From the security blog
DDoS protection — fundamentals
A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable.
Web Application Firewall — fundamentals
What matters is not the packet rate but how expensive a single request is for the origin.
Bot management — fundamentals
Filtering only at the origin means you have already paid for the capacity you meant to protect.
API security — fundamentals
A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety.
Zero Trust — fundamentals
Before any rule change, it should be clear what share of real traffic would be affected.
Attack detection — fundamentals
The threshold that was right yesterday is wrong again after a marketing campaign goes out.
Network resilience — fundamentals
When in doubt: observe before blocking — a false positive costs more than a scan that got through.
TLS and certificates — fundamentals
A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable.
DDoS protection — in practice
What matters is not the packet rate but how expensive a single request is for the origin.
Web Application Firewall — in practice
Filtering only at the origin means you have already paid for the capacity you meant to protect.
Bot management — in practice
A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety.
API security — in practice
Before any rule change, it should be clear what share of real traffic would be affected.
Zero Trust — in practice
The threshold that was right yesterday is wrong again after a marketing campaign goes out.
Attack detection — in practice
When in doubt: observe before blocking — a false positive costs more than a scan that got through.
Network resilience — in practice
A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable.
TLS and certificates — in practice
What matters is not the packet rate but how expensive a single request is for the origin.
DDoS protection — avoiding mistakes
Filtering only at the origin means you have already paid for the capacity you meant to protect.
Web Application Firewall — avoiding mistakes
A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety.
Bot management — avoiding mistakes
Before any rule change, it should be clear what share of real traffic would be affected.
API security — avoiding mistakes
The threshold that was right yesterday is wrong again after a marketing campaign goes out.
Zero Trust — avoiding mistakes
When in doubt: observe before blocking — a false positive costs more than a scan that got through.
Attack detection — avoiding mistakes
A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable.
Network resilience — avoiding mistakes
What matters is not the packet rate but how expensive a single request is for the origin.
TLS and certificates — avoiding mistakes
Filtering only at the origin means you have already paid for the capacity you meant to protect.