返回知识库
0

title: "引入自适应智能:破坏所有机器人攻击的经济基础"
source_url: "https://blog.cloudflare.com/introducing-adaptive-intelligence/"
author: "The Cloudflare Blog"
excerpt: "公共早报 Cloudflare 推出自适应智能,一个基于机器学习的系统,用于持续分析流量模式,区分合法用户和恶意机器人,从而通过增加执行难度和成本来破坏机器人攻击的经济基础。"


现代机器人威胁越来越多地由坚定的、复杂的攻击者驱动。通常甚至不是一个人,而是一组相互交易技术或向任何愿意付费的人 sold to anyone willing to pay。对于他们中的许多人来说,绕过机器人检测是一份他们真正享受的全职工作。阻止他们,他们就开始工作,寻找 workaround。AI 使这变得更容易,使攻击者设置复杂配置 even easier,降低了攻击的 overhead。

这种转变使防御者处于经济劣势。响应和适应新攻击需要小心、evidence 和 effort to ensure efforts to block attackers don't impact real users on the way。攻击者没有这样的担忧,主要受限于他们的时间和他们拥有的代理池,以及确保他们的基础设施提供商不关闭他们的账户。

他们的优势是适应成本。攻击者可以尽可能频繁地持续适应,而大多数防御以离散的、受管理的版本部署。Cloudflare 每天分析超过一万亿个请求寻找自动滥用迹象,所以我们看到攻击者改变策略的速度。那个响应差距正在扩大。

不方便的真相:整个行业的机器人检测通常 rest on a hopeful assumption that if you make the wall tall enough, attackers stay out。实际上,坚定的攻击总会找到出路。问题不是坚定的攻击者是否能通过。他们会的。问题是当他们通过时会发生什么。

今天我们推出 Adaptive Intelligence,这是一个新的机器人检测引擎,从相反的想法开始。与其赌一堵墙让每个攻击者都进不来,Adaptive Intelligence 使通过变得如此缓慢和昂贵,以至于攻击不再值得运行。

我们相信没有其他机器人检测以这种方式工作。

一个攻击者,许多伪装

并非每个攻击都很容易被发现。最复杂的那些 built to disappear into ordinary traffic。

攻击者可以将请求分散到大型 residential proxy network,保持来自每个地址的速率低,and move patiently through a login, checkout, or account-recovery flow。每个请求来自不同地址,通常带有 fresh user agent or a new bot fingerprint,所以每个看起来像一个新访客。没有单个源曾经越过速率限制。

这就是这种模式如此难以阻止的原因。将阈值收得太紧,真正的客户会被拒之门外,而这正是你最不想看到的。攻击生活在下一个请求之间,a defense that studies each request on its own will never see it。

确定性检测的缺陷

基于规则的系统的挑战是它们 give the attacker a stationary target。它们在数天内迭代,而模型等待数月 for its next update,所以当它赶上时,tooling 已经继续前进了。

机器人检测总是通过编写规则来 catch each new attack technique 来回答新攻击技术。这有效,直到攻击者研究信号,learn how to circumvent it,并迫使另一条规则被编写。一些最先进的攻击者甚至创建了 tooling 来 semi-automate this process。防御者似乎永久处于劣势。

这种检测是"确定性的",meaning that the same input always produces the same output。一个永不改变的防御教攻击者如何击败它,indirectly drives bot operators to build more capable automated attacks。Against a deterministic defense, automated probes return a clean yes or no, and over enough attempts that feedback teaches an attacker exactly where the edges of the system are。经济学在攻击者一方。

改变攻击经济学

Adaptive Intelligence 旨在扭转经济学并将其放回防御者的 favor。

一个不断变化的防御翻转了那个计算,但只有当两个事情同时成立时才。首先,防御者适应它比攻击者 work around it 花费更少。其次,攻击者必须被剥夺他们用来适应的反馈,so they cannot simply learn their way back in。正确对待两者,攻击者自己的循环转向它们:它们 learned nothing stays true,并且每次新尝试都花费 more than the last,直到攻击不再值得运行。

部分是给攻击者更少 learn from。Adaptive Intelligence 可以从一个信号 recognize a bot without visibly reacting to it,所以攻击者继续依赖他们没有意识到我们可以看到的信号。它将检测视为统计判断而不是固定规则。这使其成为非确定性的。它同时权衡许多信号,so there is no single piece of logic for an attacker to isolate and beat。

一个新的检测引擎

你的机器人分数 already comes from several detection methods working together:机器学习、行为验证、JavaScript 指纹识别、一 library of heuristics,以及识别已知、经过验证的机器人(如搜索爬虫)的检查。

Adaptive Intelligence 是一个全新的机器人检测引擎,sits behind bot score。在其他每个系统都 built to keep attackers out by accumulating rules 的地方,Adaptive Intelligence 是建立在假设攻击者最终会进入的基础上,并使那种尝试尽可能昂贵。

下面,我们解释 Adaptive Intelligence 检测引擎将拥有的三个组件,与传统模型相比是独特的:自我改进、可处置规则生成和从它保护的流量中学习。今天推出的是它的第一个组件:位于你的机器人分数中心的机器学习,现在 continuous retraining 而不是作为固定版本发布。它聚合来自 Cloudflare 网络的网络信号,and measures the probability of automated abuse for every request。在固定模型静止不动的地方,Adaptive Intelligence keeps moving。以下解释的第二个和第三个组件即将推出。

1. 自我改进

引擎在实时流量上 continuous retrain。随着 new bypass tools and bot frameworks appear,它从它们学习并 fold that knowledge into the model behind your bot score,而不是等待 scheduled release。一个技术这周出现,这周引擎就能识别它。你已经构建的分数 stay close to what attackers are actually doing,而不是在更新之间 drift further from reality。

2. 可处置规则生成

可处置规则是我们期望攻击者适应的规则,但不 improve the attacker's bot in the process。Adaptive Intelligence 旨在创建针对特定攻击的可处置规则,deploy and retire them at random intervals,并且从不将它们留在原地足够成为固定目标。因为规则不断 appearing and vanishing,它们在攻击者依赖的信号中注入噪声 来训练我们,所以攻击者永远得不到 static defense leaks 的稳定 yes-or-no。No single rule has to be perfect or unbeatable。它只需要持续足够长时间来完成其工作,然后为下一个让路。By the time an attacker has reverse-engineered a specific pattern,引擎已经继续前进,rendering their engineering effort worthless。

3. 从它保护的流量中学习

Adaptive Intelligence 还将从它在数百万网站上看到的模式中学习。当客户标记我们错误评分的真实访客时,或者当我们的 measurement catches a miss 时,那个纠正成为一个训练信号。Over time the engine tunes to the problems Cloudflare's customers are actually facing,所以你所获得的保护 reflects the current threat landscape 而不是 older one 的快照。

它如何工作

Adaptive Intelligence 运行在一个循环中:观察、训练、部署、验证。它 drawing on 的信号范围 keep growing as we connect more of the network into it。

| 观察。 引擎聚合 Cloudflare 网络信号,如 JA4 TLS 指纹、请求结构、challenge outcomes、会话行为、网络声誉和更高层次的 meta signals,以及来自 Turnstile 和 Precursor 的客户端遥测。一个客户端在任何单个请求上看起来普通,但在整个会话中像脚本一样移动,caught by its behavior over time,即使每个请求看起来合法。 | 训练。 我们在实时流量上 continuous retrain the ML system,包括最新的绕过工具和 bot frameworks as they appear in the wild。训练集经常刷新,so the system can react much faster to new attack techniques。 | | 部署。 新模型权重 own their way across the network。没有版本需要选择,没有升级需要安排,一旦你在上面,你不需要做任何事情。对你的流量进行评分的模型 reflects the threats we are seeing right now。 | 验证。 在新版本成为你的主要防御之前,它与当前版本一起在 shadow mode 下运行,scoring live traffic without affecting a single visitor。我们比较两者并 watch signals like challenge solve rates。如果新版本会对真人评分更差,它不会上线。 |

Cloudflare 多年来一直 running this kind of automated loop against DDoS attacks:sample traffic,TLS fingerprint the patterns behind an attack,push protections out across the network,and keep measuring so they can be adjusted or retired as the traffic changes。机器人是问题的一个更难版本,因为信号更安静,故事只随时间显示出来。Any one signal can look perfectly normal on its own。是它们之间的关系,and the company they keep,that reveal a bot hiding in normal traffic。

Adaptive Intelligence 同时在多个时间窗口上评估流量。一个短窗口 catches a sudden burst as it develops。一个更长的窗口 reveals the behavior that repeats across thousands of addresses, clients, and sessions that have no reason to behave alike,并将那些 scattered requests back to a single source。The same engine that spots an obvious scraping spike 也浮出一个缓慢的、distributed credential-stuffing attack,每个地址只发送少量请求。

自动构建新检测

随着 Adaptive Intelligence 的下一部分上线,mining systems 将在最近的 labeled traffic 中 search for combinations of signals that separate an emerging attack from real users。

Often, a useful detection comes from the relationship between signals we already know, rather than a signal we have never seen before。客户端可能声称是一个浏览器,同时产生另一个浏览器的网络或 JavaScript 信号。请求本身可能看起来正常,但与会话的其余部分形成 odd sequence。Automated mining lets us test many of these combinations 并将最强的 turn into candidate detections。

这些候选者 deliberately narrow。它们不需要 catch every bot on the Internet,甚至不需要 catch current attack 中的每个请求。这使它们快速构建,and easy to replace when an attack changes tactics。

它记得

攻击者不会只攻击一次。它们 pause, retool, and come back。Retiring a detection does not mean forgetting the pattern behind it。引擎保留 past attacks 的 memory,即使在它们的检测停止触发之后,so an attacker cannot escape just by flipping between two profiles and betting the second one looks new。

那种记忆 gives the system a head start when a familiar attack returns or a related one appears。检测可以在停止 earning its place 时 expire,而 behind it 的 evidence stays available to build the next one。Nothing piles up as stale rules in production,and the system never has to learn an old attack from scratch。

结果是一个自动化循环,可以对明显的 spike 做出反应,或 quietly gather evidence on a patient, distributed attack that stays under traditional thresholds。

安全部署

Constant change only helps if every change is safe,and the bar is high。客户可以忍受偶尔的机器人通过 but a real visitor wrongly turned away is the failure that actually costs。这是让团队对自动更新谨慎的担忧,所以新检测必须 earn its place before it affects anyone。

We test each candidate against recent real traffic and measure how much known automation it catches and how often it would flag a genuine visitor by mistake。它作为你的机器人分数的输入 gradually rollout,同时我们 watch score distributions, challenge outcomes, and customer feedback,we can pause or roll it back before it reaches your whole network。每个更新必须证明它至少和它替换的一样好,在对这类系统重要的衡量标准上,precision and recall among them。

一个愿景:自适应智能和 Precursor

这个引擎 not work alone。上个月我们介绍了++Precursor++,一个为机器人管理构建的 continuous behavioral validation engine,以隐私为先,通过 visitor once they reach the browser 的行为方式测量自动滥用:timing, the movement,自动化难以伪造的小 human signals。Precursor 和 Adaptive Intelligence 作为检测恶意自动化的一个想法的两个部分构建。Precursor 通过 measuring continuous session-behavior 来做到这一点;Adaptive Intelligence 从整个网络的机器人检测信号中学习,一个的信号使另一个更难被愚弄。

它也反映了我们对问题的思考方式:机器人检测引擎应该缩小通过的内容,and keep adapting faster than the attacker on the other side。

接下来是什么

Cloudflare Bot Management 产品组合现已包括:

  • 机器人管理: 我们的核心检测引擎,具有机器学习、行为分析等。

  • 机器人管理 + Adaptive Intelligence: 我们最全面的机器人保护。

  • Precursor: Continuous behavioral validation。

  • 空中机器人: 机器学习驱动的误报保护。

  • Challenge Execution: Advanced CAPTCHA replacement。

我们将在未来几个月内发布更多关于 Adaptive Intelligence 的信息。注册我们的邮件更新,follow us on X,并 check out our blog 了解最新消息。

如果你想看到 Adaptive Intelligence 的实际效果,请联系你的 Cloudflare 客户团队安排演示。


Cloudflare 团队贡献了这个博客文章。

AI知识库 / 引入自适应智能:破坏所有机器人攻击的经济基础 0 字 0 行 iliuqi
2026-09-04T08:58:42.257239729Z 2026-09-04T09:28:17.950337921Z