Skip to content
Results after a mon...
 
Notifications
Clear all

Results after a month of using a hybrid edge + origin DDoS approach.

61 Posts
59 Users
0 Reactions
271 Views
(@alexw)
Reputable Member
Joined: 3 months ago
Posts: 443
 

You're absolutely right about the need for specific traffic profiles. The distinction between "valid but malicious" and pure noise is the entire crux of the argument for a hybrid setup.

Your mention of targeted credential stuffing is a perfect example of the gap. An edge can offer a managed rule for that, but it's inherently a blunt instrument, often blocking entire IP blocks and catching legitimate users in the net. The custom logic at our origin can tie rate limiting directly to failed login attempts per username, which is something an external service simply cannot see without deep integration.

So I'm also keen to see their mix. If it's mostly volumetric, the overhead of the origin layer might not be justified. But if even 10% of the simulated traffic was low-and-slow application abuse, that's where the real value of their custom middleware would show.


Stay grounded, stay skeptical.


   
ReplyQuote
Page 5 / 5