
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[ The Cloudflare Blog ]]></title>
        <description><![CDATA[ Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet. ]]></description>
        <link>https://blog.cloudflare.com</link>
        <atom:link href="https://blog.cloudflare.com/" rel="self" type="application/rss+xml"/>
        <language>en-us</language>
        <image>
            <url>https://blog.cloudflare.com/favicon.png</url>
            <title>The Cloudflare Blog</title>
            <link>https://blog.cloudflare.com</link>
        </image>
        <lastBuildDate>Fri, 10 Apr 2026 21:43:40 GMT</lastBuildDate>
        <item>
            <title><![CDATA[Super Bot Fight Mode is now configurable!]]></title>
            <link>https://blog.cloudflare.com/configurable-super-bot-fight-mode/</link>
            <pubDate>Thu, 16 Mar 2023 13:00:00 GMT</pubDate>
            <description><![CDATA[ Super Bot Fight Mode can be used with Skip rules now to allow for configurable deployments ]]></description>
            <content:encoded><![CDATA[ <p></p><p>Millions of customers around the world use Cloudflare to keep their applications safe by blocking bot traffic to their website. We block an average of 336 million requests per day for self-service customers using a service called <a href="/super-bot-fight-mode/">Super Bot Fight Mode</a>. It is a crucial part of how customers keep their websites online.</p><p>While most customers use Cloudflare’s <a href="https://radar.cloudflare.com/traffic/verified-bots">Verified Bot</a> directory to securely allow good, automated traffic, some customers also like to write their own localized integration scripts to crawl and update their website, or perform other necessary maintenance functions. Because these bots are only used on a single website, they don’t fit our verified bot criteria the way a Google or Bing crawler does. This makes Super Bot Fight Mode difficult to manage for these types of customers.</p>
    <div>
      <h3>Super Bot Fight Mode: now configurable!</h3>
      <a href="#super-bot-fight-mode-now-configurable">
        
      </a>
    </div>
    <p>Previously, Super Bot Fight Mode ran as an independent service on our global network and other <a href="https://www.cloudflare.com/security/">Cloudflare security services</a> were unable to affect its configuration. To solve this, we’ve rewritten Super Bot Fight Mode behind the scenes. It’s now a new <a href="https://developers.cloudflare.com/waf/managed-rules/">managed ruleset</a> in <a href="/new-cloudflare-waf/">the new WAF</a>, just like the OWASP Core Ruleset or the Cloudflare Managed Ruleset. This doesn’t change the interface, but brings Super Bot Fight Mode closer to where customers are managing their other security exceptions.</p><p>As we speak, the WAF team is carefully <a href="https://developers.cloudflare.com/waf/reference/migration-guides/firewall-rules-to-custom-rules/">migrating all self-serve customers from our old Firewall Rules system to a new system</a>. This new system, called Custom Rules, simplifies the exception process in the rules you write with no other changes or loss of functionality. In the old system we had two separate actions, “allow” and “bypass”. In the new Custom Rules, there’s only one action called “skip”. Rules that “skip” traffic can skip the rest of your custom rules (just like an “allow” rule would) <i>and</i> other Cloudflare services. As Cloudflare customers are given the “Skip” action, you will be able to see the option available to “skip” Super Bot Fight Mode. Here’s an example:</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5NAxkGqQh2afrqcmqdKKAd/0b39961bf89323382c5a4544a9a7a9bf/image3-26.png" />
            
            </figure><p>While we spoke to customers about their use cases for skipping Super Bot Fight Mode, one use-case kept popping up that didn’t quite fit the rest: WordPress Loopback requests. As many people know, as part of WordPress’ self-diagnostic capabilities, a WordPress site will make automated requests back to itself over the Internet to confirm its reachability and functionality. These loopback diagnostics can come from dozens of different community developed plugins, each implementing loopback requests slightly differently. To help accommodate an ever-growing diversity in diagnostic tools used in WordPress, we have added a simple configuration option to securely allow these loop-back requests.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1wELIm0qRkZ8VxlRnOa6PK/364901a384a8e8967ac0c9888cf380c1/image2-19.png" />
            
            </figure><p>In the future, we will be integrating this feature with the Cloudflare WordPress plugin to make it even easier to use WordPress with Cloudflare.</p>
    <div>
      <h3>What’s next?</h3>
      <a href="#whats-next">
        
      </a>
    </div>
    <p>Self-serve customers with Custom Rules can create “Skip” rules to create exceptions for Super Bot Fight Mode today. We are currently rolling out Custom Rules to all of our customers. If you do not see this option available now, you should expect to see it in the next several weeks. If the lack of flexibility has prevented you from using Super Bot Fight Mode in the past, please log into the Cloudflare dashboard and try it with these new skip rules!</p><p>While we’ve added flexibility to customers’ Super Bot Fight Mode deployments, we know that Free plan customers want the same level of customization that self-serve customers do. Now that our migration of Super Bot Fight Mode to the new <a href="https://www.cloudflare.com/learning/ddos/glossary/web-application-firewall-waf/">WAF</a> is complete, we plan to do the same for the original Bot Fight Mode to allow more free customers than ever before to join us in the fight against bots.</p> ]]></content:encoded>
            <category><![CDATA[Security Week]]></category>
            <category><![CDATA[Bots]]></category>
            <category><![CDATA[Bot Fight Mode]]></category>
            <guid isPermaLink="false">7eVoKVVwvc2sxvmuAfkQzg</guid>
            <dc:creator>Adam Martinetti</dc:creator>
        </item>
        <item>
            <title><![CDATA[More bots, more trees]]></title>
            <link>https://blog.cloudflare.com/more-bots-more-trees/</link>
            <pubDate>Wed, 14 Dec 2022 14:00:00 GMT</pubDate>
            <description><![CDATA[ Cloudflare’s Bot Fight Mode caught 6x more bots in 2022, and we’re contributing to a new tree planting project in West Bengal. ]]></description>
            <content:encoded><![CDATA[ <p><i></i></p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2SFWx66fKc0jXFhGX6WURT/51fe4c5a01f880180c52c7c2be9882cc/image2-27.png" />
            
            </figure><p>Once a year, we pull data from our Bot Fight Mode to determine the number of trees we can donate to our partners at One Tree Planted. It's part of the <a href="/cleaning-up-bad-bots/">commitment</a> we made in 2019 to deter malicious bots online by redirecting them to a challenge page that requires them to perform computationally intensive, but meaningless tasks. While we use these tasks to drive up the bill for bot operators, we account for the carbon cost by planting trees.</p><p>This year when we pulled the numbers, we saw something exciting. While the number of bot detections has gone significantly up, the time bots spend in the Bot Fight Mode challenge page has gone way down. We’ve observed that bot operators are giving up quickly, and moving on to other, unprotected targets. Bot Fight Mode is getting smarter at detecting bots and more efficient at deterring bot operators, and that’s a win for Cloudflare and the environment.</p>
    <div>
      <h3>What’s changed?</h3>
      <a href="#whats-changed">
        
      </a>
    </div>
    <p>We’ve seen two changes this year in the Bot Fight Mode results. First, the time attackers spend in Bot Fight Mode challenges has reduced by 166%. Many bot operators are disconnecting almost immediately now from Cloudflare challenge pages. We expect this is because they’ve noticed the sharp cost increase associated with our CPU intensive challenge and given up. Even though we’re seeing individual bot operators give up quickly, Bot Fight Mode is busier than ever. We’re issuing six times more CPU intensive challenges per day compared to last year, thanks to a new detection system written using Cloudflare’s ruleset engine, detailed below.</p>
    <div>
      <h3>How did we do this?</h3>
      <a href="#how-did-we-do-this">
        
      </a>
    </div>
    <p>When Bot Fight Mode launched, we highlighted one of our core detection systems:</p><blockquote><p><i>“Handwritten rules for simple bots that, however simple, get used day in, day out.”</i></p></blockquote><p>Some of them are still very simple. We introduce new simple rules regularly when we detect new software libraries as they start to source a significant amount of traffic. However, we started to reach the limitations of this system. We knew there were sophisticated bots out there that we could identify easily, but they shared enough overlapping traits with good browser traffic that we couldn’t safely deploy new rules to block them safely without potentially impacting our customers’ good traffic as well.</p><p>To solve this problem, we built a new rules system written on the same highly performant Ruleset Engine that powers <a href="/new-waf-experience/">the new WAF</a>, <a href="/transform-http-response-headers/">Transform Rules</a>, and <a href="/introducing-cache-rules/">Cache Rules</a>, rather than the old <a href="/cloudflare-bot-management-machine-learning-and-more/">Gagarin heuristics engine</a> that was fast but inflexible. This new framework gives us the flexibility we need to write highly complex rules to catch more elusive bots without the risk of interfering with legitimate traffic. The data gathered by these new detections are then labeled and used to train our <a href="/machine-learning-mobile-traffic-bots/">Machine Learning engine</a>, ensuring we will continue to catch these bots as their operators attempt to adapt.</p>
    <div>
      <h3>What’s next?</h3>
      <a href="#whats-next">
        
      </a>
    </div>
    <p>We’ve heard from Bot Fight Mode customers that they need more flexibility. Website operators now expect a significant percentage of their legitimate traffic to come from automated sources, like service to service APIs. These customers are waiting to enable Bot Fight Mode until they can tell us what parts of their website it can run on safely. In 2023, we will give everyone the ability to write their own flexible Bot Fight Mode rules, so that every Cloudflare customer can join the fight against bots!</p>
    <div>
      <h3>Update: Mangroves, Climate Change &amp; economic development</h3>
      <a href="#update-mangroves-climate-change-economic-development">
        
      </a>
    </div>
    
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2eTGp8yd0bXgNsWWZ9VOPm/74ea0d252310c699ef3909e01ed6b4e0/image1-29.png" />
            
            </figure><p>Source: One Tree Planted</p><p>We're also pleased to report the second tree planting project from our 2021 bot activity is now complete! Earlier this year, Cloudflare <a href="/35-000-new-trees-in-nova-scotia/">contributed</a> 25,000 trees to a restoration project at Victoria Park in Nova Scotia.</p><p>For our second project, we donated 10,000 trees to a much larger restoration project on the eastern shoreline of Kumirmari island in the Sundarbans of West Bengal, India. In total, the project included more than 415,000 trees along 7.74 hectares of land in areas that have been degraded or deforested. The types of trees planted included Bain, Avicennia officianalis, Kalo Bain, and eight others.</p><p>The Sundarbans are located on the delta of the Ganges, Brahmaptura, and Meghna rivers on the Bay of Bengal, and are home to one of the world's largest mangrove forests. The forest is not only a <a href="https://whc.unesco.org/en/list/798/">UNESCO World Heritage</a> site, but also home to 260 bird species as well as a number of threatened species like the Bengal tiger, the estuarine crocodile, and Indian python. According to <a href="https://onetreeplanted.org/">One Tree Planted</a>, the Sundarbans are currently under threat from rising sea levels, increasing salinity in the water and soil, cyclonic storms, and flooding.</p><p>The Intergovernmental Panel on Climate Change (IPCC) has found that mangroves are critical to mitigating greenhouse gas (GHG) emissions and protecting coastal communities from extreme weather events caused by climate change. The Sundarbans mangrove forest is one of the world's largest carbon sinks (an area that absorbs more carbon than it emits). One <a href="https://www.nature.com/articles/s41598-022-11716-5#:~:text=Recent%20researchers%20have%20evaluated%20that,0.5%E2%80%933%20m%20depth17.">study</a> suggested that coastal mangrove forests sequester carbon at a rate of two to four times that of a mature tropical or subtropical forest region.</p><p>One of the most exciting parts of this project was its focus on hiring and empowering local women. According to One Tree Planted, 75 percent of those involved in the project were women, including 85 women employed to monitor and manage the planting site over a five-month period. Participants also received training in the seed collection process with the goal of helping local residents lead mangrove planting from start to finish in the future.</p>
    <div>
      <h3>More bots stopped, more trees planted!</h3>
      <a href="#more-bots-stopped-more-trees-planted">
        
      </a>
    </div>
    <p>Thanks to every Cloudflare customer who’s enabled Bot Fight Mode so far. You’ve helped make the Internet a better place by stopping malicious bots, and you’ve helped make the planet a better place by reforesting the Earth on bot operators’ dime. The more domains that use Bot Fight Mode, the more trees we can plant, so <a href="https://dash.cloudflare.com/signup">sign up for Cloudflare</a> and <a href="https://developers.cloudflare.com/bots/get-started/free/#enable-bot-fight-mode">activate Bot Fight Mode</a> today!</p> ]]></content:encoded>
            <category><![CDATA[Impact Week]]></category>
            <category><![CDATA[Sustainability]]></category>
            <category><![CDATA[Bots]]></category>
            <category><![CDATA[Bot Fight Mode]]></category>
            <category><![CDATA[Policy & Legal]]></category>
            <guid isPermaLink="false">6iUGyPq3gBlCtJErYjEyM2</guid>
            <dc:creator>Adam Martinetti</dc:creator>
            <dc:creator>Patrick Day</dc:creator>
        </item>
        <item>
            <title><![CDATA[25,000 new trees in Nova Scotia]]></title>
            <link>https://blog.cloudflare.com/25-000-new-trees-in-nova-scotia/</link>
            <pubDate>Wed, 13 Jul 2022 13:00:00 GMT</pubDate>
            <description><![CDATA[ Cloudflare is proud to announce the first 35,000 trees from our commitment to help clean up bad bots (and the climate) have been planted ]]></description>
            <content:encoded><![CDATA[ <p>Cloudflare is proud to announce the first 25,000 trees from our commitment to help <a href="/cleaning-up-bad-bots/">clean up bad bots (and the climate</a>) have been planted.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1IX7Cf2mOtF4ZfbQ4FbgQb/4437a14648c2e148e849e2c2a207d3fe/Screenshot-2022-07-13-at-13.52.00.png" />
            
            </figure><p>Working with our partners at <a href="https://onetreeplanted.org/">One Tree Planted (OTP)</a>, Cloudflare was able to support the restoration of 20 hectares of land at <a href="https://www.victoriaparktruro.ca/">Victoria Park</a> in Nova Scotia, Canada. The 130-year-old natural woodland park is located in the heart of Truro, NS, and includes over 3,000 acres of hiking and biking trails through natural gorges, rivers, and waterfalls, as well as an old-growth eastern hemlock forest.</p><p>The planting projects added red spruce, black spruce, eastern white pine, eastern larch, northern red oak, sugar maple, yellow birch, and jack pine to two areas of the park. The first area was a section of the park that recently lost a number of old conifers due to insect attacks. The second was an area previously used as a municipal dump, which has since been covered by a clay cap and topsoil.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4PgH1H6yaMcwBrcXB2i2Wz/f257025dd25e930fafb8463ef56edd6f/image5-5.png" />
            
            </figure><p>Our tree commitment began far from the Canadian woodlands. In 2019, we launched an ambitious tool called <a href="/cleaning-up-bad-bots/">Bot Fight Mode</a>, which for the first time <i>fought back</i> against bots, targeting <a href="https://www.cloudflare.com/learning/bots/what-is-content-scraping/">scrapers</a> and other automated actors.</p><p>Our idea was simple: preoccupy bad bots with nonsense tasks, so they cannot attack real sites. Even better, make these tasks <i>computationally expensive</i> to engage with. This approach is effective, but it forces bad actors to consume more energy and likely emit more greenhouse gasses (GHG). So in addition to launching Bot Fight Mode, we also committed to supporting tree planting projects to account for any potential environmental impact.</p>
    <div>
      <h3>What is Bot Fight Mode?</h3>
      <a href="#what-is-bot-fight-mode">
        
      </a>
    </div>
    <p>As soon as Bot Fight Mode is enabled, it immediately starts challenging <a href="https://www.cloudflare.com/learning/bots/what-is-a-bot/">bots</a> that visit your site. It is available to all Cloudflare customers for free, regardless of <a href="https://www.cloudflare.com/plans/">plan</a>.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4ZOQWetnhYb0G06xisWK7i/1bd764cd2d9459492d80e9ef8f166edc/image4-5.png" />
            
            </figure><p>When Bot Fight Mode identifies a bot, it issues a <i>computationally expensive</i> challenge to exhaust it (also called “tarpitting"). Our aim is to disincentivize attackers, so they have to find a new hobby altogether. When we tarpit a bot, we require a significant amount of compute time that will stall its progress and result in a hefty server bill. Sorry not sorry.</p><p>We do this because bots are leeches. They draw resources, slow down sites, and abuse online platforms. They also <a href="https://www.cloudflare.com/learning/bots/what-is-credential-stuffing/">hack into accounts</a> and steal personal data. Of course, we allowlist a small number of <a href="https://www.cloudflare.com/learning/bots/how-to-manage-good-bots/">bots that are well-behaved</a>, like Slack and Google. And Bot Fight Mode only acts on traffic from cloud and hosting providers (because that is where bots usually originate from).</p><p><b>Over 550,000 sites use Bot Fight Mode today!</b> We believe this makes it the most widely deployed <a href="https://www.cloudflare.com/products/bot-management/">bot management solution</a> in the world (though this is impossible to validate). Free customers can enable the tool <a href="https://dash.cloudflare.com/?zone=security/bots">from the dashboard</a> and paid customers can use a special version, known as <a href="/super-bot-fight-mode/">Super Bot Fight Mode</a>.</p>
    <div>
      <h3>How many trees? Let's do the math ?</h3>
      <a href="#how-many-trees-lets-do-the-math">
        
      </a>
    </div>
    <p>Now, the hard part: how can we translate bot challenges into a specific number of trees that should be planted? Fortunately, we can use a series of unit conversions, similar to those we used to calculate Cloudflare’s total GHG emissions.</p><p>We started with the following assumptions.</p><p>Table 1.</p><table><tr><td><p><b>Measure</b></p></td><td><p><b>Quantity</b></p></td><td><p><b>Scaled</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>Energy used by a standard server</p></td><td><p>1,760.3 kWh / year</p></td><td><p>To hours (0.2 kWh / hour)</p></td><td><p><a href="http://web.archive.org/web/20230401003729/https://www.goclimate.com/about">Go Climate</a></p></td></tr><tr><td><p>Emissions factor</p></td><td><p>0.33852 kgCO2e / kWh</p></td><td><p>To grams (338.52 gCO2e / kWh)</p></td><td><p><a href="http://web.archive.org/web/20230401003729/https://www.goclimate.com/about">Go Climate</a></p></td></tr><tr><td><p>CO2 absorbed by a mature tree</p></td><td><p>48 lbsCO2e / year</p></td><td><p>To kilograms (21 kgCO2e / year)</p></td><td><p><a href="http://web.archive.org/web/20230401003729/https://onetreeplanted.org/pages/carbon-footprint">One Tree Planted</a></p></td></tr></table><p>Next, we selected a high-traffic day to model the rate and duration of bot challenges on our network. On May 23, 2021, Bot Fight Mode issued 2,878,622 challenges, which lasted an average of 50 seconds each. In total, bots spent 39,981 hours engaging with our network defenses, or more than four years of challenges in a single day!</p><p>We then converted that time value into kilowatt-hours (kWh) of energy based on the rate of power consumed by our generic server listed in Table 1 above.</p><blockquote><p>39,981 (hours) x .2 (kWh/hour) = 7,996 (kWh)</p></blockquote><p>Once we knew the total amount of energy consumed by bad bot servers, we used an emissions factor (the amount of greenhouse gasses emitted per unit of energy consumed) to determine total emissions.</p><blockquote><p>7,996 (kwh) x 338.52 (gCO2e/kwh) = 2,706,805 (gCO2e)</p></blockquote><p>If you have made it this far, clearly you like to geek out like we do, so for the sake of completeness, the unit commonly used in emissions calculations is carbon dioxide <i>equivalent</i> (CO2e), which is a composite unit for all six GHGs listed in the Kyoto Protocol weighted by <a href="https://www.epa.gov/ghgemissions/understanding-global-warming-potentials">Global Warming Potential</a>.</p><p>The last conversion we needed was from emissions to trees. Our partners at OTP found that a mature tree absorbs roughly 21 kgCO2e per year. Based on our total emissions that translates to roughly 47,000 trees per server, or 840 trees per CPU core. However, in our original post, we also noted that given the time it takes for a newly planted tree to reach maturity, we would multiply our donation by a factor of 25.</p><p>In the end, over the first two years of the program, we calculated that we would need approximately 42,000 trees to account for all the individual CPU cores engaged in Bot Fight Mode. For good measure, we rounded up to an even 50,000.</p><p>We are proud that most of these trees are already in the ground, and we look forward to providing an update when the final 25,000 are planted.</p>
    <div>
      <h3>A piece of the puzzle</h3>
      <a href="#a-piece-of-the-puzzle">
        
      </a>
    </div>
    <blockquote><p>"Planting trees will benefit species diversity of the existing forest, animal habitat, greening of reclamation areas as well as community recreation areas, and visual benefits along popular hiking/biking trail networks."  - <b>Stephanie Clement, One Tree Planted, Project Manager North America</b></p></blockquote><p>Reforestation is an important part of protecting healthy ecosystems and promoting biodiversity. Trees and forests are also a fundamental part of helping to slow the growth of global GHG emissions.</p><p>However, we recognize there is no single solution to the climate crisis. As part of our mission to help build a better, more sustainable Internet, Cloudflare is investing in <a href="/cloudflare-committed-to-building-a-greener-internet/">renewable energy</a>, tools that help our customers understand and mitigate their own <a href="/understand-and-reduce-your-carbon-impact-with-cloudflare/">carbon footprints</a> on our network, and projects that will help offset or remove <a href="/cloudflare-committed-to-building-a-greener-internet/">historical emissions</a> associated with powering our network by 2025.</p><p><b>Want to be part of our bots &amp; trees effort</b>? <a href="https://developers.cloudflare.com/bots/get-started/free/">Enable Bot Fight Mode today</a>! It’s available on our free plan and takes only a few seconds. By the time we made our first donation to OTP in 2021, Bot Fight Mode had already spent more than 3,000 years distracting bots. That is enough time to watch Stanley Kubrick’s <a href="https://www.imdb.com/title/tt0081505/"><i>The Shining</i></a> more than 10 million times.</p><p>Help us defeat bad bots and improve our planet today!</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/70LcuDqcrv0Ep09Ik6M4pD/66cc6dd215f2a66a78d74b9757ebba27/image1-1.jpg" />
            
            </figure><p><i>—-For more information on Victoria Park, please visit</i> <a href="https://www.victoriaparktruro.ca/"><i>https://www.victoriaparktruro.ca</i></a><i>For more information on One Tree Planted, please visit</i> <a href="https://onetreeplanted.org/"><i>https://onetreeplanted.org</i></a><i>For more information on sustainability at Cloudflare, please visit</i> <a href="https://www.cloudflare.com/impact/"><i>www.cloudflare.com/impact</i></a></p> ]]></content:encoded>
            <category><![CDATA[Bot Fight Mode]]></category>
            <category><![CDATA[Bots]]></category>
            <category><![CDATA[Sustainability]]></category>
            <category><![CDATA[Product News]]></category>
            <category><![CDATA[Bot Management]]></category>
            <category><![CDATA[Policy & Legal]]></category>
            <guid isPermaLink="false">6ezajd9Yhr17KZeZnratSh</guid>
            <dc:creator>Patrick Day</dc:creator>
            <dc:creator>Ben Solomon</dc:creator>
        </item>
        <item>
            <title><![CDATA[Introducing Super Bot Fight Mode]]></title>
            <link>https://blog.cloudflare.com/super-bot-fight-mode/</link>
            <pubDate>Fri, 26 Mar 2021 13:01:00 GMT</pubDate>
            <description><![CDATA[ Beginning immediately, any Cloudflare user with a Pro or Business site can take new action against bots. We’ve added advanced features in the dashboard and some exciting updates to analytics.
 ]]></description>
            <content:encoded><![CDATA[ <p></p><p>Almost half of the Internet’s traffic is powered by <a href="https://www.cloudflare.com/learning/bots/what-is-a-bot/">bots</a>. Bots have scoured the net for years, relentlessly hacking into bank accounts, scooping up Bruno Mars tickets, and <a href="https://www.cloudflare.com/learning/ai/how-to-prevent-web-scraping/">scraping websites for data</a>. The problem is so widespread that we <a href="/cleaning-up-bad-bots/">launched Bot Fight Mode</a> in 2019 to fight back. Since then, over 150,000 individuals and small businesses have used the product, and we’ve received countless requests for more functionality. More analytics, more detections, and more controls.</p><p>Introducing Super Bot Fight Mode.</p><p>Beginning immediately, any Cloudflare user with a Pro or Business site can take new action against bots. We’ve added advanced features in the dashboard and some exciting updates to analytics. Free customers will retain all the benefits they've enjoyed with Bot Fight Mode, and our Enterprise Bot Management product will continue to push the needle on innovation.</p>
    <div>
      <h2>In the Dashboard</h2>
      <a href="#in-the-dashboard">
        
      </a>
    </div>
    <p>Our bot solutions have a new home. The features we discuss in this blog post go beyond a single toggle, so we created a <a href="https://dash.cloudflare.com/?to=/:account/:zone/security/bots">hub for bot protection</a>. Head to the Firewall app and select the “Bots” subtab to get started.</p><p>The new hub is live for all users, including those with Enterprise Bot Management.</p>
    <div>
      <h2>Pro Plan Features</h2>
      <a href="#pro-plan-features">
        
      </a>
    </div>
    <p>First up: we’re bringing our popular Bot Report to the Pro plan. Here, you can see a breakdown of your bot traffic, updated in real time to help you spot attacks.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5fkfog1L8NsIUuaUccMIaO/1de2a5afb05711a96d542a42d0fe91f8/Bot-Report-current.png" />
            
            </figure><p>The Bot Report includes three traffic types:</p><ol><li><p><b>Likely automated</b> traffic may have come from bad bots. We use <a href="https://developers.cloudflare.com/bots/about/plans/biz-and-ent#bot-detection-engines">heuristics, machine learning, and other techniques</a> to spot these requests. In most cases, this traffic will hurt your site without providing anything useful in return.</p></li><li><p><b>Likely human</b> traffic is legitimate and important. Ideally, the vast majority of your traffic matches this type.</p></li><li><p><b>Verified bot</b> traffic comes from good bots on the Internet. We have verified search crawlers like Google and payment notification services like PayPal. Most users choose to allow this traffic.</p></li></ol><p>All of this data is available via <a href="https://developers.cloudflare.com/analytics/graphql-api">GraphQL</a> as well. So if you are looking to routinely monitor bot traffic, the API will help you do so.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3fC40ELymoITRnhbP2Q1yp/b5886f995047b637790fab7a789639af/Bot-Monitoring.png" />
            
            </figure><p>Pro users can also do more to stop bots — select “Configure Super Bot Fight Mode” to add protection. Highlights include:</p><ul><li><p>The option to <b>challenge or block</b> traffic from “definitely automated” sources. Note that this will only affect the traffic we are most confident comes from bots.</p></li><li><p>The option to enable <b>JavaScript Detections</b> to identify headless browsers and other actors on the Internet.</p></li><li><p>The option to <b>include or exclude verified bots</b> from protection.</p></li></ul><p>If your site interacts with Slack, for example, you can exclude verified bots to help Slackbot do its job. Or if you notice an increase in ad fraud, try challenging automated traffic and watch the results.</p>
    <div>
      <h2>Business Plan Features</h2>
      <a href="#business-plan-features">
        
      </a>
    </div>
    <p>Bot Analytics is now included with the <a href="https://www.cloudflare.com/plans/business/">Business plan</a>.</p><p>We originally <a href="/introducing-bot-analytics/">launched Bot Analytics</a> to give our Enterprise users more visibility. Since the launch, however, Business users have asked us for many of the same insights. And because Cloudflare has always tried to democratize technology (as we’ve done with <a href="/supercharging-firewall-events-for-self-serve/">Firewall Events</a> and other products), this is something we had to do.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4oUJwyEWWlIZBTposcD6C7/cd661bdaf6ef3e569b05d862fde88b97/Bot-Analytics-biz-current.png" />
            
            </figure><p>Business users can access a new version of Bot Analytics; one that is designed to work with the mitigation tools described below. Users can view traffic by type, adjust the time frame, and filter by different attributes like IP address or user agent.</p><p>Another perk: Bot Analytics shows <i>how</i> we categorize traffic. Scroll to “requests by detection source” to understand which engine flagged a particular request. If you want to learn more about our detection engines, check out our <a href="/cloudflare-bot-management-machine-learning-and-more/">blog post</a> on the topic.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7gIDGyuh0xnxxXs14DJAPQ/7d9e00b585c49643bed99c52b018195f/image1-42.png" />
            
            </figure><p>Of course, we also added new mitigation features. While Pro users can defend against “definitely automated” traffic, Business users can also target “likely automated” traffic. What’s the difference? The latter includes requests scored by our <a href="https://developers.cloudflare.com/bots/about/plans/biz-and-ent#machine-learning">machine learning engine</a>. These requests often come from sophisticated bots — the ones that evade simple security tools by rotating IPs or convincingly imitating humans.</p><p>Perhaps your site suffers from inventory hoarding. You list items for sale, but they are almost immediately claimed by bots. Understandably, your customers are upset (and so are you!). Go ahead and use Bot Analytics to pinpoint the attacker, and if the attack falls under “likely automated,” consider blocking this traffic.</p><p>We also realize that different sites may have different sensitivities to bot traffic. Users can respond appropriately by issuing a challenge, blocking entirely, or doing nothing at all.</p>
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7dfm7PoILrZ5z82iWQDffC/f8335a9589dde8d06e24f3c93ca9f40f/configure-biz-current.png" />
            
            </figure><p>These features are all included in the Cloudflare Business plan. Once you enable mitigation, check your Firewall Events tab to watch traffic get blocked or challenged.</p>
    <div>
      <h2>Enterprise Bot Management</h2>
      <a href="#enterprise-bot-management">
        
      </a>
    </div>
    <p>For those with more advanced security needs, <a href="https://www.cloudflare.com/products/bot-management">Bot Management</a> remains the gold standard. And it’s only getting better.</p><p>Unlike Bot Fight Mode, Bot Management is built directly into the Firewall. This means that users can restrict their bot protection to a particular path (like a /login endpoint). Bot Management also includes granular bot scores, which users can <a href="https://developers.cloudflare.com/firewall/recipes/challenge-bad-bots">pair with other attributes</a> to produce more powerful protection. It even includes <a href="https://developers.cloudflare.com/bots/about/plans/bm-subscription#anomaly-detection">Anomaly Detection</a>, which we use to recognize outlier patterns on your site.</p><p>We also continue to improve Bot Management. For example, just moments ago, we announced <a href="/api-abuse-detection/">early access to API Abuse Detection</a>. This announcement follows months of research and development. We’re using unsupervised learning to map out APIs, identify legitimate user flows, and keep out bad bots. The end result: Cloudflare will be able to protect your mobile apps (without an SDK) and secure your API endpoints (without any provided schema). <a href="/api-abuse-detection/">Read more</a> about the early access period.</p><p>These features (and countless others) will continue to guard the Internet’s largest sites. If you think you need Bot Management, <a href="https://www.cloudflare.com/lp/automated-bot-traffic-report/">let us know</a>.</p>
    <div>
      <h2>Helping to Build a Better Internet</h2>
      <a href="#helping-to-build-a-better-internet">
        
      </a>
    </div>
    
            <figure>
            
            <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1w5n72gvJFtX7IOOXxREO3/dae17c0b9406d5f27cfbad288bc91512/Group-1338.png" />
            
            </figure><p>Cloudflare’s goal has always been to help build a better Internet. This mission extends to every part of the Internet — and to every person who uses it.</p><p>Today’s introduction of Super Bot Fight Mode was born from this mission, particularly from the idea that we are stronger as a united front against bots. Each website we protect is one that bots will waste their resources on. At Cloudflare, we are actively fighting back, and unleashing new challenges that will disincentivize bot operation with tarpitting.</p><p>We encourage you to enable Super Bot Fight Mode today. Cloudflare now offers bot protection with every plan (including Free), so there’s no excuse not to try it! Test the new features and let us know what you think.</p> ]]></content:encoded>
            <category><![CDATA[Bots]]></category>
            <category><![CDATA[Bot Fight Mode]]></category>
            <category><![CDATA[Bot Management]]></category>
            <category><![CDATA[Security Week]]></category>
            <category><![CDATA[Product News]]></category>
            <guid isPermaLink="false">5mqfk6sJZIkNwQzpPabYlt</guid>
            <dc:creator>Ben Solomon</dc:creator>
        </item>
    </channel>
</rss>