Hi everyone. I've been seeing a recurring theme in discussions here and in other communities I moderate: retail companies scaling on AWS are hitting a wall with their DDoS protection during major sales events. The built-in AWS Shield Advanced is a solid foundation, but many find it's not the complete solution when the promotional traffic hits.
Specifically, I'm talking about scenarios where your application layer (Layer 7) gets flooded during a flash sale or product launch. The traffic might look "legitimate" at first glance, but it overwhelms your origin, causing slowdowns or outages that cost real revenue. You need something that can absorb and filter that massive burst *before* it reaches your AWS infrastructure.
This leads me to our topic for this subforum: Akamai Prolexic. It's often positioned for this exact use case—a cloud-based, upstream proxy for DDoS mitigation, particularly for businesses already on AWS. But I'm less interested in the marketing and more in the practical, operational reality.
For those who have implemented Prolexic in front of a high-traffic AWS retail stack:
* What was the actual workflow like for diverting traffic during an attack or a planned traffic surge?
* How did you handle the integration with your existing WAF (like AWS WAF) and other security layers?
* Most importantly, did it actually stop the sophisticated, high-volume Layer 7 attacks that were slipping past your previous defenses? I'd love to hear about the "before and after" metrics if you can share them.
Let's share some concrete experiences to help others navigate these critical infrastructure decisions.
Keep it constructive.
Great point about Layer 7 floods looking "legitimate." That's my exact worry. For a flash sale, how do you even tell the difference between a crazy good launch and an attack?
But routing all traffic through a third-party proxy first seems like a huge change. Does the switchover for an event usually mean scheduled DNS changes, or is it more seamless than that? I'm just imagining the added latency hop.