Alright, let's get right into it. I've been running Prolexic for about eighteen months now, and while the marketing loves to talk about "intelligent edge" and "zero-day mitigation," I wanted to see what the raw data actually says about when we're getting hit. Everyone assumes it's a constant barrage, but my hypothesis was that a lot of this is just noise—automated scans and opportunistic bots that get flagged as "attacks" to justify the premium price tag. So, I pulled the incident logs and aggregated by hour of the day for the last quarter.
The results are, frankly, predictable and a bit disappointing if you're expecting a sophisticated threat landscape. The vast majority of what Prolexic categorizes as 'attack events' cluster predictably between 9 AM and 5 PM UTC, with a distinct lull overnight. This isn't some elite hacker collective carefully timing their strikes; this is the schedule of the global botnet and script kiddie ecosystem. It follows the sun, more or less. The peak "attack" hour is consistently around 2 PM UTC, which correlates with business hours overlapping across Europe, Africa, and the start of the East Coast US. What does that tell you? It tells me we're paying for a service that is primarily mitigating volumetric, non-targeted garbage—the kind of stuff a well-configured, self-hosted open-source WAF with rate limiting could probably handle for a fraction of the cost.
Digging into the event types during these peaks reveals another layer of the charade. Over 70% are classified as "application-layer anomalies" or "protocol violations," which in plain English often means badly formed packets or aggressive crawlers, not genuine DDoS attempts. The truly high-bandwidth network-layer events are rare, maybe a handful a month, and even those don't necessarily align with the peak times. This raises a serious question about the value proposition. We're locked into a multi-year contract with steep minimum commitments for a service that spends most of its cycles cleaning up internet background radiation, which they get to define as an "attack."
I'm sharing this because before you get sold on the fear and the glossy dashboard, you need to ask what you're actually buying. Is it peace of mind for a truly catastrophic event, or is it an expensive filter for junk traffic? My data suggests it's overwhelmingly the latter. The real cost isn't just the monthly invoice; it's the operational complacency it breeds and the migration pain you'll face if you ever want to leave. Their data egress and log integration are proprietary mazes, designed to make switching a herculean task. So, while the hourly attack frequency chart looks impressive in a board meeting, the substance behind it is far less compelling.
Just my two cents
Skeptic by default
You're onto something, but you're stopping at the most obvious layer. The diurnal pattern itself isn't the critique. The question is whether those 9-to-5 events represent actual mitigated threats or just low-fidelity noise. Have you correlated the hourly incident volume with your own application's traffic logs and error rates during those same windows? If there's no corresponding spike in 5xx errors, latency, or packet loss on your origin, then you're essentially just graphing their detection policy.
Prolexic's SLAs are typically based on mitigation capacity, not on the intelligence of their filtering. Your data might actually validate their model, if they're designed to absorb massive, predictable volumetric junk so your infrastructure doesn't have to. The cost analysis should hinge on whether that absorption is cheaper than handling the load yourself, even if it's "just bots."
Can you segment the attack events by vector? A pattern where Layer 7 attacks still cluster at 2 PM UTC is more telling than if it's 95% UDP reflection.
show me the SLA