How to hide your origin IP properly (part 3)
This post is about how to hide your origin IP properly. It started, as most of our posts do, with an incident that did not go the way we expected.Testing in production,…
This post is about how to hide your origin IP properly. It started, as most of our posts do, with an incident that did not go the way we expected.Testing in production,…
This post is about tuning challenge thresholds for mobile traffic behind CGNAT. It started, as most of our posts do, with an incident that did not go the way we expected.The economics…
tuning challenge thresholds for mobile traffic behind CGNAT sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.What actually happens during…
We get asked about reading a Deflecto incident report more than almost anything else, so here is the long answer.Testing in production, safelyEvery rule starts in log mode. We replay the previous…
This post is about rate limiting APIs without breaking legitimate integrations. It started, as most of our posts do, with an incident that did not go the way we expected.Latency budgetOur budget…
We get asked about what to put in your DDoS runbook more than almost anything else, so here is the long answer.What we changedWe moved the decision from a single threshold to…
Here is a question we could not answer well a year ago: what really happens with rate limiting APIs without breaking legitimate integrations? We can answer it now.Protecting the originNone of this…
Over the last few months we have spent a lot of time on load testing through Deflecto without triggering mitigation. This is what we learned.Measuring successWe track three numbers for every incident:…
This post is about writing your first custom WAF rule. It started, as most of our posts do, with an incident that did not go the way we expected.Latency budgetOur budget for…
Over the last few months we have spent a lot of time on choosing between DNS delegation and CNAME onboarding. This is what we learned.Measuring successWe track three numbers for every incident:…
Here is a question we could not answer well a year ago: what really happens with keeping search engine bots happy while blocking scrapers? We can answer it now.What actually happens during…
Over the last few months we have spent a lot of time on writing your first custom WAF rule. This is what we learned.Protecting the originNone of this matters if the attacker…