Protect static resources
Edge Security Acceleration (ESA) bot management protects static resources such as images, audio, video, CSS, and JS files from unauthorized crawling and bandwidth abuse. The system identifies malicious bots through behavior analysis and blocks their requests for cached content.
How static resource protection works
Static resources such as audio and video files, images, and CSS or JS files are typically served from the cache and do not trigger back-to-origin requests. Traditional mitigation policies focus on bot attacks against dynamic requests and overlook static resource traffic.
However, a malicious bot can hotlink the URL of a static resource directly, which causes unusual consumption of bandwidth and origin server resources.
ESA bot management addresses this scenario. The system identifies malicious bots and blocks their requests for static resources based on bot classification and risk level. This prevents crawlers from abusing cached resources or consuming bandwidth, while legitimate bots continue to crawl your content.
Prerequisites
Before you enable static resource protection, configure protection actions for at least one bot classification category: Definite Bots, Likely Bots, or Verified Bots.
Enable protection in Smart Mode
Smart Mode provides a quick way to enable static resource protection. Configure protection actions for one or more bot classification categories, and then turn on the Static Resource Protection switch. ESA then applies bot classification policies to cached static resource requests and blocks requests based on their risk levels.
In the ESA console, select Websites, and in the Website column, click the target site.
In the left navigation pane, choose .
On the Smart Mode page, click Configure for Definite Bots, Likely Bots, or Verified Bots, and set the protection action.
Definite Bots: This category includes many malicious crawlers. Set the action to Block or Slider CAPTCHA.
Likely Bots: Lower risk than Definite Bots but may include malicious crawlers and other traffic. Set the action to Monitor, or to Slider CAPTCHA during high-risk periods.
Verified Bots: This category usually includes crawlers from search engines that support SEO. Set the action to Allow. To block all search engine crawlers, set the action to Block.
Definite Bots: This category includes many malicious crawlers. Set the action to Block or Slider CAPTCHA.
Likely Bots: Lower risk than Definite Bots but may include malicious crawlers and other traffic. Set the action to Monitor, or to Slider CAPTCHA during high-risk periods.
Verified Bots: This category usually includes crawlers from search engines that support SEO. Set the action to Allow. To block all search engine crawlers, set the action to Block.
Definite Bots: This category includes many malicious crawlers. Set the action to Block or Slider CAPTCHA.
Likely Bots: Lower risk than Definite Bots but may include malicious crawlers and other traffic. Set the action to Monitor, or to Slider CAPTCHA during high-risk periods.
Verified Bots: This category usually includes crawlers from search engines that support SEO. Set the action to Allow. To block all search engine crawlers, set the action to Block.
Definite Bots: This category includes many malicious crawlers. Set the action to Block or Slider CAPTCHA.
Likely Bots: Lower risk than Definite Bots but may include malicious crawlers and other traffic. Set the action to Monitor, or to Slider CAPTCHA during high-risk periods.
Verified Bots: This category usually includes crawlers from search engines that support SEO. Set the action to Allow. To block all search engine crawlers, set the action to Block.
Definite Bots: This category includes many malicious crawlers. Set the action to Block or Slider CAPTCHA.
Likely Bots: Lower risk than Definite Bots but may include malicious crawlers and other traffic. Set the action to Monitor, or to Slider CAPTCHA during high-risk periods.
Verified Bots: This category usually includes crawlers from search engines that support SEO. Set the action to Allow. To block all search engine crawlers, set the action to Block.
Definite Bots: This category includes many malicious crawlers. Set the action to Block or Slider CAPTCHA.
Likely Bots: Lower risk than Definite Bots but may include malicious crawlers and other traffic. Set the action to Monitor, or to Slider CAPTCHA during high-risk periods.
Verified Bots: This category usually includes crawlers from search engines that support SEO. Set the action to Allow. To block all search engine crawlers, set the action to Block.
Definite Bots: This category includes many malicious crawlers. Set the action to Block or Slider CAPTCHA.
Likely Bots: Lower risk than Definite Bots but may include malicious crawlers and other traffic. Set the action to Monitor, or to Slider CAPTCHA during high-risk periods.
Verified Bots: This category usually includes crawlers from search engines that support SEO. Set the action to Allow. To block all search engine crawlers, set the action to Block.
Turn on the Static Resource Protection switch.
Verify that the Static Resource Protection switch is in the On position.
If the Static Resource Protection switch is unavailable, configure protection actions for at least one bot classification category first.
Create a static resource protection rule
Professional Mode lets you create a custom protection ruleset for static resources. Use Professional Mode to apply fine-grained mitigation policies based on bot behavior identification, characteristic-based matching, and whitelist-based exceptions.
In the ESA console, select Websites, and in the Website column, click the target site.
In the left navigation pane, choose .
Click Professional Mode > Create Ruleset, and follow the on-screen instructions to enter Rule Set Name and select Service Type and SDK Integration.
In the If requests match... section, set the match field to Serves Static Resources, set the operator to equals, and set the switch to
. In the Then execute... section, select and configure the mitigation policy that you need.In the Effective Time section, click Edit in the Actions column, set the effective time, and then click OK.
After you complete the configuration, click OK.
Verify that the ruleset appears in the ruleset list with the status Enabled.