流量检测会检查传入请求是否存在恶意或潜在恶意活动。每项已启用的检测通过填充一个或多个字段对请求进行评分或分类。这些字段会作为筛选器显示在 Security Analytics 仪表板中,并且您可以在规则表达式中使用它们。
检测一旦启用即始终运行,即使您尚未配置任何使用它们的安全规则。您可以在 Security Analytics 中查看检测结果,以识别流量模式并发现潜在恶意流量。例如,您可以根据攻击分数、机器人分数、内容扫描结果,或大型语言模型 (LLM) 提示中是否存在个人身份信息 (PII) 来分析流量。
Cloudflare 提供以下检测:
| Free | Pro | Business | Enterprise | |
|---|---|---|---|---|
Availability | Yes | Yes | Yes | Yes |
Malicious uploads detection | No | No | No | Paid add-on |
Leaked credentials detection | Yes | Yes | Yes | Yes |
Leaked credentials fields | Password Leaked | Password Leaked, User and Password Leaked | Password Leaked, User and Password Leaked | All leaked credentials fields |
Number of custom detection locations | 0 | 0 | 0 | 10 |
Attack score | No | No | One field only | Yes |
AI Security for Apps | No | No | No | Yes |
有关机器人分数的更多信息,请参阅 机器人分数。
要开启流量检测:
-
在 Cloudflare 仪表板中,转到 Security Settings(设置) 页面。
Go to Settings ↗ -
按 Detection tools(检测工具) 筛选。
-
开启所需的检测。
- 登录 Cloudflare 仪表板 ↗,并选择您的账户和域名。
- 转到 Security(安全性) > Settings(设置)。
- 在 Incoming traffic detections(传入流量检测) 下,开启所需的检测。
已启用的检测将对所有传入流量运行。
有关检测与缓解的更多信息,请参阅 概念。