Eigen RadarAI
Analysis

Cloudflare’s AI-guided firewall test leaves 49 findings for review

Cloudflare has published results from testing its web application firewall with AI-guided attack variations. Across 45 scenarios, the company logged 1,107 attempts and human reviewers retained 49 findings for investigation. The test took place in one authorized staging environment, and an unblocked request did not establish a successful break-in. Cloudflare says the work informed rule changes, some of which were released before this account appeared.

Artificial Intelligence··Evening
A security researcher reviews firewall test patterns on a monitor.

Models probed one authorized firewall setup

Cloudflare has published an account of how it used advanced language models to probe its web application firewall, the system that filters suspicious requests before they reach a website. The test ran in an authorized customer staging environment with a stated firewall configuration. One model call proposed a variation of a known attack request; another reviewed the response and chose what to try next. Code sent the requests, limited them to approved targets, disabled redirects and capped the attempts. The agent could not edit firewall rules. Those boundaries matter because the experiment tested the protection against changing attack inputs without giving the model control of the defended system.[1], [2]

Human review narrowed 1,107 attempts to 49 findings

Cloudflare recorded 1,107 attempts across 45 scenarios. Its firewall blocked 558 requests, and human reviewers judged 49 results worth further investigation. Other attempts were malformed, harmless, duplicates or never reached the target. Of the retained findings, 48 related to command injection or server-side request forgery, an attack that tries to make a server fetch another address on the attacker’s behalf. The counts describe this particular run and its filtering steps, not a general firewall success rate. An unblocked request was a lead for checking, not proof that an application was breached or data exposed. In an example involving an altered IP address, Cloudflare found no successful response from the target application.[1]

Earlier rule changes followed the test

The company says it replayed the findings, checked the risk of false alarms and used the work to change three managed firewall rules. Some of those changes had already been released on July 21; the September 29 development is Cloudflare’s account of the testing, not the first release of every resulting rule. One revised detection concerns attempts to disguise a destination address, a technique relevant to server-side request forgery. Cloudflare also describes command injection among the issues examined, while declining to treat every request that passed the firewall as an exploit. The research took place in one environment, so its figures cannot show how the same models would fare against every customer’s settings. Human verification remained the step that turned a model-generated lead into a finding.[1]

References

  1. News sourceCloudflareAI-guided WAF test yields 49 triaged findings at Cloudflare↩1↩2↩3
  2. News sourceMokaairCloudflare tests its firewall with AI-guided attacks↩