B2B API "exhausted by botnet abuse"
how tunnel protection shielded the whole net without changing infrastructure
A SaaS company's core B2B API was heavily abused by a botnet — malicious requests filled the servers' resources and legitimate enterprise customers' calls kept failing. Thanks to AwayDDoS GRE / BGP tunnel protection shielding the whole network, with L7 cleaning precisely identifying and blocking abusive traffic and zero change to existing infrastructure, abnormal traffic dropped 97% and legitimate customers stayed 100% reachable (client name withheld, figures illustrative).
Customer Background
The client is a SaaS company exposing a B2B API to a large base of enterprise customers for system integration and data sync. The API is the lifeblood of their business — any call failure or latency directly affects customers' production systems, turning into complaints, SLA breaches and renewal risk. And an open B2B API is, by nature, a popular target for botnet abuse and scraping.
Its architecture relies on fixed IP / dedicated lines to serve enterprise customers, backed by an API gateway + microservices. When a botnet keeps sending abusive requests through compromised hosts, the whole network's connections and compute are rapidly exhausted. Patching at the application layer alone treats the symptom, not the cause, and customers are unwilling to heavily re-architect their existing infrastructure just for protection.
The invisible drain of B2B APIs: botnet abuse exhausting the whole net
① Botnet keeps abusing, resources exhausted
The attacker controlled a large number of zombie hosts to launch sustained, distributed abusive requests at the B2B API — not aiming to burst it instantly, but to occupy connections and compute over a long period at scale. As resources are eaten up, legitimate enterprise customers' calls time out and fail, directly blocking business.
② Legitimate customers squeezed out, SLA and renewal threatened
Once resources are occupied by malicious traffic, real enterprise customers' legitimate calls are squeezed out, time out or fail. For a SaaS, that means customers' production systems are affected — directly triggering SLA breaches, complaints and potential churn. Worse, customers usually refuse to modify existing network architecture for protection, making traditional protection hard to deploy.
The risk of a B2B API is that abuse looks like normal calls — when the botnet's requests resemble real customers, protection must block them without touching the customers' existing infrastructure.
AwayDDoS Solution
We deployed AwayDDoS GRE / BGP tunnel protection: routing the whole network's traffic to the scrubbing center via GRE or BGP tunnel, without changing the customer's existing IP and network architecture, protecting the entire network. At the center, L7 cleaning performs deep inspection and behavioral analysis on API requests, precisely identifying and blocking botnet abusive traffic.
The key is whole-network tunnel protection + L7 precise identification: tunnel mode makes protection transparent to the customer, with zero rework on backend infrastructure; L7 cleaning, based on the API's behavioral baseline and fingerprints, precisely splits abusive from legitimate traffic. Security experts monitor and tune 7×24, ensuring legitimate customers stay 100% reachable and abusive traffic is efficiently blocked.
- Tunnel the whole net — route the entire network's traffic into the AwayDDoS scrubbing center via GRE / BGP tunnel; the customer's existing IP and architecture stay completely unchanged.
- L7 cleaning identifies abuse — at the center, deep inspection and behavioral analysis precisely identify botnet abusive requests and block them at the edge.
- Legitimate customers reachable with zero rework — cleaned legitimate traffic is re-injected on the original path; enterprise customers stay 100% reachable, infrastructure untouched.
How it works: a millisecond protection loop
Built on real-time Smart DNS probing and globally distributed scrubbing nodes, the system completes anomaly detection, traffic switching and clean re-injection in milliseconds, forming an automated protection loop that keeps the business interruption-free.
1. Smart detection & DNS switch
Continuously probes origin health; on anomaly it seamlessly switches the domain from the primary CNAME to the AwayDDoS backup node, blocking attacks from reaching the origin — no manual intervention.
2. Global node scrubbing
Traffic is pulled into distributed scrubbing clusters; using signature detection and behavioral analysis, it precisely filters DDoS, CC and other attacks while preserving legitimate requests and avoiding harm to real users.
3. Safe re-injection
Cleaned traffic is re-injected to the origin (WAF / SLB) via cloud interconnect or public IP; users notice nothing and business processing is unaffected.
Core advantages
Proactive defense, smart switching
Smart DNS health probing delivers second-level fault sensing and automatic traffic shifting, keeping access interruption-free and coping with node failures and traffic spikes without manual switchovers.
Controllable cost, elastic defense
No more "billing by peak." A fixed protection package allows a certain number of overage events, with advance confirmation before any extra — drastically lowering total TCO.
Seamless integration, no rework
Fully compatible with the existing cloud stack — no change to deployment logic. Onboard with a simple CNAME configuration; non-intrusive, zero impact on live business.
Global coverage, local scrubbing
Globally distributed high-defense nodes scrub attack traffic at the network edge, avoiding backhaul congestion; local scrubbing sharply reduces re-injection latency.
Technical specs & scenarios
Traffic diversion
| Method | Description | Best for |
|---|---|---|
| DNS CNAME diversion | Smoothly steer traffic to the scrubbing center by changing DNS records; simple, non-intrusive, fast to switch and roll back. | Websites, video, API services |
| BGP route diversion | For bare-IP services, dynamically announce target IP blocks via BGP for transparent牵引 (pull), supporting very large bandwidth in real time. | Hosting providers, financial trading |
| Anycast IP diversion | Global anycast IP; user traffic auto-connects to the nearest scrubbing node by topology, millisecond-level pull and scrub. | Global acceleration, cross-border SaaS |
Traffic re-injection
| Method | Description | Best for |
|---|---|---|
| Static IP fixed re-injection | Fixed-IP re-injection for legacy systems, returning cleaned traffic via a preset static public IP. | Fixed-IP origins, closed networks |
| Cloud interconnect / VPN tunnel | A dedicated channel returns compliant cleaned traffic to the origin — secure, stable, low-latency. | Private cloud, cross-region networks |
Comparison: AwayDDoS vs native cloud high-defense
| Dimension | AwayDDoS | Native cloud high-defense (client's prior setup) |
|---|---|---|
| Scrubbing | Two-layer, >99.9%: Layer 1 dilutes 90% volumetric at the edge; Layer 2 precisely scrubs CC / app-layer attacks. | Single layer, ~90%; limited app-layer scrubbing, users still feel pressure. |
| Blackhole | Never blackholes, no matter the attack size; origin stays online; regional isolation keeps the business interruption-free. | Protects only within quota; over the quota it blackholes the IP, taking the whole network down until you pay to lift it. |
| Expert service | Security experts deliver personalized analysis and dynamically tune policies. | Standardized self-service; rarely deep per-customer analysis. |
| Cost model | Fixed package with included overage; advance confirmation before any extra — never a surprise attack surcharge. | Billed by attack peak and duration; attacks trigger demands to pay for upgrades, or you get blackholed. |
| Global network | Integrates Tier-1 carriers (CTG, CMI, NTT) for strong volumetric scrubbing. | Mostly in-house clusters; prone to rate-limiting under multi-point global attacks. |
Protection Results
After deploying AwayDDoS tunnel protection, the B2B API shifted from "exhausted by abuse" to "precise good/bad splitting." Key metrics (illustrative):
- 97% abnormal traffic cut — botnet abusive requests precisely identified and blocked at the edge by L7 cleaning; whole-network resources no longer saturated.
- 100% legitimate customers reachable — legitimate enterprise calls flow without error; SLA and customer trust steadily held.
- Whole-network tunnel protection, zero rework — GRE / BGP tunnel shields the entire network; the customer's existing infrastructure is completely untouched.
Return on Investment (ROI)
For SaaS / API businesses, the value of protection is not "how many G blocked," but defending customer SLA and renewals while not touching existing architecture. Illustrative estimate:
| Item | Before | After (AwayDDoS) |
|---|---|---|
| API availability | Botnet abuse exhausts resources, legit calls fail | Good/bad split, legit customers 100% reachable |
| Infra cost | Traditional protection needs big re-architecting | GRE/BGP tunnel, zero-rework onboarding |
| SLA & renewal | Call failures trigger breach and churn | Legitimate reachable, SLA and trust defended |
| Ops burden | Reactive firefighting, manual IP blocking | 7×24 expert monitoring, abuse blocked on the spot |
Conservatively: a single SLA breach and customer churn caused by API abuse costs far more than a full year of protection spend; AwayDDoS's whole-network tunnel protection + L7 precise cleaning lets the SaaS block botnet abuse without re-architecting. Just "saving one major customer renewal" already yields an excellent return.
The real payoff: operations can finally tell the boss, "Our B2B API was abused by a botnet — we shielded the whole net without touching the customers' infrastructure."