March 2021 Summaries
48 posts from Cloudflare
Filter
Month:
Year:
Post Summaries
Back to Blog
The blog discusses the Annual March Hackness phishing tournament and highlights how the COVID-19 pandemic has influenced attackers' strategies. It mentions that newcomers like WHO, Target, and DocuSign have seen a surge in impersonation attempts due to their relevance during the pandemic. However, established players like Microsoft and Google remain top targets for phishing attacks. The blog also emphasizes that email authentication standards such as SPF, DKIM, and DMARC are not foolproof solutions against brand spoofing and impersonation-based phishing attacks.
Mar 31, 2021
889 words in the original blog post.
Cloudflare has made its Durable Objects beta available for anyone with a Cloudflare Workers® subscription. Durable Objects provide coordination across multiple Workers and strongly consistent edge storage, allowing developers to spend less time configuring databases and more on building app features. The platform is still in beta and users should be aware of the limitations, including capped storage per account at 10 GB and no associated SLA for object availability or durability. Pricing details have been shared, with Durable Objects being significantly cheaper than comparable compute and storage offerings from other major cloud providers.
Mar 31, 2021
1,139 words in the original blog post.
Cloudflare has introduced a new feature for its Zero Trust platform, Cloudflare Access, allowing teams to build rules that only allow users to connect to applications from devices managed by their enterprise. This helps prevent data loss and ensures compliance with security protocols. The solution is designed to work even if an organization does not have a device management platform or mobile device manager (MDM) in place. It involves setting up a list of corporate device serial numbers, deploying the WARP client across these devices, and building Access rules that check if a device's serial number is on the managed devices list. This feature is available for existing Cloudflare customers and can be set up with a free Teams account for new users.
Mar 30, 2021
703 words in the original blog post.
Cloudflare has published blog posts detailing their efforts in securing customer accounts from various forms of account takeover attacks, such as credential stuffing and botnets. The company also uses its own products to prevent account compromises on internal applications. They employ a two-tiered approach: firstly, using Cloudflare products to proactively prevent account breaches; secondly, building detections and automations to alert them if an employee account is compromised. This allows for quick investigation and remediation of suspicious behavior. The blog post also discusses common methods of account takeovers, such as brute force attacks, credential stuffing, botnets, social engineering, and phishing. It provides examples of how companies can prevent these attacks using Cloudflare's products and services.
Mar 30, 2021
1,663 words in the original blog post.
Cloudflare has introduced new features aimed at improving end user account security, including Open Proxy Managed list, Super Bot Fight Mode, Exposed Credential Checks, and Rate Limiting on failed logins. These features can be used in conjunction to increase the protection of authentication endpoints against credential stuffing attacks and other threats. The Open Proxy Managed list helps maintain an updated IP list for access control, while Super Bot Fight Mode keeps automated traffic away from authentication endpoints. Exposed Credential Checks warn users when their credentials have been compromised in a data breach, allowing them to initiate two-factor authentication or password reset processes. Rate Limiting on failed logins helps prevent brute force attacks by slowing down repeated login attempts. These features are designed to be easy to deploy and can significantly enhance end user account security when used together.
Mar 30, 2021
1,643 words in the original blog post.
Cloudflare's Web Application Firewall (WAF) has received the Gartner Peer Insights Customers' Choice distinction for 2021 due to its ease of use, scale, and innovative controls. The positive feedback from customers highlights the effectiveness and reliability of Cloudflare's WAF, which is praised as a partner rather than just a vendor. In 2020, numerous security product releases were made by Cloudflare, including IP lists, payload encryption, customizable firewall rules, API Shield, and gRPC proxy support. The recognition from Gartner Peer Insights underscores the company's commitment to providing top-quality security solutions for its clients.
Mar 30, 2021
485 words in the original blog post.
The new version of Cloudflare's Web Application Firewall (WAF) is now available, offering improved rule browsing and configuration, a new matching engine, updated rulesets, and global configuration capabilities. The WAF blocks over 57 billion cyber threats per day and has received accolades for its ability to execute. The new version aims to enhance performance and security while maintaining ease of use. New features include better filtering and matching capabilities, more control over the sensitivity score, and a paranoia level feature. Additionally, account-based configurations will be available for Enterprise customers.
Mar 29, 2021
1,690 words in the original blog post.
Cloudflare ประกาศวิธีใหม่ในการควบคุมการแก้ไขและการจับคู่ที่เรียบงานด้วยซินแทกซ์ wirefilter และภาษา LuaJIT ในฐานะโมดูล NGINX ซึ่งจะช่วยให้สามารถควบคุมการแก้ไขและการจับคู่ที่ดียิ่งขึ้น และมีความเร็วอีกด้วย ซึ่งเราได้พูดถึงใน Blog นี้ ผู้ใช้สามารถติดต่อไปที่ทีมบัญชีของตน และขอสิทธิ์การเข้าใช้งานล่วงหน้า ซึ่งจะใช้ประโยชน์จาก API หรือเครื่องมือการทำงานอัตโนมัติ เช่น ผู้ให้บริการ Cloudflare Terraform และการปรับใช้งานใหญ่ข้า ซึ่งเราวางแผนที่จะเริ่มเปิดให้ใช้งานในอีกไม่กี่เดือนข้างหน้าในขั้นต้น การกำหดค่าตามบัญชีจะพร้อมใช้งานสำหรับลูกค้าองค์กรเท่านั้น ซึ่งในขณะนี้องค์กรสามารถขอสิทธิ์การเข้าใช้งานล่วงหน้าได้โดยการติดต่อไปที่ทีมบัญชีของตน กฎไฟร์วอลล์แบบกำหดเองจะถูกย้ายไปที่เอนจิ้นใหม่ในไม่ช้า ทำให้ลูกค้าสามารถสร้างกฎไฟร์วอลล์แบบกำหดเอง และทำการใช้งานกฎตัวกรองการรับส่งข้อมูลได้ตามความต้องการแพลตฟอร์มใหม่สำหรับคุณลักษณะใหม่ ผลิตภัณฑ์ที่เราทำเพื่อช่วยสร้างอินเทอร์เน็ตที่ดียิ่งขึ้น ซึ่งเราหวังเป็นอย่างยิ่งว่าจะได้รับความคิดเห็นจากคุณ และเรารู้สึกตื่นเต้นที่จะได้เห็นว่าเราจะสามารถสร้างสรรค์สิ่งใหม่ ๆ ได้เพิ่งขึ้น ๆ ไกลกว่าเดิมได้เพียงใด.......1
REFERENCES:
1. Cloudflare, "Introducing the new and improved WAF," Cloudflare, December 9, 2021, https://www.cloudflare.com/blog/introducing-the-new-and-improved-waf/.
Mar 29, 2021
740 words in the original blog post.
Cloudflare has introduced Advanced Certificate Manager (ACM), a flexible and customizable way to manage certificates on its platform. ACM allows users to modify their certificate's validity period, set cipher suites, and create custom signing requests. The new features aim to improve security posture by encouraging frequent certificate rotation and key updates. With ACM, customers can issue up to 100 edge certificates per zone and choose their preferred validation method and certificate authority. Existing Dedicated Certificate users will be automatically upgraded to ACM with no additional cost for Free, Pro, and Business customers.
Mar 27, 2021
1,445 words in the original blog post.
Cloudflare has announced support for cloud-hosted Hardware Security Modules (HSMs) from major providers, including Amazon Cloud HSM, Google Cloud HSM, IBM Cloud HSM, and Microsoft Azure Dedicated HSM and Managed HSM. This update enables customers with strict information security policies to use private encryption keys stored in these HSMs for securing HTTPS connections at Cloudflare's global edge. Keyless SSL is a protocol that allows TLS handshakes without access to the customer's private keys, mitigating risks associated with key handling and storage. The integration of cloud-hosted HSMs offers enhanced security options for financial services, healthcare, cryptocurrency, and other highly regulated or security-focused companies moving to the cloud.
Mar 27, 2021
1,795 words in the original blog post.
In 2014, a bug called Heartbleed was discovered in OpenSSL, which allowed attackers to read memory from affected servers and extract their TLS/SSL certificate private keys. This event highlighted major issues with how the internet is secured. Since then, Cloudflare has taken lessons from Heartbleed and applied them to improve the design of its systems and the resiliency of the internet overall. Key measures include defense-in-depth strategies for protecting TLS/SSL private keys, Keyless SSL, Geo Key Manager, Delegated Credentials, and improvements in OCSP stapling support. These enhancements have made Cloudflare a leader in the security space and reduced the risk of key compromise and the cost of recovery if it happens.
Mar 27, 2021
1,282 words in the original blog post.
Cloudflare has introduced Super Bot Fight Mode, an advanced feature for combating bots on websites. The new mode is available for Pro and Business site users, offering more analytics, detections, and controls to protect against malicious bots. Key features include the Bot Report, which provides a breakdown of bot traffic in real-time, and enhanced mitigation options for both "definitely automated" and "likely automated" traffic. Additionally, Super Bot Fight Mode is now included with every Cloudflare plan, including Free accounts.
Mar 26, 2021
1,064 words in the original blog post.
Bots on the internet are automated software that replace human interaction, often used for both good and bad purposes such as search engine crawling or attacking a website. The global pandemic has led to an increase in bot activity due to high demand and low supply of certain products. Cloudflare's Bot Management product helps detect and block bots using machine learning models and network data. It has been successful in protecting various parts of their platform, including customer-facing sites, billing systems, and API endpoints. The Super Bot Fight Mode release extends this capability to Pro and Business users, providing a boost across all Bot Management users by training the models more directly with bot signals.
Mar 26, 2021
1,516 words in the original blog post.
Cloudflare has announced early access to API Discovery and API Abuse Detection, aimed at helping businesses protect their APIs from malicious activity. The new features include API Discovery, which maps out an organization's APIs, and two forms of abuse detection - one based on volume anomalies and another using sequential anomaly detection. These tools are designed to help organizations identify and mitigate abusive behavior on their APIs, such as price wars between rideshare services or manipulation of discounts for lattes. The API Abuse Detection technology is also expected to improve Bot Management for mobile apps by detecting abusive behavior without the need for bulky SDKs.
Mar 26, 2021
1,766 words in the original blog post.
Cloudflare introduces Page Shield, a client-side security product designed to detect attacks in end-user browsers. The Magecart hacker group has stolen payment credentials from online stores by infecting third-party dependencies with malicious code. Page Shield helps customers monitor potential attack vectors and prevent confidential user information from falling into the hands of hackers. Existing browser technologies such as Content Security Policy (CSP) and Subresource Integrity (SRI) provide some protection against client-side threats but have drawbacks. The first available feature of Page Shield is Script Monitor, which records a site's JavaScript dependencies over time and alerts customers when new files appear. Cloudflare plans to add code change detection and intelligent analysis of JavaScript files in the future. Business and Enterprise customers can sign up for the closed beta of Page Shield starting today.
Mar 25, 2021
1,204 words in the original blog post.
Cloudflare has introduced Route Leak Detection, a new feature that alerts customers when their onboarded prefixes are being leaked or hijacked by unauthorized parties. Route leaks occur when a network incorrectly advertises routes for traffic that is not supposed to go through them, potentially causing congestion and data leak implications. The detection system helps protect networks from such attacks by providing timely information about route leaks, enabling customers to respond quickly and mitigate the issue. Cloudflare's alert notification system supports webhooks, email, and PagerDuty, ensuring that teams are kept up-to-date across their preferred mediums. The company also encourages the adoption of RPKI (Resource Public Key Infrastructure) as a preventive measure against route leaks.
Mar 25, 2021
1,528 words in the original blog post.
Data exfiltration is a significant threat to businesses, causing financial loss, negative brand association, and legal penalties. Both internal and external threats should be considered when protecting networks from data theft. Insider threats can result from careless users or those ignoring policies, as demonstrated in the Twitter hack of 2020. To mitigate these risks, implementing a multi-layered approach to prevention and monitoring is crucial. Cloudflare's suite of tools, including Access, Gateway, Browser Isolation, and API Shield, can help organizations implement a Zero Trust model and protect their networks from data exfiltration.
Mar 24, 2021
1,258 words in the original blog post.
Cloudflare has announced a new feature in its Web Application Firewall (WAF) to help teams prevent data loss from external-facing applications. This feature scans and blocks responses that contain sensitive data, such as credit card numbers or social security numbers. The company also plans to add more patterns and the ability to search for specific data. Additionally, Cloudflare is working on a solution to scan all traffic leaving devices and locations for data loss without compromising performance. This feature will apply standard, consistent rules around what data can leave an organization regardless of how that traffic arrived in their network.
Mar 24, 2021
1,761 words in the original blog post.
API traffic is growing rapidly, making it a prime target for data theft and abuse. To address this issue, Cloudflare launched API Shield in October 2020, offering various security solutions for API traffic. Today, they are introducing four new features to help reduce the impact of exfiltration attacks: Schema Validation for all Enterprise customers, a managed IP List allowing users to block traffic from Open Proxies, more control over the certificate lifecycle, and a Data Loss Prevention solution. These features aim to protect APIs from exposing sensitive data and enhance overall security.
Mar 24, 2021
2,098 words in the original blog post.
Cloudflare has introduced its Browser Isolation service, which aims to protect internet-connected organizations from security threats by shifting the burden of executing untrusted code from users' devices to a remote isolated browser. The solution is now available as an add-on for Cloudflare for Teams suite of zero trust security and secure web browsing services. It leverages Chromium, along with Cloudflare's patented Network Vector Rendering technology, to ensure safe and consistent rendering of web pages even as technologies evolve and become more complex. The service also offers a faster internet experience for users on low-bandwidth connections by connecting remote browsers to the backbone of the Internet.
Mar 23, 2021
1,050 words in the original blog post.
Cloudflare has announced new integrations with VMware Carbon Black, CrowdStrike, and SentinelOne to enhance its existing Tanium integration for Cloudflare for Teams customers. These integrations allow users to restrict access to applications based on security signals from their devices. The new features aim to improve the security of remote work environments by incorporating device security signals into network access decisions. This includes checking for attributes like serial number, device location, and status of anti-malware or endpoint security providers. These integrations provide an additional layer of security by requiring that a device runs certain endpoint security software before granting it access to resources protected by Cloudflare. The partnerships with these vendors will continue to grow, providing more flexibility for customers in choosing their preferred vendor.
Mar 23, 2021
1,373 words in the original blog post.
Cloudflare has announced support for malware detection and prevention directly from its edge, providing an additional layer of security for Gateway users against threats on the internet. The new feature enhances protection for employees and data without compromising performance. With this update, administrators can block malicious files from being downloaded onto corporate devices as they pass through Cloudflare's edge for file inspection. This layered approach to security helps protect networks from becoming infected with malware, which can cause significant damage such as ransomware attacks or data exfiltration by spyware. The new feature is included in Teams Standard and Enterprise plans.
Mar 23, 2021
1,218 words in the original blog post.
Ransomware is a type of malicious software that encrypts files on computers, rendering them useless until decrypted. Payment for decryption keys is often demanded in cryptocurrency. Recently, Cloudflare protected a Fortune 500 company from a targeted ransom DDoS attack. The author shares insights into the evolution of ransomware attacks and how Cloudflare can help prevent them. Key points include:
1. Attackers often exploit unpatched vulnerabilities, compromised credentials, or spear-phishing to gain initial access.
2. After gaining access, attackers perform internal reconnaissance, install backdoors, delete data backups, and exfiltrate sensitive data before deploying ransomware.
3. Cloudflare's Access protects RDP servers from brute force attacks, while Magic WAN & Firewall allow users to control access to other internal resources.
4. Web Application Firewall (WAF) can block exploitation attempts until a patch becomes available.
5. Gateway with AV helps detect malicious files and domains, while Cloudflare RBI isolates threats at the browser level.
6. Maintaining multiple redundant backups of critical systems and data is crucial for recovery from ransomware attacks.
Mar 23, 2021
1,365 words in the original blog post.
In October 2020, Cloudflare introduced Cloudflare One, a vision for the future of corporate networking and security. Today, they have announced two foundational aspects of this platform: Magic WAN and Magic Firewall. Magic WAN provides secure, performant connectivity and routing for your entire corporate network, reducing cost and operational complexity. Magic Firewall integrates smoothly with Magic WAN, enabling you to enforce network firewall policies at the edge, across traffic from any entity within your network.
Traditional network architecture doesn't solve today's problems, as enterprise networks have historically adopted one of a few models that were designed for secure information flow between offices and data centers, with access to the Internet locked down and managed at office perimeters. As applications moved to the cloud and employees moved out of offices, these designs stopped working, and band-aid solutions like VPN boxes don't solve the core problems with enterprise network architecture.
Magic WAN allows you to securely connect any traffic source - data centers, offices, devices, cloud properties - to Cloudflare’s network and configure routing policies to get the bits where they need to go, all within one SaaS solution. Magic Firewall allows you to centrally manage policy across your entire network, all at the edge as a service.
Magic WAN provides the foundation for the broad suite of functions included in Cloudflare One, which were all built in software from the ground up to scale and integrate smoothly. Magic Firewall is available for Magic WAN out of the box, and customers can easily activate additional Zero Trust security and performance features such as their Secure Web Gateway with remote browser isolation, Intrusion Detection System, Smart Routing, and more.
Mar 22, 2021
2,135 words in the original blog post.
Cloudflare has announced new partnerships for its Cloudflare One network security platform. The company is partnering with VMware, Aruba and Infovista to help customers connect their existing trusted WAN & SD-WAN appliances to Cloudflare's global network. Additionally, Digital Realty, CoreSite, EdgeConneX, 365 Data Centers, BBIX, Teraco and Netrality Data Centers have been added as Network Interconnect partners. These partnerships expand the reach of Cloudflare's Network On-ramp to 15 leading connectivity providers in 70 unique locations, making it easier for customers to securely and efficiently connect their traffic sources to Cloudflare.
Mar 22, 2021
1,263 words in the original blog post.
Area 1 Security introduces its 5th Annual March Hackness: The Phishing Tournament, a bracket-style competition featuring the top 64 brands spoofed in over 22 million phishing messages. This year's tournament sees new players like the World Health Organization and Centers for Disease Control due to COVID-19 themes, while traditional heavyweights such as Microsoft, Google, Facebook, and PayPal remain strong contenders. The tournament aims to highlight the evolving landscape of phishing attacks and identify emerging trends in cybersecurity threats.
Mar 22, 2021
463 words in the original blog post.
Cloudflare has kicked off its 2021 Security Week with a series of announcements aimed at improving internet security. The company, which was initially reluctant to be labeled as a "security company," now offers approximately half of its products in the security domain due to the inherent lack of security engineering in the foundational protocols of the internet. Throughout the week, Cloudflare will announce new security features and partnerships with leading companies in adjacent areas to help customers build complete solutions around their network. The goal is to address various security challenges faced by users today while maintaining a focus on building a fundamentally secure internet.
Mar 21, 2021
1,112 words in the original blog post.
Over the past year and a half, Cloudflare has been transitioning its back-end services from REST APIs to gRPC. The company chose gRPC due to its ability to split monolithic applications into microservices with granular control of communication. While HTTP worked well for most communication between services, as the number of endpoints increased, it became clear that a more efficient method was needed. gRPC provides improved usability and performance compared to REST APIs, allowing large DNS zones to be streamed between client and server without issues related to sizing constraints or compression. Additionally, gRPC supports four types of service methods: Unary, Server Streaming, Client Streaming, and Bi-directional Streaming. The combination of HTTP/2 and protobuf in gRPC has shown almost no performance change from the application's point of view, with efficiency improvements noticeable when writing newly created or edited records to the edge.
Mar 20, 2021
1,973 words in the original blog post.
In response to the COVID-19 pandemic, Cloudflare engineer David Wragg introduced "Random Employee Chats" to recreate casual office encounters and maintain social cohesion among remote workers. The process involved randomly pairing participants for 30-minute video calls with no fixed agenda. Initially, a shared spreadsheet was used to coordinate the chats, but this relied on manual tasks. To automate these repetitive tasks, Cloudflare developed an application using its Workers platform, which runs entirely in Cloudflare's edge network without any need for backend or origin servers. The resulting application includes a user interface, storage, automatic participant pairing and notifications, and reminders for users to register for the next session. The code for this implementation is available on GitHub.
Mar 20, 2021
1,127 words in the original blog post.
Cloudflare and Automattic have announced a collaboration to improve internet privacy. The partnership includes the integration of Cloudflare's privacy-first web analytics into WordPress.com, giving publishers more control over data collection. Additionally, users can now access links for Cloudflare APO and CDN within the WordPress.com dashboard. This collaboration aims to create a better internet experience by combining security, performance, and privacy features from both platforms.
Mar 19, 2021
390 words in the original blog post.
Cloudflare's Content Delivery Network (CDN) uses caching to improve website load times and reliability. However, a notable exception since 2010 was that requests with query strings were not cached until they had been requested three times. This policy aimed to reduce unnecessary disk writes for potentially unpopular queries. In March 2021, Cloudflare conducted an A/B test to evaluate the impact of caching query string requests on the first request. The results showed a minor but acceptable increase in disk writes and a modest hit rate increase of around +3% for Enterprise customers. This led to a -5% decrease in total bytes served from origin, resulting in bandwidth savings for customers. Based on these findings, Cloudflare removed the policy, allowing query string requests to be cached at first sight.
Mar 19, 2021
1,152 words in the original blog post.
Area 1 Security recently stopped a sophisticated Microsoft Office 365 credential harvesting campaign targeting C-suite executives, high-level assistants, and financial departments across numerous industries. The attackers utilized various techniques to bypass email authentication and Microsoft's email defenses. These methods involved using legitimate-looking domains and login pages, advanced phishing kits, and exploiting inherent weaknesses in email authentication protocols. The campaign targeted specific individuals at each company, with a large majority of the attacks aimed at financial controllers and treasurers across various international companies. By targeting financial departments, the attackers could potentially gain access to sensitive data of third parties through invoices and billing, commonly referred to as a BEC (Business Email Compromise) attack. The phishing messages contained just enough details to lure unsuspecting targets into opening the attachment, which was either a PDF, HTML, or HTM file. Once the target clicked on the "Apply Update" button or opened the HTML/HTM attachments, their browser would be directed to one of several spoofed Office 365 login pages. The attackers used free-use licenses for front-end web development to assist in creating an advanced phishing kit to clone the Microsoft login page.
Mar 18, 2021
2,281 words in the original blog post.
Cloudflare has deployed a global autonomous DDoS protection system across its 200+ data centers. The software-defined system, which runs on commodity servers, actively protects all customers against DDoS attacks without requiring human intervention. It detects and mitigates L3/4 and L7 attacks at the edge using a denial of service daemon (dosd). The latest improvements have expanded dosd's capabilities to protect against L7 attacks in addition to L3/4, covering 98.6% of all L3/4 DDoS attacks and mitigating 81% of all L7 attacks. This autonomous system is designed to disrupt the economics of DDoS attacks by protecting customers from both large-scale and small-scale attacks.
Mar 18, 2021
1,252 words in the original blog post.
In July 2019, Bethany Sonefeld's team at Cloudflare began conceptualizing a product that would eventually become Cloudflare for Teams. The goal was to bring protection to anyone and everyone by extending the same security technology offered in their app. After months of brainstorming sessions, design iterations, and testing, they had an MVP version of Teams: offering customers a way to protect their network from security threats on the web using DNS filtering.
In 2018, Access had been helping customers secure their applications using a zero-trust security model. Bringing this functionality into Teams felt like a natural fit — Access would act as a bouncer standing in front of the door, checking identity, while Gateway would be a bodyguard, keeping your team safe as you navigate the Internet.
During Zero Trust week, they introduced three new capabilities into Teams: L7 inspection of traffic for threats that hide below the surface, launched the Teams WARP client, and expanded their Zero Trust offering to support SaaS applications.
As the product grew, so did Bethany's design team. By November 2020, she had hired three designers to partner with her on crafting the rest of the Teams story. Looking ahead, strategic thinking will help the entire team aim for a common goal, increase efficiency, and lay the foundation for a scalable product that grows over time.
Mar 18, 2021
897 words in the original blog post.
The blog post discusses the performance of Cloudflare's Automatic Platform Optimization (APO) for WordPress sites since its launch. Real-world improvements in several performance metrics, such as Time to First Byte (TTFB), First Contentful Paint (FCP), and Speed Index, were observed through internal testing with WebPageTest. Chrome User Experience Report data also demonstrated significant improvements in these metrics after enabling APO. The post highlights the benefits of synthetic testing using WebPageTest and real-world monitoring using RUM data from Google's Chrome User Experience Report. It also covers extended functionality and compatibility updates for Automatic Platform Optimization, including smart caching for marketing query parameters, improved cache hit ratio, enhanced security features, page rules integration, subdomain support, and caching by device type. The post concludes that APO has shown consistent improvements in performance metrics across various scenarios and emphasizes the importance of customer feedback in driving product development.
Mar 16, 2021
2,951 words in the original blog post.
Cloudflare has released three new features for its privacy-first Web Analytics platform: adding multiple websites to an account, supporting Single-Page Applications (SPA), and showing Core Web Vitals in Web Analytics. The company aims to provide essential web analytics without compromising user privacy. Users can now measure up to 10 websites and view analytics for all their sites combined in one place. Additionally, SPA support has been implemented, allowing users to see route changes within the Web Analytics dashboard. Core Web Vitals metrics are also available for every Web Analytics customer.
Mar 15, 2021
968 words in the original blog post.
Cloudflare's Anomaly Detection for bot management utilizes a "defense in depth" model that combines multiple detection systems to create a robust platform. One of these systems is Anomaly Detection, which identifies bots by modeling the characteristics of legitimate user traffic as a healthy baseline and targeting anomalous traffic. The algorithm used for this purpose is Histogram-Based Outlier Scoring (HBOS), which detects global outliers quickly in linear time.
Anomaly Detection processes over 500K requests per second, with more than 200K CAPTCHAs issued per minute. It identifies suspected bots from over 140 different countries and 2,200 different ASNs using automatically generated baselines and visitor models unique to each enrolled site.
The Anomaly Detection platform consists of a series of microservices running on Kubernetes, with request data coming in through a dedicated Kafka topic and being inserted into ClickHouse and Redis for analysis. The Detector service calculates outlier scores for visitors compared to the baselines, while the Publisher service sends detections to the edge for use in bot score calculations.
The platform has grown significantly since its launch, with improvements made to Redis optimization, microservices architecture, and overall scalability. Future developments include expanding into a problem space with huge cardinality, delivering better detection accuracy on sites with multiple traffic types, and enhancing support and education for the team behind Anomaly Detection and Bot Management.
Mar 12, 2021
2,075 words in the original blog post.
The text discusses a comparison between the Ampere Altra Q80-30 and AWS Graviton2, both of which are Neoverse N1-based processors designed for server use. The author found that the Ampere Altra outperforms the AWS Graviton2 in both single and multi-core performance due to its higher operating frequency and greater number of cores. Additionally, the Ampere Altra was found to consume less power than expected, which could lead to more flexibility in server deployment. The author is currently assessing the Altra's performance against their existing fleet of servers and working with Ampere to define an ARM edge server based on the Altra for potential large-scale deployment.
Mar 11, 2021
2,179 words in the original blog post.
On March 8, a hacker breached vendor Verkada's internal support tools, gaining access to manage Cloudflare's office security cameras remotely. As soon as the breach was discovered, Cloudflare shut down all cameras in their offices worldwide. The company clarified that no customer data or production systems were compromised during this incident. This event emphasizes the importance of the Zero Trust model that Cloudflare follows and provides to its customers, ensuring that if any one system or vendor is compromised, it does not compromise the entire organization.
Mar 10, 2021
1,108 words in the original blog post.
Cloudflare has introduced new features to its Cloudflare Gateway platform, which aims to secure employees from internet security threats and enforce appropriate use policies. The latest updates include an L7 firewall that enables administrators to apply security and content policies to HTTP traffic. Additionally, the company now supports applications and app types in the Gateway rule builder, allowing IT administrators to create rules by application or app type instead of managing lengthy lists of hostnames. This feature is available for all customers using the L7 firewall on standalone Gateway, Teams Standard, and Teams Enterprise plans.
Mar 09, 2021
966 words in the original blog post.
Cloudflare is celebrating International Women's Day with a series of events throughout March, designated as Women's Empowerment Month. The company has introduced Womenflare, an Employee Resource Group (ERG) for women and advocates, which focuses on making sure women feel supported and represented at the organization. Key initiatives include hosting panels and workshops featuring women leaders, launching new episodes of Cloudflare TV segments focused on women's journeys and accomplishments, organizing allyship activities to promote gender equality, and encouraging women colleagues to share their voices through various platforms.
Mar 08, 2021
974 words in the original blog post.
The text discusses a solution for reducing DNS query latencies using Consul and Unbound. The problem arises due to long latencies when resolving names in certain parts of the world, especially with DNS over TLS and low TTLs. To address this issue, prefetching and stale cache strategies are explored. Prefetching refreshes DNS records before they expire but is not effective for infrequently accessed records or those with small TTLs. Stale cache serves expired records from the cache while dispatching a job to refresh the record in the background, which helps improve latency and resiliency. The text also covers test configurations, results, and future improvements for this solution.
Mar 08, 2021
2,137 words in the original blog post.
Cloudflare has deployed managed rules protecting customers against a series of remotely exploitable vulnerabilities found in Microsoft Exchange Server. Web Application Firewall (WAF) users with the Cloudflare Specials ruleset enabled are automatically protected against CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Microsoft recommends patching on-premise systems immediately to mitigate these vulnerabilities actively being exploited in the wild by attackers. Cloudflare has also taken the unusual step of immediately deploying rules in "Block" mode due to active attempted exploitation.
Mar 07, 2021
564 words in the original blog post.
Alice Bracchi, technical and UX writer for Cloudflare for Teams, discusses the importance of product voice in user experience design. She explains how a consistent, recognizable product voice can enhance user interactions with an interface by creating familiarity and predictability. To develop a unique product voice for Cloudflare for Teams, Bracchi led a series of collaborative brainstorming sessions with various teams within the company to define their product principles and derive a product voice that matches their core values. The resulting voice matrix outlines guidelines for UX writing in terms of content, vocabulary, syntax, grammar, punctuation, and capitalization choices. Bracchi emphasizes the importance of iterating on these principles over time to achieve true consistency throughout the Teams Dashboard.
Mar 05, 2021
1,889 words in the original blog post.
The text discusses the connection tracking layer in the Linux kernel called conntrack, and how it interacts with the network stack. It explains that conntrack relies on the Netfilter framework to get notified about network packets passing through the stack, and uses its set of hooks baked into the stack. The author also explores how to observe a TCP SYN packet dropped by the firewall using conntrack. They delve into various ways to discover the inner workings of the Linux network stack, such as using tools like drgn, bpftrace, or Ftrace, and cross-referencing source code.
Mar 04, 2021
2,920 words in the original blog post.
Cloudflare has been named a leader in The Forrester Wave™: DDoS Mitigation Solutions, Q1 2021 report. The company provides unlimited and unmetered DDoS protection for all its customers as part of every service plan, including the free one. Its automated systems constantly analyze traffic samples to detect patterns indicative of a DDoS attack. Over the past year, Cloudflare has seen and automatically mitigated some of the largest and most creative cyber attacks. The company received top scores in the strategy category and among the top three in the current offering category. It also scored highly in threat detection, burst attacks, response automation, speed of implementation, product vision, security operation center (SOC) service, and more.
Mar 02, 2021
1,714 words in the original blog post.
This article discusses the process of executing machine code directly from object files, skipping steps like linking and runtime linking. It explains how to load an object file into a program's memory and execute functions from it. The author also provides a detailed walkthrough of parsing ELF files, which are used by most Linux executables and shared libraries. They demonstrate how to find the .text section containing executable code, locate specific functions within that section, and make the code executable in memory. Finally, they provide an example of importing and executing functions from an object file using a loader program. The article concludes with a note on security considerations when processing external inputs like parsing ELF files from disk.
Mar 02, 2021
3,725 words in the original blog post.
In 2010, Cloudflare was introduced as a security and performance solution that aimed to make tools of the biggest service providers available to anyone online. The company launched Cloudflare for Teams in January 2020 with the vision of building a secure and powerful Zero Trust solution that is easy to use. However, rapid feature shipping led to an unintentional "Feature Shop" dilemma where Product and Design only thought about what they were building without considering why. This resulted in siloed functionality and fractured experiences.
To address this issue, the design team became hyper-obsessed with asking why, leading them to challenge each feature hypothesis and research the problem alongside users it may impact. By focusing on the problem space first, Product and Design then partnered on the solution itself. This approach led to a redesigned onboarding experience for Cloudflare for Teams that prioritized user success and time-to-value.
Moving forward, the company will continue to expand on its Quick Start guide, add more robust starter packs, enhance continuous learning opportunities, incorporate intelligent recommendations based on users' environments, and apply these underlying concepts to other areas of the UI.
Mar 01, 2021
1,160 words in the original blog post.