tencent cloud

Web Application Firewall

Browser Bot Defense

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-08-03 16:49:34
Diterjemahkan oleh AI
This document introduces the Frontend Defense feature in client risk identification. Using client dynamic security verification technology, this feature generates a unique ID for each client making a business request. It detects potential robot and malicious crawler activities during client visits to Web or HTML5 pages, thereby reducing the risk of core website APIs and business being threatened by BOT.

Background Information

Compatibility Notes: Frontend Defense is suitable for protecting web or HTML5 services. Using frontend defense technology, it dynamically generates a client ID and Token. By detecting the client ID and dynamic Token, it identifies malicious and crawler requests. In specific scenarios, POST requests may have compatibility issues (when the response body's content-type is not text/html and the response body does not contain an <html> Tag), causing abnormal frontend dynamic detection. In such cases, you can add the request path or response request to the allowlist.
Interactive Frontend Defense: This feature verifies and identifies eligible client requests by presenting a Captcha (such as a slider, puzzle, or character comparison). It distinguishes between human and bot (BOT) access behaviors and blocks requests that fail verification a certain number of times. It is suitable for protecting core website APIs (such as shopping cart, payment, and SMS APIs). This capability is already integrated into various handling actions (such as Observe, Human-Machine Verification, Redirect, and Block) within WAF. You can configure and use it according to your actual needs.
Non-Intrusive Frontend Defense: It performs client behavior detection without impacting user experience, making it suitable for scenarios with high requirements for user experience. Using dynamic security technology, Non-Intrusive Frontend Defense generates a unique client ID for each requesting client. It detects potential traffic flooding and malicious crawler activities during client visits to Web or HTML5 pages. You can take handling actions against malicious access behaviors according to your actual needs.
Attention:
Frontend Defense technology is only applicable to Web or HTML5 environments. It does not currently support mobile apps or mini programs.
Frontend Defense takes precedence over CC protection. Requests intercepted by Frontend Defense (HTTP 403) will not enter the CC protection process. Therefore, the 403 status codes in the attack logs may originate from Frontend Defense, not CC protection.

Prerequisites

You have purchased WAF and BOT Traffic Management.
Add and properly connect the domain name to be protected. The domain name is now under normal protection, and the master switch for BOT management rules is enabled. For details, see Quick Start.
Note:
Browser Bot Defense is not currently supported for domains added to Cloud-native WAF instances.
Browser Bot Defense is not currently supported for wildcard domains added to SaaS-WAF instances.
Based on the design of the defense feature, enabling the browser bot defense switch inserts JS into the Response, which may cause a slight increase in bandwidth between WAF and the origin server.

Protection configuration

1. Log in to the WAF console. In the left sidebar, choose BOT Management.
2. On the BOT Management page, select the domain to protect in the top-left corner.
3. On the BOT Management page, enable BOT management.
4. In Global Settings, click Configure now for the browser bot defense module to enter the Browser Bot Defense Configuration page.
5. On the Browser Bot Defense page, you can configure the switches for features such as Webpage anti-debugging and Automated identification, and add Allowlist policies.
6. In Scenario-based Management, select the target scenario and click View Configuration on the right.
7. On the Scenario Details page, click Browser Bot Defense to configure the browser bot defense feature for this scenario (enable/disable) and select a protection mode.
Field Description
Switch: Disabled by default. After you enable it, WAF performs browser bot defense on the pages within the specified scope of the domain to protect against security threats. It identifies potential crawler activities in client requests. You can take different handling actions against requests identified as crawler activities. This policy does not currently apply to APPs and mini programs.
Action: Monitoring by default. After you enable the switch, you can configure a handling action for crawler activities detected by the browser bot defense module. The action types include: Monitor, CAPTCHA, Redirect to, and Block.

Configuring the Allowlist Policy

1. Log in to the WAF console. In the left sidebar, choose BOT Management. On the BOT Management page, select the domain to protect in the top-left corner.
2. In Global Settings, click Configure now for the browser bot defense module.
3. On the Browser Bot Defense page, click Add rule to open the Add Allowlist Rule window.
4. In the Add Allowlist Rule window, configure the relevant parameters and click OK to complete the operation.
Field Description
Type
Request allowlist: Request paths or URLs that are added to the allowlist and do not require dynamic security detection under the protection path.
Response allowlist: JavaScript is inserted into the response pages under the protection path by default. You can specify pages where JavaScript is not inserted to improve website compatibility.
Condition: It supports Path suffix match, Equal to, Start with and Include. Path suffix match is the default.
Content: When the matching condition is Path Suffix Match, a list of file extensions that need to be added to the allowlist is provided by default, including: ico, gif, bmp, htc, jpg, jpeg, png, tiff, swf, js, css, rm, rmvb, wmv, avi, mkv, mp3, mp4, ogg, wma, zip, exe, rar, eot, woff, woff2, ttf, svg. You can modify this list based on your actual needs. For other matching conditions, enter the allowlist path according to your actual situation.
Rule description (Optional): Enter the rule description.
On/Off: It is Off by default. You can adjust it based on your actual needs.
5. Existing allowlist rules can be Edit or Delete.

Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan