Here is a question we could not answer well a year ago: what really happens with why attackers love login endpoints? We can answer it now.
What we changed
We moved the decision from a single threshold to a continuous score, added an explanation to every decision and made every rule testable against historical traffic before it goes live.
The result is fewer late-night pages for our analysts and — more importantly — fewer real users challenged by mistake.
The numbers
Across the last quarter, 71% of challenged clients never attempted a solution, 24% solved one challenge and then behaved normally, and 5% solved challenges repeatedly while continuing to attack — the last group is where analysts spend their time.
Median added latency for legitimate visitors that were challenged was 280 ms on desktop and 410 ms on mid-range Android devices.
Compliance is a side effect
Regulators increasingly ask for evidence of resilience, not just promises. An incident timeline with start, peak, vectors and impact is exactly the evidence DORA and NIS2 ask for — and it falls out of good observability for free.
We export incident reports in formats auditors can file without anyone rewriting them.
Latency budget
Our budget for the whole filtering pipeline is one millisecond at the 99th percentile. Anything that cannot be decided within that budget runs asynchronously and influences the next request from the same client, not the current one.
That constraint shapes everything: data structures, where state lives and which signals we are willing to compute inline.
The economics behind it
A booter service rents out a 100 Gbps attack for less than the price of a pizza. Defending against it with bandwidth alone is a race you lose. Defending against it by making each malicious request cost more than it earns is a race you win.
This is the entire idea behind never metering attack traffic: our costs scale with filtering, not with your invoice.
The full incident data behind this post is available to customers in the dashboard under Reports.
Thanks — sharing this with our on-call team.
Thanks — sharing this with our on-call team.
Thanks — sharing this with our on-call team.
Machine-readable ranges are at /ips.json and via the API.
Thanks — sharing this with our on-call team.
Our auditors asked for exactly this kind of incident evidence under DORA.
Carpet bombing is nasty. Good to see a clear explanation of it.
Verified good bots and allow-listed partners bypass challenges entirely.
Carpet bombing is nasty. Good to see a clear explanation of it.