最終更新日:2026-08-21 15:59:36
Reading time: About 6 minutes
As internet adoption becomes universal and automation accelerates, Bot traffic has grown into a significant share of overall network traffic. While automated tools and intelligent agents make everyday life more convenient, they also pose major challenges to network security. Recent research shows that Bot traffic now accounts for more than 50% of global internet traffic.
Bot traffic is highly mixed in composition, and businesses may view some types as beneficial and others as unwanted. Based purely on intent, Bot traffic falls into two categories:
Note: We do not classify Bots as good or bad on your behalf. You need to select the appropriate Bot management policies based on your website’s business content, allowing beneficial Bot traffic through while mitigating malicious Bot traffic.
We are committed to building a simple, intelligent automated threat protection system that balances strong security with an excellent user experience.
Built on the WAAP architecture, the product uses Bot intelligence, heuristic detection, machine learning, and active detection technologies to identify and manage different types of automated traffic on your network — helping keep your business secure, stable, and competitive.

The following are the main Bot management policies. For details, see the corresponding sections.
| Policy Name | Description | Use When |
|---|---|---|
| Custom Bots | Lets you define specific Bot characteristics — such as User-Agent, request headers, and fingerprints — to precisely manage particular types of traffic. | Use when your website receives traffic from explicitly authorized automation tools run by your own organization or by third-party vendors, and you need to allow this traffic so it isn’t mistakenly blocked by subsequent Bot policies. |
| AI Bots | Manages automated traffic related to AI applications, including AI search crawlers, AI assistants, AI data scrapers, and undocumented AI agents. | Use when you want to block AI large-model crawlers with a single click, to prevent issues such as copyrighted content theft and sensitive data leaks. |
| Public Bots | Manages traffic from bots that are publicly declared on the internet, such as those used for SEO, marketing analysis, and website monitoring. | Use when you want to allow public crawlers that benefit your business with a single click. |
| Definite Bots | Manages non-public automated traffic with clearly identifiable characteristics, including automation frameworks, development frameworks, HTTP libraries, vulnerability scanners, crawler tools, proxy tools, and fake spiders. | Use when you want to block, with a single click, malicious automated activity carried out using crawler development tools, frameworks, and scanners commonly used by black-and-grey market operators. |
| Likely Bots | Manages traffic with abnormal behavior patterns that deviate from normal user characteristics, using multi-dimensional detection to identify potential hidden automation tools and reduce malicious attacks such as business fraud and data scraping. | Use when you want to apply secondary verification to suspicious requests that are highly likely to come from automated tools, so you can determine whether to block the malicious automation. |
| Web Bot Detection | Strengthens Bot defense in specific client scenarios using active detection technology, such as embedding a JS SDK in HTML pages. | Use for Web/H5 pages accessed through standard desktop or mobile browsers, including pages loaded through the built-in browser inside apps or mini programs (enhanced defense). |
| Workflow Detection | Applies custom rules based on the behavior logic of normal users to identify Bot traffic that doesn’t follow expected logic. | Use when you want fine-grained control over Bot traffic based on your own business logic (enhanced defense). |
Policies are matched in the following priority order, from top to bottom, and the request is handled according to the configured action:
1. Policy execution constraints:
2. Scope of Web Bot Detection: