Security best practices
Structured learning path for application security.
← Use Cases / use-cases
Protect your website or application from attacks, bots, and abuse. Cloudflare's application security (also known as Web Application Firewall or WAF) blocks SQL injection, XSS, and OWASP Top 10 vulnerabilities. DDoS Protection mitigates volumetric and application-layer attacks automatically. Bot Security uses machine learning to score every request. API Shield validates API traffic against your OpenAPI specification. Client-side security monitors third-party scripts for malicious behavior.
Protect a website or web application from common attacks:
Secure Application Programming Interface (API) endpoints with schema enforcement and authentication:
Protect visitors from threats that execute in the browser:
Structured learning path for application security.
Analyze security events and fine-tune your configuration.
Explore how companies secure their applications with Cloudflare.