Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Keep critical paths available, separate abusive from legitimate demand, and avoid moving the bottleneck from the edge to the origin or a paid dependency.
Capture before evidence disappears
- Capture request rate, bandwidth, methods, paths, countries, ASNs, IPs, fingerprints, cache status, challenge outcomes, origin load, and start time.
- Separate network, protocol, application, login, search, API, and expensive-query traffic patterns.
- Record every rule, threshold, allowlist, block, challenge, cache, and origin change with before-and-after impact.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Block or challenge? | A signal is strong enough to measure false positives. | Block high-confidence abuse, challenge uncertain traffic, and preserve access for customers and providers. |
| Degrade features? | Expensive noncritical endpoints threaten core availability. | Disable or cache them, cap concurrency, and prioritize authentication, purchase, and status paths. |
Proof that recovery worked
- Origin saturation, error rate, and latency recover while legitimate conversion and login rates remain acceptable.
- Rules work at the edge and attackers cannot bypass them through alternate hostnames or direct origin access.
- Costs, logs, and third-party limits remain controlled through the attack window.
Controls to put in place
- Hide and firewall the origin so only approved edge networks can reach it.
- Set endpoint-specific rate, concurrency, cache, and cost controls before an attack.
- Maintain provider contacts, emergency rules, safe allowlists, and a static status channel.
Generate authorized load against a staging endpoint. Apply a targeted rule, preserve a legitimate cohort, degrade an expensive feature, and verify the origin stays below its limit.
Open the DDoS provider's emergency route when capacity or attack sophistication exceeds self-service controls; involve law enforcement only through qualified advice for credible extortion or threats.
What this means
The attack may target the network, HTTP endpoints, login, search, exports, or any operation that amplifies cost. Scaling alone can convert downtime into a large bill.
Warning signs
- Request volume or connections rise without matching customers or conversions.
- Traffic clusters around costly endpoints, networks, or fingerprints.
- Origin resources saturate while the CDN remains reachable.
- Cloud cost and latency increase together.
Recover now
First 15 minutes
- Confirm traffic shape and the exhausted resource.
- Put the service behind the configured DDoS/CDN protection layer.
- Rate-limit or challenge abusive paths and protect the origin address.
- Disable optional expensive features before scaling blindly.
Today
- Work with hosting and protection providers using timestamps and traffic samples.
- Add caching, queues, concurrency caps, and per-account limits.
- Rotate an exposed origin address or credential if attackers bypass the edge.
- Review cost exposure and set temporary spending controls.
Verify recovery
- Legitimate journeys work at expected latency.
- Origin traffic comes only through intended paths.
- Abusive traffic is blocked before scarce resources.
- Cost and resource use return to a sustainable range.
Prepare now
Access
- Protection controls can be changed by two authorized people.
Backups and evidence
- Traffic, firewall, origin, and cost logs are retained.
Contacts and ownership
- Hosting, CDN, and DNS emergency support routes are recorded.
Practice
- A load test has proved rate limits and degraded-mode behavior.
Common mistakes
- Autoscaling without a cost ceiling.
- Blocking entire countries without measuring customer impact.
- Leaving the origin directly reachable.