EMZETT.
Login

Bot protection

In short: Bot protection means measures that keep automated access (bots) away from a website without disturbing real visitors.

In more detail: Bots create spam, try stolen passwords (credential stuffing), copy content or overload servers. Good protection combines several layers, because no single one is enough.

In Depth

  • CAPTCHA and Turnstile: tasks or invisible checks that humans pass easily. Cloudflare Turnstile works without puzzle images (Cloudflare).
  • Rate limiting: limits the number of requests per time and address (rate limiting).
  • Honeypot: a hidden form field that only bots fill in. Whoever fills it in is rejected.
  • WAF and rules: a WAF blocks known bad patterns and addresses.
  • Behaviour analysis: mouse movement, speed and sequence are assessed.
  • Account protection: two-factor login makes stolen passwords useless.
  • robots.txt: a request to friendly bots, no protection against bad ones.

Trade-offs

Checks that are too strict lock out real users or threaten accessibility and privacy. Good methods are unobtrusive and block only on suspicion.

See also: bots, DDoS, crawler