Cloudflare Radar splits security views and adds bot, DDoS, and credential insights
Cloudflare Radar is expanding its security and traffic analysis offerings with new datasets and a reorganization of its Security section. The update adds dedicated graphs for application-layer DDoS attacks, leaked credential trends, and a new Bots page, while also splitting the existing Security & Attacks page into separate Application Layer and Network Layer views.
Security section splits into application and network layers
Since Radar launched in 2020, its security data — spanning network layer (Layers 3 & 4) and application layer (Layer 7) attack traffic — has lived on a single page. As more datasets were added over time, the page grew harder to navigate. The Security section now separates these views into two pages: the Application Layer page (now the default) covers HTTP-based malicious and attack traffic analysis, while the Network Layer page covers network/transport layer attacks along with observed TCP resets and timeouts. The Email Security page remains a dedicated, standalone view. Future security-related datasets will be slotted into whichever page corresponds to the relevant layer.
Application-layer DDoS attacks get geographic and AS-level detail
Radar’s quarterly DDoS threat reports have given regularly-scheduled, aggregated insights into top sources and targets of application-layer DDoS attacks. New interactive views now make that data available on demand. A choropleth map and accompanying table on the Application Layer page show the geographic distribution of source and target locations. Source locations are attributed by geolocating the IP address that originated the blocked request; targets are mapped to the billing location of the account owning the attacked site.
Data from the first week of March 2025 shows the United States, Indonesia, and Germany as the top sources of application-layer DDoS attacks, together contributing over 30% of such traffic. The target-side concentration was notably different: customers in Canada, the United States, and Singapore absorbed 56% of application-layer DDoS attacks during that window.

Source ASN treemap
Beyond geography, a new treemap shows attack distribution by source autonomous system (AS), giving visibility into the networks hosting the attacking infrastructure. Globally, the largest source ASNs include cloud and hosting providers based in Germany, the United States, China, and Vietnam. Selecting a specific country or region shows the source AS breakdown for attacks originating there. In some locations — Portugal, for example — attack traffic is heavily concentrated in consumer and business network providers. In countries with significant cloud presence, such as Ireland, Singapore, and the United States, hosting-provider ASNs dominate. That pattern aligns with Singapore’s recurring appearance among the top sources of application-layer DDoS attacks in the 2024 quarterly reports.

Leaked credential trends arrive on Radar
Cloudflare has offered customers the ability to scan authentication requests for known-leaked credentials since 2024 using a privacy-preserving compromised credential checker. Aggregated data from that service now feeds Radar, showing how often leaked usernames and passwords are observed across Cloudflare’s network. “Leaked credentials” here means usernames or passwords found in a public dataset, or where the username/password pair is detected as being similar to one in such a dataset.
Leaked credentials detection scans incoming HTTP requests for known authentication patterns from common web apps and any custom-configured detection locations. A hash of each detected password is checked against hashes of compromised passwords in leaked databases without exposing the actual credentials. The new Radar graph on the worldwide Application Layer page shows the distribution of authentication requests classified as “clean” versus “compromised,” filterable by human users, bots, or all requests.
For the first week of March 2025, leaked credentials appeared in a striking share of worldwide authentication traffic: over 64% of all requests, more than 65% of bot requests, and over 44% of human requests. The high human share points to recurring problems with password reuse and delayed responses to breach notifications. The bot-side numbers suggest attackers see meaningful cross-site success with credential stuffing.
Complementing that data is a worldwide graph showing the share of authentication requests originating from bots. Not all bot authentication traffic is malicious — some comes from automated scripts or other benign applications — though malicious request volume far outstrips legitimate automated logins. During the same March 2025 week, over 94% of authentication requests were automated. That was substantially above the roughly 30% bot share of overall request traffic across Cloudflare in the same period, indicating that authentication endpoints are a major focus of automated activity.

Dedicated Bots page
Bot traffic — any non-human internet traffic — has gotten increasing attention as a security and operational concern. To make bot insights easier to reach, Cloudflare Radar has launched a new dedicated Bots page in the Traffic section. For both worldwide and location views, it shows the distribution of bot versus human HTTP requests over the selected period and graphs bot traffic trends. Identification relies on Cloudflare’s bot score, which combines machine learning, heuristics, and other techniques to flag automated requests.

The page’s Bot Traffic Sources insight was previously available only through the annual Radar Year in Review microsites, which aggregated January-through-November traffic once a year. The new page provides the same macroscopic view on an ongoing basis. The worldwide view includes a choropleth map and table showing which locations originate the largest shares of bot traffic. (A separate Traffic Characteristics map on the Traffic Overview page ranks locations by what percentage of that location’s traffic is bot traffic, a different measure.) Consistent with Year in Review findings, the United States continues to originate the largest share of bot traffic.
Bot traffic by autonomous system
The worldwide Bots view also breaks down bot traffic share by AS. Cloud platform providers account for significant amounts of bot traffic, mirroring what Radar has previously reported for the top bot-producing networks. At the location level, the top source mix varies: some countries see dominance from cloud or hosting providers, others from consumer/business networks. In France, four ASNs together account for just over half of bot traffic — two from cloud/hosting providers (AS16276 and AS12876) and two from network providers (AS3215 and AS12322).

The Verified Bots list also moves to the new Bots page. Its data and functionality are unchanged, and existing links automatically redirect to the new location.
API and exploration access
All underlying data for these new views is available through the Radar API, covered by the Application Layer, Network Layer, Bots, and Leaked Credentials subresources. Charts and graphs on Radar and Data Explorer remain downloadable and embeddable.



