blog.cloudflare.com 29 Sept 2026, 13:00 UTC

Cloudflare Uses Learned App Profiles to Block Malformed Requests

Cloudflare Uses Learned App Profiles to Block Malformed Requests
CyberSIXT Evidence Panel Source marked as original reporting

CLOUDFLARE has introduced Application Profiles to enforce a positive security policy by learning the expected structure of HTTP requests and then validating live traffic against that profile. The approach concentrates on what good requests look like rather than solely detecting known attacks, with the goal of dramatically reducing the attack surface.

After onboarding an application, Cloudflare learns its profile and deploys an always-on validation layer that annotates each request with metadata indicating conformity. The validation signal itself does not block traffic automatically; users review analytics in Security Analytics and create Security Rules to block non-conforming requests as appropriate.

Profiles are learned by observing web or API traffic and periodically updating to reflect changes in the application. To begin learning, an operation must have a minimum amount of qualifying traffic (at least 1,000 requests with 2xx responses in the prior seven days to learn fields, and at least 10,000 to learn data boundaries). Once learned, fields such as path variables, query parameters, headers, cookies, and body structure (JSON or form-encoded) are captured with data types and constraints.

Validation can identify non-conforming inputs, including strings in place of integers, values outside learned ranges, or malformed UUIDs. The learned schema can be viewed in the dashboard, exported as OpenAPI v3, and used to drive Security Rules that block or monitor violations. The feature currently supports various request components but does not cover multipart forms, GraphQL, or XML, and protection can be scoped to specific fields or operations. Security Analytics also offers a Profile Analysis view to track conforming versus non-conforming traffic before enforcement.

View full article

Article by CyberSIXT