Knowledge Hub · Security

How does Cloudflare, managed by FirstNet, stop bad bots and protect APIs?

Web Application & DDoS Protection · Answered by FirstNet Technology Services

Short answer

Cloudflare Bot Management uses machine-learning bot scoring, JavaScript challenges and mobile signals to stop automated abuse such as credential stuffing, scraping, inventory hoarding and fake sign-ups. API Shield protects APIs with schema validation, mutual TLS, JWT validation, sequence analytics and abuse detection, covering risks a traditional web application firewall can miss.

In detail

What each control does:

  • Bot scoring rates how likely each request is to be automated, so policies can challenge or block suspect traffic while letting real users through
  • Challenges test suspicious clients before they reach your application
  • Schema validation rejects API calls that do not match the expected structure
  • Mutual TLS and JWT validation confirm that API clients are who they claim to be
  • Sequence analytics spots abnormal patterns of API calls that point to abuse

Both run on the same platform as Cloudflare's WAF and DDoS protection, with one dashboard, and FirstNet tunes the policies as part of the managed service.

Bot Management suits retail and e-commerce sites facing credential stuffing or inventory hoarding, while API Shield suits organisations whose application surface has shifted towards APIs that the WAF no longer fully covers.

Source: FirstNet Web Application & DDoS Protection service page →

Didn’t answer your question?

Call