DDoS Protection & Rate Limiting Abuse Cases
DEV Community

DDoS Protection & Rate Limiting Abuse Cases

A DDoS (Distributed Denial of Service) attack overwhelms your system with fake traffic until real users can't get through. Defense is layered - no single solution works alone.

Types of Attacks

Type How Target
Volumetric Flood bandwidth (Gbps UDP) Network layer
Protocol Exhaust TCP connections (SYN flood) Transport layer
Application (L7) HTTP flood, slowloris Your app
Credential stuffing Try billions of stolen passwords Auth endpoints
Scraping Extract all your data Business logic
Account enumeration Guess valid emails User existence

Defense in Depth (Layers)

Internet
โ”‚
โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  CDN / DDoS Scrubbing Center    โ”‚ โ† Cloudflare, AWS Shield
โ”‚  Filters volumetric attacks     โ”‚   Absorbs Tbps-scale traffic
โ”‚  IP reputation, anycast routing โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                   โ”‚ (clean traffic only)
                   โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  WAF (Web Application Firewall) โ”‚ โ† Cloudflare WAF, AWS WAF
โ”‚  Blocks SQLi, XSS, bad patterns โ”‚   Rate limits by IP/user-agent
โ”‚  OWASP Top 10 rules             โ”‚   Bot fingerprinting
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                   โ”‚
                   โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  API Gateway / Load Balancer     โ”‚ โ† Rate limiting per API key
โ”‚  Request throttling             โ”‚   IP allowlist/blocklist
โ”‚  Auth enforcement               โ”‚   Quota per user tier
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                   โ”‚
                   โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Application Rate Limiting       โ”‚ โ† Redis-backed counters
โ”‚  Per-user, per-endpoint limits  โ”‚   Sliding window algorithm
โ”‚  CAPTCHA triggers               โ”‚   Business logic rules
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                   โ”‚
                   โ–ผ
              Your Services

Rate Limiting Abuse Cases

1. Credential Stuffing Defense

// Stricter limits on auth endpoints
rateLimiter({
  "/api/login": {
    max: 5,
    window: "15min",
    by: "ip"
  },
  "/api/forgot-password": {
    max: 3,
    window: "1hr",
    by: "ip"
  },
  "/api/register": {
    max: 10,
    window: "1hr",
    by: "ip"
  },
});
  • After 5 failures: require CAPTCHA
  • After 10 failures: temp block IP for 1 hour
  • Alert security team if 1000+ failures from IP range

2. API Abuse Tiers

  • Free tier: 100 req/day, 10 req/min
  • Pro tier: 10,000 req/day, 100 req/min
  • Enterprise: Unlimited, custom limits
// Headers to return (industry standard):
X-RateLimit-Limit: 100
X-RateLimit-Remaining: 42
X-RateLimit-Reset: 1699999999 (unix timestamp)
Retry-After: 60 (when limit hit, return 429)

3. Slow Loris Defense

Attacker sends HTTP headers very slowly to hold connections open.

# Nginx settings
client_body_timeout 10s;
client_header_timeout 10s;
keepalive_timeout 5s 5s;
send_timeout 10s;

Bot Detection Signals

Signal Legitimate User Bot
Request rate ~1-2 req/sec 100s req/sec
User-agent Chrome/Firefox Empty or spoofed
TLS fingerprint Real browser curl, Python requests
Behavioral pattern Random, varied Uniform, sequential
JavaScript execution Yes No (headless bots)
IP reputation Clean Known datacenter/VPN

Cloudflare Bot Management and reCAPTCHA v3 automate most of this.

AWS Shield Tiers

Tier Protection Cost
Shield Standard Automatic L3/L4 protection Free
Shield Advanced L7 protection, DDoS cost protection, 24/7 DRT $3,000/month

Most startups: Cloudflare Free or Pro tier is sufficient.

Pros

  • CDN/scrubbing centers absorb traffic before it reaches you
  • WAF handles OWASP Top 10 without code changes
  • Rate limiting protects business logic and database
  • Layered approach means no single point of failure

Cons

  • Cloudflare/Shield costs money at scale
  • Sophisticated L7 attacks (mimic real users) are hard to distinguish
  • Blocking legitimate users with aggressive rate limits hurts UX
  • Misconfigured WAF rules cause false positives

When to Use / When NOT to Use

Use when:

  • Any public-facing API or website (DDoS is a real threat)
  • Financial or health apps (credential stuffing target)
  • APIs with expensive backend operations (LLM calls, DB writes)
  • Any endpoint that is unauthenticated

Don't over-engineer when:

  • Internal-only API (behind VPN/private network)
  • Early prototype with 10 users - Cloudflare Free is enough
  • Traffic is already behind authentication (harder to abuse)
Read on DEV Community ↗ ← Back to News

Comments

No comments yet. Start the discussion.