Skip to content
Unpopular opinion: ...
 
Notifications
Clear all

Unpopular opinion: Spending on DDoS protection is often fear-based, not risk-based.

1 Posts
1 Users
0 Reactions
24 Views
(@devops_grandad)
Reputable Member
Joined: 4 months ago
Posts: 354
Topic starter   [#11758]

I've seen more than a few budgets get approved for six-figure DDoS protection services after a single, slick vendor presentation that's heavy on FUD and light on actual data. Let's be real: for the majority of businesses, especially those not in gaming, fintech, or direct-to-consumer retail, the risk profile doesn't justify the "always-on, scrubbing center" model that gets pushed. You're paying for insurance against a threat that's statistically unlikely to be existential, while ignoring basic hardening that would stop 80% of problems.

Most of the volumetric attacks I've dealt with in the last decade were UDP reflection or simple SYN floods. These aren't sophisticated. They're brute force. And you can mitigate a surprising amount of that at the edge, for a fraction of the cost, by having a sensible architecture and using the tools you probably already pay for.

* **Your cloud provider's basic L3/L4 protections:** AWS Shield Standard, Google Cloud Armor, Azure DDoS Protection Basic. They're free, and they absorb all the common, network-layer junk traffic before it ever reaches your instances.
* **A properly configured CDN:** Serving your static assets (and even caching dynamic content) from a global CDN like Cloudflare, Fastly, or even CloudFront/Akamai immediately shrinks your attack surface. The origin is hidden, and their networks are built to soak up traffic.
* **Intelligent rate limiting at the application layer:** This is where you stop the "cheap" attacks that bypass volumetric protections. Nginx or your API gateway can do this.

```
# Example Nginx rate limiting for a login endpoint
limit_req_zone $binary_remote_addr zone=login:10m rate=5r/m;

location /api/login {
limit_req zone=login burst=10 nodelay;
proxy_pass http://backend;
}
```

The real failure mode isn't a 100 Gbps flood; it's a 2 Gbps attack on your under-provisioned, single-homed origin server because you put everything in one AWS region with no scaling groups. For the cost of a premium DDoS subscription for one year, you could build a multi-region failover system with auto-scaling that would make you resilient to both traffic attacks and regional outages.

I'm not saying DDoS protection is never needed. If you're in a high-risk vertical, or your revenue is directly tied to 100% uptime, then it's a cost of doing business. But for the internal line-of-business app, the corporate website, the SaaS product with a modest user base? You're likely buying peace of mind based on a vendor's fearmongering, not a realistic assessment of your threat model. Start with the fundamentals: architecture, basic cloud protections, and application-level controls. Monitor your traffic, know your baseline, and have a runbook for when things look weird. Then, and only then, consider if you need to escalate to a dedicated service.



   
Quote