Cloudflare Launches Application Profiles for Positive Security
Cloudflare has announced the launch of Application Profiles, offering organizations a seamless way to enforce positive security policies by analyzing the structure and format of HTTP requests.

Combating AI-Driven Threats with Positive Security
Today, Cloudflare is launching Application Profiles as a seamless way to enforce a positive security policy. By analyzing the structure and format of HTTP requests and identifying deviations, the system helps organizations significantly reduce their attack surface area in response to evolving threat landscapes.
Security teams frequently express concerns regarding attacks utilizing frontier artificial intelligence models. Large language models allow non-technical individuals to autonomously generate malicious payloads, test known techniques, and probe applications by mutating tactics based on feedback from the application or web application firewall.

Shifting Toward Request Structure Validation
While managed WAF rules and machine learning detections remain essential for addressing SQL injection, cross-site scripting, and remote code execution, patching faster alone is no longer fully sustainable. Application Profiles shift the paradigm by learning what valid requests look like through traffic structure analysis, allowing only expected requests.
For instance, if a query search field expects only alphanumeric strings instead of special characters, the system can block deviations and prevent a wide range of typical attack vectors.

Extending Protection to Web Applications
Cloudflare already supports positive security for APIs through Schema Learning and Schema Validation. The company is now extending these protections to web applications through Application Schema Profiles, establishing an always-on detection mechanism that identifies non-conformity.
A closed beta for this capability is currently open to invited Enterprise customers who do not already use API Security, while customers with API Security already have access to the feature.

Evaluating Traffic and Managing Validation
Schema Profiles periodically learn expected request structures from observed traffic. Once a profile is established, an always-on validation layer evaluates whether live traffic conforms, appending the results as metadata without taking automated enforcement actions by default.
Because non-conforming requests are not necessarily malicious—such as instances involving new client releases or unusual valid inputs—users are advised to start in observation mode. Security Analytics includes a new Profile Analysis tab to review traffic trends and non-conforming request volumes.

Operational Requirements and Weekly Learning
Profiling applies to operations selected by customers. In Web Assets, an operation represents an endpoint identified by its HTTP method, hostname pattern, and path pattern, which can be discovered continuously or added manually.
For discovered operations, users must intentionally select learning from the overflow menu. To generate a profile, an operation requires a minimum number of successful requests over a seven-day period, after which Cloudflare runs learning automatically on a weekly basis.
Sources
- Cloudflare BlogEnforce positive security with Cloudflare Application Profiles