Hi,
I am trying to find a solution for what appears to be an ongoing bot attack on my site which began about a week ago.
For bot prevention I have been using Cloudflare Firewall with Managed Challenge using dolcevita's corporate IP address rules as well as more stringent versions of other rules dolcevita posted.
Up until last week the rules have been working amazingly well. Adsense clawback for January 2023 was only 0.2%.
On February 17 Adsense earnings were 5x normal and traffic tripled according to Google Analytics. Traffic increased at the same multiples for both direct traffic and search. The increase in traffic (according to Analytics) is coming from all over the U.S.
It is a strange and sudden increase which is why I suspect bots. I did notify Adsense about the unusual increase in earnings, but do not expect to receive a response.
I added a new temporary firewall rule that gives a Managed Challenge to all visitors, but still allows known bots. Not a great solution, but quick to implement.
Since the new rule has been added traffic has been slowly coming back down to normal. It is still well above average with search being below average, maybe due to the managed challenge? Direct traffic is still about 2x normal which I suspect is most likely the bots.
Adsense earnings are still well above normal with only one day being on the high end of average.
I actually know little about reading the site logs and figuring out who, what, where to find the offending traffic.
Any recommendations for tutorials or a service that help me with the server logs?
Any ideas about how to fight this bot issue?
Thank you for any help.
P.S. Thank you dolcevita for posting your Cloudflare rules last year.
[
webmasterworld.com ]