Cloudflare's Adaptive DDoS Protection Profiles Traffic Per Customer
Cloudflare has announced the general availability of Adaptive DDoS Protection, a new system that learns the unique traffic patterns of individual Internet properties and adjusts its defenses accordingly. The feature is designed to complement existing dynamic fingerprinting defenses with a more granular, cost-efficient layer of protection against sophisticated attacks.
The system is available now for Enterprise customers in two forms:
- HTTP Adaptive DDoS Protection – for WAF/CDN Enterprise customers subscribed to the Advanced DDoS Protection service.
- L3/4 Adaptive DDoS Protection – for Magic Transit and Spectrum customers on an Enterprise plan.
Profiles Built From Seven-Day Traffic History
Adaptive DDoS Protection constructs a traffic profile by tracking the maximal rates of traffic seen each day over the previous seven days. These profiles are recalculated daily. The system stores the maximum traffic rates observed for each predefined dimension—such as source country, the Cloudflare data center location that received the packet, user agent, IP protocol, and destination ports.
For example, a profile using source country as its dimension would log separate maximal rates per country: 2,000 requests per second (rps) for Germany, 3,000 rps for France, 10,000 rps for Brazil, and so forth. The same profiling logic applies to L3/4 traffic for Magic Transit and Spectrum customers.
The rate calculations use the 95th percentile of observed maximums, discarding the top 5% of highest readings to remove outliers from the profile.
Profile computation happens asynchronously, so it introduces no latency to customer traffic. Once built, a compact representation of the profile is distributed across Cloudflare's network, where the DDoS protection systems consume it for detection and mitigation. The profiles are combined with Cloudflare's Machine Learning–generated Bot Scores as another signal, helping the system distinguish between legitimate spikes in user activity and automated, potentially malicious traffic.
Rules and Configuration
The system is designed to work with minimal setup. Profiles are generated automatically, and customers can tune behavior through the DDoS Managed Rules interface, adjusting sensitivity levels, using expression fields to create overrides that exclude specific traffic types, or changing the mitigation action.
Adaptive DDoS Protection operates in conjunction with the existing dynamic fingerprinting defenses. New Internet properties are protected automatically by fingerprinting upon onboarding; once the profile system has learned their legitimate traffic patterns, customers can enable it for an additional layer of protection.
| Profiling Dimension | Availability | |
|---|---|---|
| WAF/CDN customers on the Enterprise plan with Advanced DDoS | Magic Transit & Spectrum Enterprise customers | |
| Origin errors | ✅ | ❌ |
| Client IP Country & region | ✅ | Coming soon |
| User Agent (globally, not per customer*) | ✅ | ❌ |
| IP Protocol | ❌ | ✅ |
| Combination of IP Protocol and Destination Port | ❌ | Coming soon |
*The User-Agent–aware feature profiles the top user agents seen across the Cloudflare network, which helps identify DDoS attacks that exploit legacy or misconfigured user agents.
With the exception of the User-Agent–aware rules, Adaptive DDoS Protection rules are initially deployed in Log mode. Customers can review flagged traffic and adjust sensitivity before switching to mitigation mode, following Cloudflare's guided process.
Deployment and Availability
Adaptive DDoS Protection is part of Cloudflare's long-term effort to minimize the impact of denial-of-service attacks by making automated defenses more precise and tailored to each customer's distinct traffic profile. Further technical details are available on the developer documentation site. Customers interested in upgrading can contact their account team.



