A new WAF experience
Cloudflare » Firewall
by Zhiyuan Zheng
10M ago
This post is also available in 简体中文, 繁體中文, 日本語, 한국어, Deutsch, Français, Español, Italiano. Around three years ago, we brought multiple features into the Firewall tab in our dashboard navigation, with the motivation “to make our products and services intuitive.” With our hard work in expanding capabilities offerings in the past three years, we want to take another opportunity to evaluate the intuitiveness of Cloudflare WAF (Web Application Firewall). Our customers lead the way to new WAF The security landscape is moving fast; types of web applications are growing rapidly; and within the indus ..read more
Visit website
Replace your hardware firewalls with Cloudflare One
Cloudflare » Firewall
by Ankur Aggarwal
10M ago
This post is also available in 简体中文, 日本語, 한국어, Deutsch, Français, Bahasa Indonesia, ไทย. Today, we’re excited to announce new capabilities to help customers make the switch from hardware firewall appliances to a true cloud-native firewall built for next-generation networks. Cloudflare One provides a secure, performant, and Zero Trust-enabled platform for administrators to apply consistent security policies across all of their users and resources. Best of all, it’s built on top of our global network, so you never need to worry about scaling, deploying, or maintaining your edge security hardwa ..read more
Visit website
PII and Selective Logging controls for Cloudflare’s Zero Trust platform
Cloudflare » Firewall
by Ankur Aggarwal
10M ago
This post is also available in 简体中文, 日本語, bahasa Indonesia, ไทย. At Cloudflare, we believe that you shouldn’t have to compromise privacy for security. Last year, we launched Cloudflare Gateway — a comprehensive, Secure Web Gateway with built-in Zero Trust browsing controls for your organization. Today, we’re excited to share the latest set of privacy features available to administrators to log and audit events based on your team’s needs. Protecting your organization Cloudflare Gateway helps organizations replace legacy firewalls while also implementing Zero Trust controls for their users. Ga ..read more
Visit website
Account Takeover Protection and WAF mitigations to help stop Global Brute Force Campaigns
Cloudflare » Firewall
by Michael Tremante
10M ago
Earlier today a cybersecurity advisory was published by international security agencies identifying widespread attacks against government and private sector targets worldwide. You can read the full report here, which discusses widespread, distributed, and anonymized brute force access attempts since mid-2019 and still active through early 2021. Today, we have rolled out WAF mitigations to protect our customers against these types of attacks. And we are making the exposed credential check feature of Account Takeover Protection available to all paid plans at no additional charge today. We had b ..read more
Visit website
Magic WAN & Magic Firewall: secure network connectivity as a service
Cloudflare » Firewall
by Achiel van der Mandele
10M ago
This post is also available in 简体中文, 繁體中文, 한국어, 日本語, Español, Bahasa Indonesia and ไทย. Back in October 2020, we introduced Cloudflare One, our vision for the future of corporate networking and security. Since then, we’ve been laser-focused on delivering more pieces of this platform, and today we’re excited to announce two of its most foundational aspects: Magic WAN and Magic Firewall. Magic WAN provides secure, performant connectivity and routing for your entire corporate network, reducing cost and operational complexity. Magic Firewall integrates smoothly with Magic WAN, enabling you to en ..read more
Visit website
Using HPKE to Encrypt Request Payloads
Cloudflare » Firewall
by Miguel de Moura
10M ago
The Managed Rules team was recently given the task of allowing Enterprise users to debug Firewall Rules by viewing the part of a request that matched the rule. This makes it easier to determine what specific attacks a rule is stopping or why a request was a false positive, and what possible refinements of a rule could improve it. The fundamental problem, though, was how to securely store this debugging data as it may contain sensitive data such as personally identifiable information from submissions, cookies, and other parts of the request. We needed to store this data in such a way that only ..read more
Visit website
Holistic web protection: industry recognition for a prolific 2020
Cloudflare » Firewall
by Patrick R. Donahue
10M ago
I love building products that solve real problems for our customers. These days I don’t get to do so as much directly with our Engineering teams. Instead, about half my time is spent with customers listening to and learning from their security challenges, while the other half of my time is spent with other Cloudflare Product Managers (PMs) helping them solve these customer challenges as simply and elegantly as possible. While I miss the deeply technical engineering discussions, I am proud to have the opportunity to look back every year on all that we’ve shipped across our application security ..read more
Visit website
Encrypting your WAF Payloads with Hybrid Public Key Encryption (HPKE)
Cloudflare » Firewall
by Michael Tremante
10M ago
The Cloudflare Web Application Firewall (WAF) blocks more than 72B malicious requests per day from reaching our customers’ applications. Typically, our users can easily confirm these requests were not legitimate by checking the URL, the query parameters, or other metadata that Cloudflare provides as part of the security event log in the dashboard. Sometimes investigating a WAF event requires a bit more research and a trial and error approach, as the WAF may have matched against a field that is not logged by default. Not logging all parts of a request is intentional: HTTP headers and payloads ..read more
Visit website
Building even faster interpreters in Rust
Cloudflare » Firewall
by Zak Cutner
10M ago
At Cloudflare, we’re constantly working on improving the performance of our edge — and that was exactly what my internship this summer entailed. I’m excited to share some improvements we’ve made to our popular Firewall Rules product over the past few months. Firewall Rules lets customers filter the traffic hitting their site. It’s built using our engine, Wirefilter, which takes powerful boolean expressions written by customers and matches incoming requests against them. Customers can then choose how to respond to traffic which matches these rules. We will discuss some in-depth optimizations w ..read more
Visit website
Cloudflare Bot Management: machine learning and more
Cloudflare » Firewall
by Alex Bocharov
10M ago
This post is also available in 한국어. Introduction Building Cloudflare Bot Management platform is an exhilarating experience. It blends Distributed Systems, Web Development, Machine Learning, Security and Research (and every discipline in between) while fighting ever-adaptive and motivated adversaries at the same time. This is the ongoing story of Bot Management at Cloudflare and also an introduction to a series of blog posts about the detection mechanisms powering it. I’ll start with several definitions from the Bot Management world, then introduce the product and technical requirements, leadi ..read more
Visit website

Follow Cloudflare » Firewall on FeedSpot

Continue with Google
Continue with Apple
OR