Release Notes

最終更新日:2026-09-18 13:47:17

2026-09

Feature Description
Bot Management Added Bot Score as a matching condition in Custom Bot rules, allowing users to deny abnormal requests based on Bot Score for more granular bot protection.
AI Crawler Control Expanded the AI Bots feature into a standalone AI Crawler Management module within Bot Management, combining visual traffic analytics with granular control capabilities to help enterprises monitor and govern AI service providers' crawling and access behaviors.
Security Analysis Added analysis of Request Methods, JA3, and JA4 to provide deeper insights into traffic characteristics and improve anomalous traffic detection efficiency.
API Added an API for querying China Premium Service information. Customers can now look up the CPS for each resource group, streamlining self-service domain onboarding.
Shared Configurations Added a Client Lists API, enabling programmatic management of IP ranges, ASNs, and regions for automated operations.
Basic Function Optimized console access, allowing sub-accounts to sign in even when they have no authorized domains.
Basic Function Optimized the frontend component library styles to improve the overall user experience.

2026-08

Feature Description
Console Navigation Improved the console navigation bar to unify UI and interaction patterns across product lines, ensuring a smooth experience when switching between products.
IP Access Enabled automatic service order status lookup when binding a domain in AIP, ensuring the binding completes smoothly once the order sync finishes.
Security Report Improved the wording in English-language security reports for greater professionalism and readability.
Security Report Added time zone selection for security reports, enabling users to generate reports in the desired time zone with more accurate time information.

2026-06

Feature Description
Custom Rules & Custom Bots Added header-order matching to Custom Rules and Custom Bots, enabling detection based on the sequence of HTTP request headers for more granular and accurate policy enforcement.
Actions Added emoji support to Custom Actions, allowing users to insert emoji into block pages and error pages to make content more expressive and better aligned with their brand identity.
Traffic Fraud Detection Added detection and mitigation of slow-rate large-file scraping in Traffic Fraud Detection, automatically blocking persistent abuse over established connections — a scenario that was previously difficult to mitigate.
Bot Management Added a Skip action for AI Bots. For known AI crawler requests, the system logs the traffic and bypasses other Bot Management policy checks, while keeping WAF, API Security, and other protections active — ensuring website content remains accessible for indexing by AI search engines.
Bot Management Added 20+ AI Bot identification types covering crawlers from major LLM providers, expanding coverage for AI Bot traffic management.

2026-05

Feature Description
IP Access Added Anycast IP support to Secure Acceleration Pro, routing traffic through the nearest available node to reduce domain hijacking risks and improve connection reliability for global users.
Alert Management Optimized alert notification content to improve information readability in complex monitoring scenarios, enabling faster identification and response to security incidents.
Web Security Trends Improved data retrieval performance to resolve latency issues in scenarios with a large volume of domains, ensuring faster system responsiveness for large-scale asset management.
Web Security Trends Optimized security trend charts with dynamic statistical granularity and refined unit displays based on time spans, providing clearer visual insights for diverse analysis scenarios.
WAF Enabled custom default actions for WAF rule sets, letting users choose Block, Monitor, or Disable instead of using a fixed Block default, reducing the risk of unintended traffic disruption.

2026-04

Feature Description
Rate Limiting Support for custom response pages under status code matching conditions allows users to configure intercepted content, addressing the need for branded or personalized notifications while providing greater flexibility in maintaining brand consistency.
Custom Rules/Rate Limiting/Whitelist/Custom Bots By supporting wildcard matching for HTTP headers across multiple modules, this feature resolves the inability to match fuzzy traffic patterns, providing enhanced policy compatibility and configuration flexibility.
Bot Management Optimized the bot skip logic so that requests that match the skip rules will only skip bot protection, and other modules such as WAF and API security will still take effect normally. This prevents malicious attackers from using skip logic to forge legitimate bots and bypass overall security defenses, ensuring business access without weakening other protection capabilities.
Bot Management Added support for configuring custom bot rules according to specific paths to achieve fine-grained control of bot traffic, helping customers implement differentiated control for different URL paths and reduce the risk of false positives and false negatives.
Client List By adding "Region" to client list criteria, this feature addresses the issue of redundant geographic configurations across modules, enabling efficient reuse and unified management of security policies.

2026-03

Feature Description
Bot Management Added the Likely Bots feature to intelligently identify abnormal behaviors and deviations from normal user patterns, detecting stealthy automation tools to effectively prevent business fraud and data scraping. It supports one-click deny, continuous logging, or secondary challenge verification (JavaScript Challenge, Interactive Challenge), helping you flexibly manage Likely Bot traffic, enhance business security, and safeguard normal user access experiences.
Bot Management Optimized the Bot Tagging function, which marks Bot traffic characteristics and transmits the information back to your origin server through custom HTTP request headers. It supports Bot Score and Bot Tags.

2026-02

Feature Description
Rate Limiting Added an ASN matching condition, addressing the limitation that original rate limiting only supported IP, path and other dimensions, lacking precise control over requests from specific ASN sources. It enhances the accuracy and flexibility of the rate limiting function.
Rate Limiting Optimized the matching logic for two configured statistical dimensions: the original rule required both dimensions to be matched for a successful hit (match failed if either was missing); now a successful hit is achieved when either dimension is captured. This simplifies logic configuration and reduces missed interception of malicious requests.
Threat Intelligence Added support for configuring ASN and request header whitelists to specify ASN and request header traffic as exceptions. This precisely resolves false blocking issues caused by automated tool IPs of third-party partners, vendors, or data service providers that are included in the threat intelligence library.
Custom Rules Added a Query String matching condition, improving user experience and business adaptability.
Rate Limiting Added support for the 'JavaScript Challenge' action. For requests that trigger rate limiting, a JavaScript challenge page will be presented. This page uses browser environment detection, brief waiting, and automatic redirection to block malicious automated traffic while optimizing the user experience. This approach achieves a better balance between security and usability, enhances protection against sophisticated attacks, and increases the cost for attackers to simulate legitimate behavior.

2026-01

Feature Description
Rate Limiting/Whitelist A client list is added to the matching conditions. Users can consolidate client information requiring batch maintenance (such as enterprise egress IPs or partner IPs) into a single list for unified management, which simplifies configuration maintenance costs and improves management efficiency.
Rate Limiting The statistical granularity supports multi-dimensional combined counting. It enables free combined statistics based on multiple protection dimensions including IP, specified Cookies, URLs, User-Agents, and request headers, achieving more refined access frequency limiting. This addresses complex attack scenarios such as "the same IP polling different interfaces" and "the same IP switching Cookies", improves the accuracy of identifying malicious requests, and reduces the risk of false interception.
Rate Limiting Actions support IP blocking. When a request triggers the policy, it blocks all subsequent requests from the client’s IP, enabling rapid and automatic blocking of threats such as high-frequency attacks and scanning tools, reducing manual handling costs and improving real-time protection efficiency.
Analysis & Logs - Web Security Trends When performing security trend analysis, users can pin one or more objects to improve the consistency and efficiency of the analysis process.
Threat Intelligence Added support for configuring an IP address whitelist to exclude specific IP address requests from being blocked, precisely resolving false blocking issues caused by automated tool IPs of third-party partners, vendors, or data service providers that are included in the threat intelligence library.
Whitelist Added a new 'GEO' matching condition, allowing requests from specified regions to bypass filtering. This meets customer requirements for region-based whitelist controls.
Bot Management Added Kakao search engine crawler identification to support the identification of official crawler traffic from the Kakao search engine and to effectively identify abnormal or malicious requests disguised as Kakao crawlers for classification control.

Optimized Yeti search engine crawler recognition by updating the User-Agent characteristics of the Yeti search engine crawler to improve recognition accuracy and reliability.
Through accurate crawler recognition and classification capabilities, it focuses on solving the problem of managing the traffic of local mainstream search engines (such as Kakao and Yeti) when conducting business in the Korean regional market.
Security Report Attack traffic information is added to L3/4 DDoS Attack, making protection effectiveness measurable and easy to interpret, and supporting internal security reviews and reporting tasks.
DDoS Protection Adjust the default protection level of Application-Layer DDoS for hostname access according to different customer types. It helps users select the appropriate default protection level according to their different risk characteristics and service scenarios, and reduce the probability of false negatives during initial access protection.

2025-10

Feature Description
DDoS Protection Adjusted the DDoS Protection level description. Added descriptions of scenarios for selecting each level to guide customers in selecting the appropriate protection level, reducing the probability of false positives.
Alert Management Updated the WAF rule matching function so that the entire protection process forms a closed loop: attack → monitoring → protection.

Optimized the read and write permissions of custom rules for monitoring objects. Clearly distinguished the read and write permissions of the main and sub-accounts on monitoring objects.
Traffic Fraud Trends The newly added Traffic Fraud Trends function presents traffic theft trends, source distributions, target resources, and more. This helps users understand the overall protection situation and improves the efficiency of theft analysis and resolution.

2025-09

Feature Description
Bot Management [New Feature] AI Bots
Added 20+ new AI large-model crawler detection rules, which mainly provide you with the ability to intercept/monitor known AI bots with one click, preventing AI large-model crawlers from causing copyright theft or sensitive data leakage on your website.

[Optimization function] Public Bots
Optimized the original known-bot classification and management logic and enhanced the coverage of known public bots, mainly providing you with the ability to release/intercept/monitor known public bots with one click, such as crawlers for website SEO, market analysis, website monitoring, etc.

[Optimization function] Definite Bots
We've optimized the original User-Agent feature detection management logic and added over 30 new fake spider (i.e., fake public bot) detection rules. These rules primarily allow you to one-click intercept/monitor traffic from non-public, clearly automated programs, such as automation frameworks, HTTP libraries, vulnerability scanners, proxy tools, fake spiders, and more.

[Optimization function] Web Risk Detection-Application Request Whitelist
The application request whitelist configuration path has been moved to the Web Risk Detection feature, and support for AJAX request exceptions has been added.

2025-08

Feature Description
Analysis & Logs - Alert Management Alert management function focuses on attack detection scenarios in security operations, and enables users to manage security-related alert rules and triggered historical events. Through this feature, users can flexibly adapt to security monitoring requirements: they can directly enable system predefined rule notifications or customize alert policies to achieve real-time awareness of business abnormal status; meanwhile, users can also view alert history records to understand and trace back the attack situation.

2025-07

Feature Description
Rate Limiting Added support for interactive CAPTCHA. The client needs to check a certain checkbox for verification. Compared with the original CAPTCHA action, the interactive experience has been enhanced.
WAF The Scan Protection module supports Scanner Detection and Repeated Violation Detection, enhancing the effectiveness of scan protection and enabling customers to handle vulnerability scanning with ease.

2025-06

Feature Description
WAF Added the following Managed Rule types to WAF: AI Component Framework Vulnerability and Mainland China-Developed Software Vulnerability.

2025-05

Feature Description
DDoS Protection Improved adaptive protection capabilities and the interaction experience.

2025-02

Feature Description
Custom Rules The conditions for Custom Rules have been enhanced with the addition of JA3 and JA4 fingerprints, allowing for more flexible rule configuration to precisely match specific client traffic.

2025-01

Feature Description
IP/Geo Block, Rate Limiting, Custom Rules The match condition "Region" now includes "Asia-China-unknown" to cover IP addresses in Mainland China that have not been assigned a specific location.

2024-12

Feature Description
Traffic Fraud Detection Bot Management - Traffic Fraud Detection is primarily used to identify and mitigate traffic scraping behaviors. This update adds a console management entry, supporting one-click start/stop of protection through the console, specifying Protection Periods/Actions, and configuring Protection Exceptions. Additionally, the detection model has been optimized for more accurate identification and blocking of scraping activities. If the console does not have access to Traffic Fraud Detection, please contact technical support for evaluation and activation.