Bot Protection
Detect and Block malicious bots in real-time
Overview
Bot Protection helps you quickly determine, manage, and mitigate automated requests. You can configure Legitimate/Malicious Crawlers, Tor, Bot Request Rate, and Bad Traffics. HaltDos Threat Stream TM provides a list of malicious IPs, known as bad bots and crawlers. Enterprise can specify the action to take against this malicious traffic.
How to Use:
-
Go to WAF > Zones > Listener > Security Profiles > Bot Protection.
-
Configure your settings.
-
Click Save.
Configure the following parameters to set up the desired settings:
| PARAMETERS | DESCRIPTION | ACCEPTED VALUES | DEFAULT |
|---|---|---|---|
| Allowed Crawlers | Specify the list of good crawlers by specifying their user agents. Such requests will be allowed. | User Agent | Blank |
| Bad Crawlers | Specify the list of bad crawlers by specifying their user agents. Such requests will be dropped. | User Agent | Blank |
| Suspicious Crawlers | Specify a list of suspicious crawlers by specifying their user agents. Such requests will be rate-limited. | User Agent | Blank |
| Maximum Bot Request Rate | Specify the maximum allowed Bot request rate from a single client IP. | Integer | 30 |
| Maximum Bot Request Burst | Specify the maximum allowed Bot request burst from a single client IP. | Integer | 50 |
| Tor Traffic | Specifies the action to perform on TOR Network traffic. | NO ACTION / DROP / SEND CHALLENGE | NO ACTION |
| Bad Reputation Traffic | Specifies the action to perform on traffic from suspicious IPs reported by Haltdos Threat Stream TM. | NO ACTION / DROP / SEND CHALLENGE | NO ACTION |
| Advance Bot Protection | Specifies the advanced bot protection method. | NONE / FINGERPRINT / TOKEN VALIDATION / ANY | NONE |
| Fingerprint Suspicion Threshold | Specify the score after which the request will be marked as bot request if fingerprinting enabled. As value increased, requests marked as suspicious. | Integer (2-10) | 8 |
| Fingerprint Bot Traffic Action | Specifies the action when the request is marked by the bot using fingerprinting | NO ACTION / RECORD / RATE LIMIT /SEND CHALLENGE / DROP | NO ACTION |
| Invalid Token Traffic Action | Specifies the action when the request contains an invalid token, if token validation is enabled. | NO ACTION / RECORD / RATE LIMIT / DROP | NO ACTION |
| Anonymous Traffic Action | Specifies the action when request contains no token, if token validation is enabled. | NO ACTION / RECORD / RATE LIMIT / DROP | NO ACTION |
Allowed Crawlers
This field specifies the list of good crawlers by specifying their user agents. You can add single or multiple user agents. All the user agent mentioned in Allowed Crawlers permits the crawlers to access the protected URL.
Accepted values: String