Cloudflare’s Keyless SSL and Bot Management Come to IBM Cloud

IBM Cloud and Cloudflare have collaborated since 2018 to embed Cloudflare’s application security and performance products directly into IBM Cloud Internet Services (CIS). Their joint work serves a client base spanning many industries, but a recent focus has been on highly regulated sectors, where resiliency, performance, security, and compliance demands are especially strict.

One particular group leading this effort is IBM Cloud for Financial Services, which tailors IBM Cloud capabilities to meet the security and compliance requirements of banks, financial institutions, and fintech companies. That group’s requirements drove two new security capabilities for IBM CIS customers: Cloudflare Bot Management and Keyless SSL.

Bot Management for Application-Layer Threats

Enterprise applications facing the internet increasingly deal with sophisticated, automated bot attacks. Manual mitigations are no longer practical at scale. Cloudflare’s Bot Management, now being made available on IBM Cloud Internet Services in the second quarter of 2023, is designed to counter targeted application abuse including account takeover attacks, inventory hoarding, and carding.

Financial services entities are frequent targets of account takeover attempts. According to Cloudflare data, 71% of login requests observed on its network come from bots. The Bot Management product relies on a global machine learning model that analyzes an average of 45 million HTTP requests per second, tracking botnets across Cloudflare’s network to identify and block malicious traffic patterns.

Keyless SSL for Regulated Industries

IBM Cloud has built several key management solutions that allow clients to store private keys only in custom-built hardware devices. But using a cloud-based security service typically introduces friction: proxying traffic through a cloud provider often requires handing over private keys, which organizations in regulated industries may not be permitted to do due to internal security policies or compliance mandates.

To address that tension, IBM CIS is integrating Cloudflare’s Keyless SSL solution. Keyless SSL lets customers retain complete control over the storage location of their private keys. With this setup, enterprises can continue to use Cloudflare’s WAF, DDoS protection, and Bot Management features while keeping private keys on IBM’s key storage hardware within their own controlled environments.

“We aim to ensure our clients meet their resiliency, performance, security and compliance needs. The introduction of Keyless SSL and Bot Management security capabilities can further our collaborative accomplishments with Cloudflare and help enterprises, including those in regulated industries, to leverage cloud-native security and adaptive threat mitigation tools.”Zane Adam, Vice President, IBM Cloud

By combining Cloudflare’s edge security with IBM’s key custody approach, the two companies intend to give regulated enterprises the option of layered, adaptive threat protection without requiring them to forfeit control over encryption keys. IBM CIS teams have indicated that this mix of DDoS mitigation, WAF, and bot detection at the cloud edge, coupled with Keyless SSL, is central to serving financial services clients under current security review practices.

More details about how IBM uses Cloudflare to protect its customers are available at https://www.ibm.com/cloud/cloudflare.