Intrusion detection without the legacy trade-offs

Cloudflare is opening a private beta of intrusion detection capabilities built into its Network Services portfolio, part of Cloudflare One. The goal: apply signature-based threat monitoring across an entire corporate network — data centers, cloud properties, and branch locations — without the capacity constraints, performance penalties, or operational overhead that come with traditional hardware IDS deployments.

The IDS offering extends Cloudflare's existing Network Services controls, which already let customers enforce firewall rules, integrate custom or managed IP lists, and block traffic associated with known malware, bots, or anonymizers. The new capabilities actively monitor traffic against a broader set of known threat signatures and fingerprints.

Why traditional IDS falls short

Intrusion Detection Systems are conventionally deployed as standalone appliances or bundled into higher-end firewalls. Where a traditional firewall blocks traffic you know you don't want, an IDS analyzes traffic against a wider threat database to catch sophisticated attacks — ransomware, data exfiltration, network scanning — based on signatures. Many IDS products also layer in anomaly detection against baseline activity to identify unexpected patterns. But the delivery model has historically created problems of its own.

Cloudflare's customer interviews surfaced the same complaints that plague other hardware-based security gear: painful capacity planning, difficult location planning, backhauling traffic to central monitoring points, downtime for installs and maintenance, and vulnerability to congestion or outright failure under large traffic volumes such as DDoS attacks.

There's also a sharp security-versus-performance trade-off. One network engineer put it this way:

"I know my security team hates me for this, but I can't let them enable the IDS function on our on-prem firewalls - in the tests my team ran, it cut my throughput by almost a third. I know we have this gap in our security now, and we're looking for an alternative way to get IDS coverage for our traffic, but I can't justify slowing down the network for everyone in order to catch some theoretical bad traffic."

Even customers who accepted the performance hit reported a second failure mode: after turning on their IDS appliance, they often muted or ignored the alert feed. The volume of noise — false positives and non-actionable notifications — leads to alert fatigue in SOC teams and risks silencing important signals buried in the noise.

Monitoring everything, everywhere

Cloudflare's answer is an IDS built from scratch in software and deployed across every server on its global Anycast network, rather than as dedicated hardware. That design removes the traditional constraints:

  • No capacity planning: The capacity of the IDS is the capacity of Cloudflare's global network — currently 142 Tbps and counting.
  • No location planning: Every server runs the IDS software, and traffic is automatically attracted to the closest network location to its source. Redundancy and failover are inherent; there are no regions to pick, no central sites to backhaul to, and no primary/backup appliances to deploy.
  • No maintenance downtime: Updates to the IDS, like all Cloudflare products, roll out continuously across the global network.

The service operates across all network traffic — any IP port or protocol — covering IPs Cloudflare advertises on a customer's behalf, IPs leased to customers, and (soon) traffic within a customer's private network via Magic WAN. Consistent monitoring and security control can be enforced from a single management plane.

Feeding the signatures from a network-scale vantage point

Because the IDS is delivered as software Cloudflare writes and maintains, threat intelligence can be continuously updated. The system combines community-maintained open-source feeds such as Suricata signatures with data derived from Cloudflare's position as an interconnected network carrying a significant share of Internet traffic.

That intelligence flows two ways. Publicly, insights are shared through Cloudflare Radar. Internally, the same intelligence is fed back into security tools including the IDS, so customers get protection from emerging attack patterns. Cloudflare's Threat Intel team will further support these efforts, applying dedicated research to the network data.

Advanced Magic Firewall customers can access the private beta now by contacting their account team.