launch as AI tools, inexpensive infrastructure, and readily available software lower the technical barrier for attackers.

Threat actors can use compromised devices, residential IP addresses, and software designed to imitate human activity to conduct activities such as credential stuffing, scraping, and other forms of automated abuse.

For security teams, the challenge is fundamentally different. They need to identify and stop malicious automation while ensuring legitimate customers and visitors continue to access online services.

Cloudflare argues that traditional security systems can struggle with this imbalance when defensive updates are slower than the pace at which attackers modify their techniques.

A Continuously Learning Detection Engine

Adaptive Intelligence is designed to continuously learn from live traffic rather than depend exclusively on periodic updates.

Cloudflare says its machine learning model retrains continuously, incorporating signals associated with new bot frameworks and emerging bypass techniques into its detection engine.

The company says the system analyses more than a trillion web visits every day to identify changes in traffic behaviour and emerging threats.

This allows the defensive system to adapt as attack patterns change rather than relying solely on predefined signatures or scheduled updates.

Making Attackers Start Over

One of the key components of Adaptive Intelligence is its use of short-lived, targeted rules.

Instead of giving attackers a static defensive system that can be studied and systematically bypassed, the technology is designed to generate rules that target specific threats and then rotate them.

The objective is to prevent threat actors from gaining lasting knowledge of defensive configurations.

Cloudflare CTO Dane Knecht described the approach as creating a "moving target" for attackers, arguing that continually changing defenses can undermine the economics of automated attacks.

Detecting Low-and-Slow Attacks

Adaptive Intelligence is also designed to identify attack patterns that unfold over longer periods.

Traditional bot detection can have difficulty identifying low-volume automated activity when individual requests appear relatively normal.

Cloudflare says its system can analyse behavioural patterns across multiple timeframes, helping identify campaigns such as slow credential stuffing and scraping that may otherwise remain below conventional detection thresholds.

Distinguishing Automation From Real Users

Another component of the architecture involves combining multiple sources of behavioural and network information.

Cloudflare says Adaptive Intelligence incorporates browser-level session behaviour signals from Cloudflare Precursor alongside global edge telemetry.

The combination is intended to provide additional context when determining whether activity represents malicious automation or legitimate human behaviour.

For businesses, the goal is to improve detection without relying on overly aggressive controls that could inadvertently block genuine customers.

Testing Security Updates Before Deployment

Adaptive Intelligence also introduces an automated approach to deploying detection improvements.

According to Cloudflare, security updates can test themselves against live traffic in the background before being deployed.

The objective is to validate detection accuracy and reduce the likelihood of false positives while allowing changes to be introduced without downtime.

This creates an additional layer of automation within the security update process itself.

Changing the Economics of Bot Attacks

The broader strategy behind Adaptive Intelligence is to shift the economics of automated attacks.

When attackers can repeatedly test inexpensive techniques against relatively static defenses, the cost of experimentation remains low.

Cloudflare's approach is to continuously change the defensive environment, forcing attackers to repeatedly adapt their tooling and tactics.

If successful, this could make automated campaigns less attractive by increasing the engineering effort required to maintain them at scale.


About Cloudflare

Cloudflare, Inc. (NYSE: NET) is a connectivity cloud company providing services designed to help organisations make applications, networks, and employees faster and more secure.

Its platform combines connectivity, security, performance, and developer capabilities across a global network. Cloudflare says its network blocks billions of threats for customers every day and serves organisations ranging from large enterprises to small businesses, nonprofits, and governments.


Source & Credits

Hotwire Global & Cloudflare Press Release