본문으로 건너뛰기

Action Mode

Action Mode defines how to process access requests determined to be bots by policies.

Mode Types

BotManager provides two action modes:

ModeDescriptionUser Experience
DetectionDetected as a bot but access is allowedNormal service usage available
BlockDetected as a bot and access is blockedBlock page displayed or secondary verification

Detection Mode

How It Works

In detection mode, even if determined to be a bot, actual blocking does not occur.

Features

  • Bot determination results are recorded in logs
  • Users can use the service normally
  • Counted as detection count in statistics data
  • Secondary verification does not operate

Use Cases

ScenarioDescription
Policy TestingAssess impact before applying new policies
Threshold TuningMonitor to derive appropriate threshold values
False Positive AnalysisAnalyze cases where normal users are detected as bots
Recommended Usage

When applying new policies, it is recommended to first operate in detection mode to collect sufficient data, then switch to blocking mode.

Blocking Mode

How It Works

In blocking mode, requests determined to be bots are actually blocked.

Features

  • Access by users determined to be bots is blocked
  • Block page displayed to blocked users
  • Additional verification possible through secondary verification
  • Automatic block release time can be set

Secondary Verification Integration

In blocking mode, you can configure secondary verification:

Secondary VerificationDescription
Not ConfiguredImmediate block when determined to be a bot
ConfiguredAdditional verification through CAPTCHA or browser challenge

For more details, see Secondary Verification.

Mode Selection Guide

  • When first applying policies
  • When adjusting threshold values
  • When checking for false positives of normal users
  • When understanding traffic patterns
  • After sufficient operation in detection mode
  • When policy thresholds are verified
  • When clear bot attacks are confirmed
  • When immediate defense is needed

Precautions When Switching Modes

Detection → Blocking Switch

  1. Recommended to operate in detection mode for at least 1-2 weeks
  2. Analyze detection statistics to check for false positives
  3. Adjust thresholds if necessary, then switch to blocking mode
  4. Continue monitoring statistics after switching

Blocking → Detection Switch

  • Applied immediately
  • Already blocked users remain blocked until automatic release time
  • Detection mode applies only to new bot determinations

Per-Policy Mode Configuration

Each policy can have its action mode configured individually:

정보

If a single access request is determined to be a bot by multiple policies, it will be blocked if even one policy is set to blocking mode.

Statistics Recording

Statistics recording by action mode:

ItemDetection ModeBlocking Mode
Detection CountO-
Block Count-O
Bot Type StatisticsOO
Access IP RecordsOO