INTEGRITY Cloudflare Docs

Adaptive DDoS Protection

Adaptive DDoS Protection learns your unique traffic patterns and adapts to them to provide better protection against sophisticated DDoS attacks on layer 7 and layers 3/4, depending on your subscribed Cloudflare services.

Adaptive DDoS Protection provides the following types of protection:

Availability

Cloudflare Adaptive DDoS Protection is available to Enterprise customers according to the following table:

Feature Profiling dimension WAF/CDN1 Magic Transit /
Spectrum BYOIP2
HTTP Adaptive DDoS Protection
For Origins Origin errors Yes
For User-Agents User Agent
(entire Cloudflare network)
Yes
For Locations Client IP country and region Yes
L3/4 Adaptive DDoS Protection
For Protocols IP protocol Yes
For Protocols Client IP country and Region for UDP Yes

1 WAF/CDN customers on the Enterprise plan with the Advanced DDoS Protection subscription.


2 Magic Transit and Spectrum BYOIP customers on an Enterprise plan.

How it works

Adaptive DDoS Protection creates a traffic profile by looking at the maximum rates of traffic every day, for the past seven days. These profiles are recalculated every day, keeping the seven-day time window. Adaptive DDoS Protection stores the maximal traffic rates seen for every predefined dimension value (the profiling dimension varies for each rule). Every profile uses one dimension, such as the source country of the request, the user agent, and the IP protocol. Incoming traffic that deviates from your profile may be malicious.

To eliminate outliers, rate calculations only consider the 95th percentile rates (discarding the top 5% of the highest rates). Cloudflare requires a minimum amount of requests per second (rps) to build traffic profiles. HTTP Adaptive DDoS Protection rules also take into account Cloudflare's Machine Learning (ML) models to identify traffic that is likely automated.

Cloudflare may change the logic of these protection rules from time to time to improve them.


View flagged traffic

To view traffic flagged by HTTP Adaptive DDoS Protection rules:

  1. In the Cloudflare dashboard, go to the Security Analytics page.

    Go to Analytics ↗
  2. Go to Events.

  3. Filter by Service equals HTTP DDoS and by rule ID.

To view traffic flagged by L3/4 Adaptive DDoS Protection rules:

  1. In the Cloudflare dashboard, go to the Security Analytics page.

    Go to Analytics ↗
  2. Go to Events.

  3. Filter by rule ID.

You may also obtain information about flagged traffic through Logpush or the GraphQL API.

To determine if an adaptive rule fits your traffic in a way that will only mitigate attack traffic and will not cause false positives, review the traffic that is Logged by the adaptive rules.

If you do see traffic that was Logged by the adaptive rules, use the dashboard to determine if the traffic matches the characteristics of legitimate users or that of attack traffic. As each Internet property is unique, understanding if the traffic is legitimate requires your understanding of how your legitimate traffic looks. For example, the user agent, source country, headers, query string for HTTP requests, and protocols and ports for L3/4 traffic.

The default rule action for log with a sensitivity set to high will only show packets or requests with suspected attack traffic over internal high thresholds in your logs. For instance, if you set the threshold to medium or low, then only packets over those thresholds will be logged.

Configure the rules

You can adjust the action and sensitivity of the Adaptive DDoS Protection rules. The default action is Log. Use this action to first observe what traffic is flagged before deciding on a mitigation action.

To configure a rule, refer to the instructions in the following pages:

For more information on the available configuration parameters, refer to the following pages: