Skip to main content

Overview

All Traffic Configurations that are proxy services (HTTP Proxy and L4 Proxy) are always protected from Network DDoS attacks and malicious known bad actor Source IPs in our IP Reputation feed.

You can enable Rate-limiting on each Traffic Configuration to mitigate smaller singular IP high-rate application attacks. It’s always recommended to enable Rate-limiting as it can identify and stop bad actors during an application attack.

When an application flood attack is identified using the configured rate-liming values, mitigation starts by initially rate-limiting the HTTP requests. The client will receive a 429 Too many requests message for each request violating the configured values.

If the attack persists over time, a mitigation rule is created and installed into our DDoS mitigation platform. These rules are then active until the HTTP attack stops.

We use a leaky bucket algorithm to identify the attacks. We have two different keys we are identifying attacks based on: Source IP and Source IP:Path.