Why we stopped fighting bots at the App layer
Use Cases and Deployment Scope
We are mostly using it on login portals, signup forms, cart pages, pricing tools and search endpoints. These areas tend to attract credential stuffing, scarping and account takeovers especially for fintech and e-com clients. We deploy it through the main cloud platform, integrated with both our edge proxy and app backend.
Pros
- Distinguishing between automated traffic and real users without breaking the front end or overloading our WAF
- I absolutely love the telemetry fingerprinting.
- The integration through the console has made rollouts much faster.
Cons
- The documentation is thin on edge-case handling. We constantly run into issues enabling bots on multi tenant apps.
Likelihood to Recommend
In my 7 year career as a security engineer, F5 Distributed Cloud Bot Defense is one of the few solutions that actually delivers bot mitigation without affecting the real users. Behavior detection is really smart and fast, which is what we needed for protecting sensitive endpoints. The only thing however that could get better is the admin console. everything is everywhere here.
