Bot Score

Last update:2026-08-21 18:00:12

Reading time: About 3 minutes

The system generates a score between 1 and 100 for every request that undergoes Bot detection, indicating how likely the request is to have come from a bot — the higher the score, the more likely the request is a bot.
For example, a score of 1 indicates the request is likely from a human, while 100 indicates the request is almost certainly automated.
The Bot Score can be forwarded to your origin server through a custom HTTP request header for use in your own risk control logic. For details, see the Configuring Bot Tag Forwarding to Origin section.

Bot Score Details

Category

Score Range

Description

Definite Bots

100

Requests clearly initiated by an automated tool.

Likely Bots

80-99

Abnormal, suspicious requests that are highly likely to have been initiated by an automated tool.

Likely Human

1-79

Requests that are likely from a genuine human user.

Not Scored

0

Internal system service requests, which are excluded from detection.

Publicly Declared Bots

-

Generally non-malicious automated traffic, including AI Bots and Public Bots.

Note: If a request has already been allowed or denied by an upstream security policy — such as Whitelist, IP/Geo Firewall, Custom Rules, DDoS Protection, or Rate Limiting — that request does not proceed to Bot detection, and no Bot Score is generated.

How the Bot Score Is Generated

The Bot Score is generated automatically through a dual-engine intelligent detection system combining heuristic detection and machine learning. You only need to enable Bot Management on the console’s Bot Management page and turn on the Definite Bots and Likely Bots detection policies — the system then performs deep inspection on every request that passes through, and generates a unique Bot Score using a weighted aggregation algorithm across multiple risk dimensions.

Detection Engine

How It Works

Heuristic Detection

A "rule library" built on the accumulated experience of security experts.

The system collects a range of characteristics from each request in real time and matches them against a Bot intelligence library (cloud provider, proxy, and threat-intelligence risk IPs) and an anomaly detection rule library (User-Agent, HTTP request headers, TLS fingerprints, and other characteristics) to identify possible automated behavior.

Machine Learning

Data-driven "self-learning."

The system uses algorithmic models to learn from large volumes of normal traffic data and black-and-grey market data, uncovering anomalies such as clustered group activity and behavioral chains, in order to identify covert automated tools that may be disguised as normal users.

In short, the Bot Score is the result of combining security-expert knowledge, large-scale data analysis, and intelligent algorithms. It is not a “black box” — every detection dimension carries a clearly defined risk weight, and the final score directly reflects the request’s security risk level.

Detailed Detection Dimensions

The system evaluates each request across multiple dimensions, including IP intelligence, User-Agent, request headers, and fingerprints, and assigns the corresponding tags. For details, see the Bot Tag section.

Limitations

Currently, the Bot Score is used only in Bot Tag Forwarding to Origin and Log Analysis. More high-value use cases will be added in the future to help you manage Bot traffic more effectively.

Is the content of this document helpful to you?
Yes
I have suggestion
Submitted successfully! Thank you very much for your feedback, we will continue to strive to do better!