Cybercriminals have an annoying economic advantage. Automated attacks can be launched cheaply, modified quickly, and repeated endlessly, while defenders have to successfully stop them without locking legitimate people out of websites.
Cloudflare thinks it can change that equation. You see, the company today announced Adaptive Intelligence, a new detection engine built into Cloudflare Bot Management. Rather than relying entirely on defenses that remain relatively static until the next update arrives, the technology is designed to continuously learn from traffic across Cloudflare’s network and adapt as attackers change their tactics.
The idea is surprisingly straightforward. If attackers can repeatedly probe a defense, learn what gets blocked, and adjust their bots accordingly, a static security system effectively gives them a target to study. Cloudflare wants that target to keep moving.
Adaptive Intelligence analyzes signals collected across Cloudflare’s network, including request patterns, TLS fingerprints, challenge results, session behavior, and network reputation. Cloudflare says it analyzes more than a trillion requests per day, giving its models a considerable amount of traffic from which to identify patterns.
The machine learning system at the heart of Adaptive Intelligence continuously retrains using live traffic. That should allow Cloudflare to incorporate newly observed bot frameworks and bypass techniques without waiting for the traditional cycle of manually releasing another model version.
Cloudflare eventually plans to take the idea further with what it calls “disposable rules.” Instead of creating a detection rule and leaving it sitting there for an attacker to reverse engineer, Adaptive Intelligence is being designed to generate narrowly targeted rules that appear and disappear over time.
That could make attacking a Cloudflare-protected service considerably more frustrating. An attacker might spend time figuring out why a bot stopped working, make the necessary changes, and discover that the defense it just defeated has already disappeared or changed.
There is an important distinction between what Cloudflare is announcing and what customers actually get today, however. Continuous machine learning retraining is launching now. The automatic disposable-rule generation and additional learning capabilities described by Cloudflare are still being developed and will arrive later.
The system is also intended to look beyond obvious bursts of malicious traffic. By evaluating activity across different periods of time, Cloudflare says Adaptive Intelligence can identify slower distributed attacks such as credential stuffing that might otherwise appear harmless when individual requests are examined separately.
Automatically changing security defenses introduces another problem: false positives. A system that becomes extremely good at stopping bots isn’t particularly useful if it also starts throwing real customers out.
Cloudflare says new models are therefore tested against live traffic in the background before becoming the primary defense. The company compares their results against the existing model and monitors signals such as challenge solve rates. A replacement that performs worse at identifying legitimate visitors should not be promoted.
Adaptive Intelligence also works alongside Precursor, Cloudflare’s browser-level behavioral system. The combination gives Cloudflare signals about what happens at the network level as well as how a visitor behaves during a session.
For customers, Cloudflare is trying to keep the transition relatively boring. Enterprise Bot Management customers can enable “Auto Update Machine Learning” and continue using the existing bot score rather than migrating applications to an entirely different security system.
Whether Adaptive Intelligence actually makes attacks economically unattractive will depend on how well the system performs once attackers deliberately start trying to fool it. Cybersecurity is an endless game of adaptation, and attackers aren’t going to stop experimenting because Cloudflare introduced a new machine learning model.
But that is essentially Cloudflare’s point. Instead of pretending it can build a wall that attackers will never climb, the company wants to make them rebuild the ladder every time they try.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz