Web应用防火墙
Search documents
一个网站的更新,让外国人集体断网6小时
虎嗅APP· 2025-11-20 10:18
Core Points - The article discusses a significant outage of Cloudflare that caused widespread internet disruptions for approximately six hours, affecting numerous websites and online services globally [5][6][76]. - Cloudflare is described as an essential internet infrastructure provider, likened to a property management company for websites, responsible for security, speed, and traffic management [35][41]. - The outage was triggered by a misconfiguration during an update, leading to a database overload that caused the system to crash [46][52][76]. Group 1: Incident Overview - The outage began when users experienced difficulties accessing popular platforms like Twitter and ChatGPT, with many websites displaying Error 500 messages indicating Cloudflare's failure [7][14][16]. - The incident led to a collective outcry from users, highlighting the dependency on Cloudflare for internet access [16][19]. - The outage lasted nearly six hours, with services gradually restored after identifying and reverting to a previous stable configuration [75][76]. Group 2: Cloudflare's Role and Functionality - Cloudflare operates over 330 data centers worldwide, optimizing website access speed and providing security features such as DDoS protection and web application firewalls [38][41]. - The company’s architecture involves a complex database system designed to handle vast amounts of data, which was compromised during the incident due to a permissions adjustment [52][54]. - The misconfiguration led to a chaotic response from the system, where multiple data sources provided conflicting information, overwhelming the database and causing the crash [58][62]. Group 3: Implications and Future Considerations - The outage underscores the vulnerabilities inherent in relying on a few key infrastructure providers, as disruptions can have far-reaching consequences for businesses and users alike [81][87]. - Previous incidents, such as an AWS outage affecting millions, highlight the potential economic impact of such failures, with losses estimated in the millions per hour [81][82]. - The article calls for infrastructure companies to learn from these incidents to improve their systems and prevent future outages [85][88].
“北京榜样•最美互联网从业者”提名人选|董志强:守护云端安全的掌门人
Sou Hu Cai Jing· 2025-10-14 07:12
Core Insights - The article highlights the journey of Dong Zhiqiang, Vice President of Tencent Security and head of the Cloud Security Lab, emphasizing his transition from a literature major to a key figure in cybersecurity, driven by passion and dedication [1][4]. Group 1: Cybersecurity Achievements - Dong Zhiqiang gained recognition in the cybersecurity field after developing the "Super Patrol" tool, which successfully intercepted the widespread "Panda Burning Incense" virus in 2007, marking his rise to prominence [4]. - He led a team that assisted in dismantling a criminal gang responsible for nearly half of the DDoS black market in China in 2017, significantly curbing the rampant DDoS attacks at that time [4]. - In 2020, he identified the emerging threat of AI-related cybercrime, leading efforts that resulted in the arrest of over 20 individuals involved in high-tech, covert black market activities [4]. Group 2: Cloud Security Strategies - Dong Zhiqiang emphasizes the importance of a multi-faceted approach to cloud security, focusing on three interconnected areas: technical breakthroughs, standard development, and platform governance, to create a robust security framework [5][8]. - Under his leadership, the Cloud Security Lab has developed core security products such as cloud firewalls and data security platforms, which are widely used within Tencent Cloud and by external enterprises [8]. - He actively participates in the formulation of cloud security standards, contributing to over ten standards and white papers, including the "Container Security Standard" and "Cloud Native Security White Paper," which influence both enterprise clients and national critical information infrastructure [8]. Group 3: Commitment to Continuous Improvement - Dong Zhiqiang believes that cybersecurity is an ongoing journey with no endpoint, requiring professionals to stay at the forefront of technology, standards, and operations [9]. - He has shared memorable moments from his career, such as providing free security services to small and medium-sized enterprises during the 2022 Spring Festival, showcasing the human aspect of cybersecurity [11]. - His daily routine reflects a deep commitment to cybersecurity, as he routinely reviews attack interception reports and engages with security technology literature, demonstrating a continuous learning mindset [11].
Cloudflare 的 AI 新叙事:线上内容“做市商”,Agent 互联网流量基建
海外独角兽· 2025-09-12 12:04
Core Viewpoint - Cloudflare is evolving its business model to adapt to the changing internet landscape, particularly with the introduction of the "Pay-per-crawl" service, which aims to redefine content monetization in the age of AI and address the challenges faced by content creators as traditional revenue models become less effective [2][3][20]. Company Overview - Cloudflare, founded in September 2010, has a current market capitalization of $78.2 billion and annual revenue of $1.8 billion, making it the largest CDN provider globally. The company has over 265,000 paid customers, with 36% of Fortune 500 companies using its services. The gross margin stands at 75%, and the revenue has grown at a compound annual growth rate of over 42% over the past five years [5][6]. Business Segments - Cloudflare operates three core business segments: - Zero Trust Service: Protects internal and external access security - Network Services: Provides DDoS protection and intelligent routing - Application Services: Includes web application firewalls and CDN services [6]. Pay-per-Crawl Introduction - The "Pay-per-crawl" service allows content creators to set permissions for AI crawlers, including options for free access, pay-per-crawl, or blocking access entirely. This service is still experimental and aims to provide a more equitable market for content creators [31][32][33]. Impact of AI on Content Monetization - The rise of AI chatbots is disrupting traditional internet monetization models, shifting the focus from search engines to answer engines, which directly provide answers rather than links. This transition is leading to decreased traffic for content creators, making it harder to monetize their work [20][21][24]. Challenges for Content Creators - Content creators face several challenges, including: - The potential disappearance of high-quality news and academic content due to unsustainable revenue models - The risk of content monopolization by a few companies - The need to establish new business models that allow for revenue sharing with content creators [28][29][30]. Cloudflare's Role in the New Ecosystem - Cloudflare aims to act as a market maker, facilitating transactions between content creators and AI companies, particularly for long-tail content creators. The company is exploring mechanisms to ensure fair compensation for content creators while promoting knowledge sharing across AI platforms [39][40]. Future Opportunities in AI - Cloudflare sees significant opportunities in improving inference compute efficiency, which is currently limited by high power consumption. The company aims to become a key player in the AI infrastructure space, similar to VMware's role in the virtualization market [48][49][50].