Cloudflare is introducing two new WAF capabilities to eliminate the traditional log-versus-block trade-off. Attack Signature Detection runs all detection signatures on every request continuously, attaching rich metadata before any action is taken, so security teams gain full visibility without sacrificing protection or performance. Full-Transaction Detection goes further by correlating both HTTP request and response data to confirm successful exploits, detect data exfiltration, and surface misconfigurations that request-only systems miss. Both features separate detection from mitigation, allowing teams to build precise blocking policies based on historical traffic data rather than guesswork. Attack Signature Detection is in Early Access; Full-Transaction Detection is under development.

13m read timeFrom blog.cloudflare.com
Post cover image
Table of contents
The always-on frameworkAttack Signature DetectionFull-Transaction DetectionSign up to get access

Sort: