Cloudflare Launches Application Profiles for Positive Security
Cloudflare introduces Application Profiles to enforce positive security policies, reducing the attack surface area for web applications.
Cloudflare has launched Application Profiles, a feature that enforces positive security policies for web applications. It analyzes HTTP requests to identify deviations and reduce the attack surface area. This is particularly aimed at protecting against attacks using frontier AI models.
Key facts
| Fact | Detail | The source says |
|---|---|---|
| Feature Name | Application Profiles | “Today, we are launching Application Profiles, a seamless way to enforce a positive security policy.” |
| Primary Goal | Reduce attack surface area | “By analyzing the structure and format of HTTP requests and identifying deviations, Cloudflare can help you significantly reduce the attack…” |
| Supported Features | Paths, query parameters, headers, cookies, JSON request bodies, form-encoded request bodies | “The feature supports paths, query parameters, headers, cookies, JSON request bodies, and form-encoded request bodies.” |
What happened
Cloudflare has introduced Application Profiles, a new feature designed to enforce positive security policies for web applications. By analyzing the structure and format of HTTP requests, Cloudflare can identify deviations and significantly reduce the attack surface area. This feature is particularly aimed at protecting against attacks that use frontier AI models, which can generate malicious payloads and probe applications autonomously. Application Profiles are now available in a closed beta for invited Enterprise customers without API Security, while those with API Security already have access.
What to weigh
- Application Profiles are in closed beta for invited Enterprise customers.
- Does not support multipart forms, GraphQL, and XML.
Source: cloudflare
