This page was machine-translated and may differ from the original. View original
Real-time blocking of automated bots without CAPTCHA through session-wide behavior analysis
With automated bot traffic surpassing human activity in the proportion of total web requests for the first time, Cloudflare has released a bot detection engine that continuously analyzes user behavior on a session basis. Unlike the existing CAPTCHA method, it signals a change in security verification methods by identifying automated traffic in real-time in the browser without a separate authentication process.Cloudflare announced on the 21st the general availability (GA) of Precursor, a persistent behavior-based validation engine for bot management.
Precursors run on the Cloudflare edge network and continuously collect and analyze the user's entire usage process within the web browser to detect automated bots.
Currently, about 57% of all web requests on the internet are attributed to automated bot traffic.
As internet usage patterns shift towards AI agents, new forms of automated attacks are on the rise, including increased infrastructure costs, inventory manipulation, and data theft.
Precursors were designed based on the observation that while modern bots can easily pass one-time security verification, it is difficult to mimic an entire session of a real user.
"Existing security verifications only check at specific points in time, but modern bots have become sophisticated enough to bypass such one-time verifications," said Dane Knecht, Chief Technology Officer (CTO) of Cloudflare. "Because precursors analyze the user's entire usage process, legitimate users can use the service without separate authentication, and the cost for attackers to mimic human behavior increases significantly."
Precursors collect various interaction signals such as mouse movement, scroll patterns, input speed and rhythm, clipboard usage, and page dwell time.
Key features include: △Privacy protection design: Collects only aggregated behavioral patterns such as input intervals and rhythms, rather than keyboard input content △One-click and freeCode settings: activated with a single click and require no modification of existing application code △Real-time analysis engine: immediately analyzes browser telemetry data on the server to identify forgery signals △Persistent session protection: continuously updates the Bot Score across the entire session, including Single Page Applications (SPAs), etc.
Precursors work by Cloudflare automatically injecting lightweight dynamic scripts over the network.
The scope of security has been expanded from protecting individual requests, such as logins and payments, to the entire session.
The company explained that the automation agent enables continuous detection because accumulated behavior history cannot be reset even if the page is refreshed.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)













