cd /news/ai-crawlers/how-to-stop-bad-bots-and-ai-scrapers · home › topics › ai-crawlers › article
[ARTICLE · art-148131] src=dev.to ↗ pub= topic=ai-crawlers verified=true sentiment=· neutral

How to Stop Bad Bots and AI Scrapers

A developer has published a tutorial on using Aegis, an open-source, self-hosted web application firewall and reverse proxy, to block automated scrapers, AI training crawlers, and credential-stuffing bots. The guide walks through enabling bot protection, setting per-crawler policies for GPTBot, CCBot, Anthropic, and Bytespider, and deploying client-side cryptographic browser challenges that drop headless scripts at the edge. It notes that automated traffic accounts for over 40% of all internet traffic.

by read2 min views2 publishedOct 9, 2026

-- Automated scrapers, AI training crawlers, and credential stuffing bots account for over 40% of all internet traffic.

Allowing bots to scrape your web application without restrictions inflates hosting bills, degrades performance for real users, and drains database connection pools.

In this tutorial, we are going to use Aegis—an open-source, self-hosted Web Application Firewall (WAF) and reverse proxy—to configure automated bot defense, manage AI scrapers, and deploy client-side cryptographic browser challenges.

#

Step 1: Access Bot Defense Settings

  1. Open your Aegis Admin Console at http://server-ip:8081 .
  2. In the left navigation menu, navigate to Traffic Control > Bot Defense .
  3. Toggle on Enable Bot Protection .

Aegis evaluates incoming client fingerprints, request headers, and traffic behavioral patterns in real time.

#

Step 2: Configure AI Crawlers and Scraper Policies

Manage how automated crawlers access your site:

Search Engine Crawlers: Toggle onAllow Verified Search Engines (Googlebot, Bingbot, DuckDuckGo). Aegis verifies reverse-DNS signatures to ensure fake bots cannot spoof search engine user-agents. 2. AI Scrapers & Training Bots: Select your policy for known AI crawlers (GPTBot, CCBot, Anthropic, Bytespider): - Block: Immediately drop requests withHTTP 403 Forbidden . #

Challenge: Require the bot to pass a client-side challenge. 3. Click Apply Policy .

#

  Step 3: Deploy Client-Side Browser Challenges (Smart Challenge)

For requests that exhibit suspicious behavior or exceed baseline request velocities:
  1. Under Mitigation Strategy , selectBrowser Challenge (Smart Challenge) .
  2. When a suspected bot requests a protected page, Aegis returns a lightweight HTML payload that executes a fast cryptographic challenge in the background.
  3. Genuine human visitors running modern web browsers solve the challenge automatically in milliseconds without seeing a CAPTCHA.
  4. Headless scripts, scraping tools, and automated botnets fail the execution and are dropped at the edge.

#

Step 4: Verify Bot Mitigation

Test the endpoint with an automated CLI client:

Response:

The request is rejected at the ingress proxy and never reaches your origin web server.

#

Resources

The Community Edition is free to self-host:

── more in #ai-crawlers 4 stories · sorted by recency
── more on @aegis 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/how-to-stop-bad-bots…] indexed:0 read:2min 2026-10-09 · —