Illustrative security case study

Beyond Cloudflare: stopping advanced automated registration abuse

How SiARA Shield can protect a SaaS registration journey against rotating identities, automated challenge solving and high-volume fake account creation.

Website Create Account journey protected against automated fake sign-ups
Illustrative SaaS registration security scenario based on advanced automated-abuse patterns.

A public-facing SaaS registration journey was protected by Cloudflare as part of its existing web-security stack. The scenario examines a modern automated sign-up operation using browser automation, rotating network identities, changing session characteristics and commercially available challenge-solving services.

Passing a network or browser security challenge should not automatically be treated as proof that a genuine human is performing the protected action.

The key risk was not a single fake account, but the ability to repeat the workflow at machine speed across concurrent workers. For this registration journey, SiARA Shield replaced the existing Cloudflare bot/challenge control protecting account creation, moving the security decision closer to the high-value action: account creation.

At a glance

Platform at a glance

Market segment
SaaS / Digital Services
Channel
Public web sign-up
Existing security
Cloudflare-protected web app
Threat
Automated fake accounts
Replacement control
SiARA Shield
Use case
Public account registration
Existing challenge
< 5 sec scenario average for automation to progress through the existing challenge
End-to-end sign-up
< 20 sec scenario average from session initiation to completed registration
Key results

Machine-speed abuse as an application risk

< 5 sec

scenario average for automation to progress through the existing challenge.

< 20 sec

scenario average from session initiation to completed registration.

1,000s/hr*

theoretical potential when automated workers run concurrently.

Near zero

illustrative automated registration activity after SiARA Shield was introduced.

The challenge

A modern attack chain is designed to look less repeatable

The automated workflow continuously changes its technical identity while repeatedly targeting the same business action: account creation.

Rotating network identity. Repeated attempts arrived through changing network identities, weakening simple per-IP correlation.

Changing browser/session signals. Fresh sessions and varied browser characteristics made repeated automation less obviously related.

Outsourced challenge solving. Commercial solving services can become another programmable component in an automated workflow.

Conceptual automated sign-up flow targeting account creation
At a 20-second journey, one worker could theoretically attempt ~180 registrations per hour. Parallel execution can multiply that exposure rapidly.
Conceptual automated sign-up flow

Why the existing controls did not stop this scenario

The scale effect: at a 20-second journey, one worker could theoretically attempt ~180 registrations per hour. Parallel execution can multiply that exposure rapidly — which is why machine-speed abuse must be treated as an application risk, not only a traffic problem.

1. Automation Browser workflow
2. Rotation IP / session changes
3. Cloudflare Existing controls
4. Solver External service
5. Sign-up Account created

Before: Internet traffic > Cloudflare > Registration. After: Internet traffic > SiARA Shield > Registration / account creation.

SiARA Shield | Replacement protection

Put human verification before the action that matters

For this registration journey, SiARA Shield replaced the existing Cloudflare bot/challenge control with TSM-based human verification immediately before account creation.

Identity rotation does not bypass TSM

Attackers may still rotate IPs, proxies, sessions and browser fingerprints. Those changes can alter how a bot appears, but they do not enable it to satisfy the TSM verification step.

What is Trans-Saccadic Memory (TSM)?

TSM is a human visual-memory mechanism that helps the brain retain and integrate visual information across rapid eye movements. CyberSiARA’s TSM-based technology uses characteristics of human visual interaction to distinguish genuine human activity from automated systems.

How TSM breaks the automated journey

The attacker can continue changing proxies, IP addresses, sessions and browser fingerprints. But once the workflow reaches SiARA Shield, those infrastructure changes do not help the bot progress.

The journey stops before account creation

If it cannot satisfy the TSM-based human-verification step, the journey stops before account creation.

TSM-based. No traditional CAPTCHA. No cookies.

SiARA Shield | Human verification & advanced bot protection.

Results & business impact

Illustrative automated registration activity

Before: sustained high-volume activity. Thousands of automated registrations / hour (illustrative). After: near zero.

Changing the bot’s technical identity does not make it human. TSM verifies the human before the protected action is completed.

Illustrative security trend. Before: thousands of automated registrations / hour (illustrative). After: near zero.
Security & business impact

Business exposure from automated sign-ups

Compute, API, database, storage, bandwidth and logging consumed by illegitimate activity. Security, fraud, support and operations teams inherit investigation and cleanup workload.

CISO takeaway: changing the bot’s technical identity does not make it human. TSM verifies the human before the protected action is completed.

Business exposure from automated sign-ups

  • Infrastructure cost — compute, API, database, storage, bandwidth and logging consumed by illegitimate activity.
  • Operational cost — security, fraud, support and operations teams inherit investigation and cleanup workload.
  • Data integrity — fake accounts distort acquisition, conversion, attribution and customer analytics.
  • Fraud & abuse — trials, promotions, referrals, messaging and downstream platform features can be exploited.
Why it matters

Changing the bot’s technical identity does not make it human

Passing a network or browser security challenge should not automatically be treated as proof that a genuine human is performing the protected action.

TSM verifies the human before the protected action is completed.

Scenario note: Illustrative SaaS registration security scenario based on advanced automated-abuse patterns. Scale exposure of 1,000s/hr is theoretical potential when automated workers run concurrently. At a 20-second journey, one worker could theoretically attempt ~180 registrations per hour.

See what is reaching your applications

Put human verification before the action that matters.

SiARA Shield | Human verification & advanced bot protection | TSM-based. No traditional CAPTCHA. No cookies.