heroui logo

Cloudflare Bot High Volume

Panther Rules

View Source
Summary
The Cloudflare Bot High Volume detection rule is designed to monitor HTTP requests made by bots at a threshold rate exceeding 2 requests per second. This rule is particularly valuable for identifying potentially malicious automated activities that could lead to service degradation or downtime. The rule operates by tracking several attributes associated with incoming requests including the client IP, user agent, HTTP request types, and responses. A set threshold of 7560 requests per hour triggers alerts, enabling proactive monitoring of potential bot activity. Additionally, the rule's response may involve further inspection of the instances and supportive analytics to ensure the health and security of the internet-facing services. Given the nature of the detection, which is focused on traffic volume from bots, the severity is marked as low while nonetheless maintaining vigilance against potential threats from automated sources.
Categories
  • Cloud
  • Kubernetes
  • Containers
  • Web
Data Sources
  • Cloud Storage
  • Network Traffic
  • Application Log
Created: 2022-09-02