Radar adds live attack maps
Cloudflare Radar, launched during last year's Birthday Week as a "newspaper for the Internet," has expanded with two new data visualizations that show the geographical distribution of application-level attacks. Radar's existing coverage includes near real-time global Internet usage, country-level statistics, domain insights with traffic and certificate data, and deep-dive reports on topics such as DDoS and the Meris botnet.
Cloudflare's network spans more than 250 cities in over 100 countries, giving it visibility into both broad and granular traffic trends—including where attacks originate and which countries are targeted. The new Radar Maps features are designed to make this information easier to consume.
Two ways to visualize attack flows
The first visualization is a global map that draws near real-time directional lines between attack sources and their targets—a "pew pew" map in the tradition of the 1983 film WarGames. The second uses Sankey diagrams to show the relative strength of attack flows between countries. A note on the maps clarifies that the identified location of devices involved in an attack may not reflect the actual location of the people behind it.
Attack volume and direction at a glance
The release comes amid a sustained surge in cyber threats. In the third quarter of 2021, Cloudflare blocked an average of 76 billion threats per day and had visibility over many more. Radar has offered time-series views of attack types, protocol distribution, and volume since launch; the new maps add a geographical component that shows both the origin and the target of those attacks.

Built on Cloudflare's edge platform
Unlike other Internet insights platforms, Radar is built entirely on Cloudflare components, including the Workers serverless computing platform and Workers KV. That architecture, the company says, enables new ways of representing data at scale. The maps are available now at radar.cloudflare.com.




