Customer Story

B2B API "exhausted by botnet abuse"
how tunnel protection shielded the whole net without changing infrastructure

A SaaS company's core B2B API was heavily abused by a botnet — malicious requests filled the servers' resources and legitimate enterprise customers' calls kept failing. Thanks to AwayDDoS GRE / BGP tunnel protection shielding the whole network, with L7 cleaning precisely identifying and blocking abusive traffic and zero change to existing infrastructure, abnormal traffic dropped 97% and legitimate customers stayed 100% reachable (client name withheld, figures illustrative).

Customer Background

The client is a SaaS company exposing a B2B API to a large base of enterprise customers for system integration and data sync. The API is the lifeblood of their business — any call failure or latency directly affects customers' production systems, turning into complaints, SLA breaches and renewal risk. And an open B2B API is, by nature, a popular target for botnet abuse and scraping.

Its architecture relies on fixed IP / dedicated lines to serve enterprise customers, backed by an API gateway + microservices. When a botnet keeps sending abusive requests through compromised hosts, the whole network's connections and compute are rapidly exhausted. Patching at the application layer alone treats the symptom, not the cause, and customers are unwilling to heavily re-architect their existing infrastructure just for protection.

①① 97% abnormal traffic cutBotnet abusive requests precisely identified and blocked by L7 cleaning; abnormal traffic dropped sharply.
②② 100% legitimate customers reachableLegitimate enterprise calls unaffected; SLA and renewal risk resolved together.
③③ Whole-network tunnel protectionGRE / BGP tunnel shields the entire network; existing infrastructure zero rework.

The invisible drain of B2B APIs: botnet abuse exhausting the whole net

① Botnet keeps abusing, resources exhausted

The attacker controlled a large number of zombie hosts to launch sustained, distributed abusive requests at the B2B API — not aiming to burst it instantly, but to occupy connections and compute over a long period at scale. As resources are eaten up, legitimate enterprise customers' calls time out and fail, directly blocking business.

② Legitimate customers squeezed out, SLA and renewal threatened

Once resources are occupied by malicious traffic, real enterprise customers' legitimate calls are squeezed out, time out or fail. For a SaaS, that means customers' production systems are affected — directly triggering SLA breaches, complaints and potential churn. Worse, customers usually refuse to modify existing network architecture for protection, making traditional protection hard to deploy.

The risk of a B2B API is that abuse looks like normal calls — when the botnet's requests resemble real customers, protection must block them without touching the customers' existing infrastructure.

AwayDDoS Solution

We deployed AwayDDoS GRE / BGP tunnel protection: routing the whole network's traffic to the scrubbing center via GRE or BGP tunnel, without changing the customer's existing IP and network architecture, protecting the entire network. At the center, L7 cleaning performs deep inspection and behavioral analysis on API requests, precisely identifying and blocking botnet abusive traffic.

The key is whole-network tunnel protection + L7 precise identification: tunnel mode makes protection transparent to the customer, with zero rework on backend infrastructure; L7 cleaning, based on the API's behavioral baseline and fingerprints, precisely splits abusive from legitimate traffic. Security experts monitor and tune 7×24, ensuring legitimate customers stay 100% reachable and abusive traffic is efficiently blocked.

  1. Tunnel the whole net — route the entire network's traffic into the AwayDDoS scrubbing center via GRE / BGP tunnel; the customer's existing IP and architecture stay completely unchanged.
  2. L7 cleaning identifies abuse — at the center, deep inspection and behavioral analysis precisely identify botnet abusive requests and block them at the edge.
  3. Legitimate customers reachable with zero rework — cleaned legitimate traffic is re-injected on the original path; enterprise customers stay 100% reachable, infrastructure untouched.

How it works: a millisecond protection loop

Built on real-time Smart DNS probing and globally distributed scrubbing nodes, the system completes anomaly detection, traffic switching and clean re-injection in milliseconds, forming an automated protection loop that keeps the business interruption-free.

1. Smart detection & DNS switch

Continuously probes origin health; on anomaly it seamlessly switches the domain from the primary CNAME to the AwayDDoS backup node, blocking attacks from reaching the origin — no manual intervention.

2. Global node scrubbing

Traffic is pulled into distributed scrubbing clusters; using signature detection and behavioral analysis, it precisely filters DDoS, CC and other attacks while preserving legitimate requests and avoiding harm to real users.

3. Safe re-injection

Cleaned traffic is re-injected to the origin (WAF / SLB) via cloud interconnect or public IP; users notice nothing and business processing is unaffected.

Core advantages

Proactive defense, smart switching

Smart DNS health probing delivers second-level fault sensing and automatic traffic shifting, keeping access interruption-free and coping with node failures and traffic spikes without manual switchovers.

Controllable cost, elastic defense

No more "billing by peak." A fixed protection package allows a certain number of overage events, with advance confirmation before any extra — drastically lowering total TCO.

Seamless integration, no rework

Fully compatible with the existing cloud stack — no change to deployment logic. Onboard with a simple CNAME configuration; non-intrusive, zero impact on live business.

Global coverage, local scrubbing

Globally distributed high-defense nodes scrub attack traffic at the network edge, avoiding backhaul congestion; local scrubbing sharply reduces re-injection latency.

Technical specs & scenarios

Traffic diversion

MethodDescriptionBest for
DNS CNAME diversionSmoothly steer traffic to the scrubbing center by changing DNS records; simple, non-intrusive, fast to switch and roll back.Websites, video, API services
BGP route diversionFor bare-IP services, dynamically announce target IP blocks via BGP for transparent牵引 (pull), supporting very large bandwidth in real time.Hosting providers, financial trading
Anycast IP diversionGlobal anycast IP; user traffic auto-connects to the nearest scrubbing node by topology, millisecond-level pull and scrub.Global acceleration, cross-border SaaS

Traffic re-injection

MethodDescriptionBest for
Static IP fixed re-injectionFixed-IP re-injection for legacy systems, returning cleaned traffic via a preset static public IP.Fixed-IP origins, closed networks
Cloud interconnect / VPN tunnelA dedicated channel returns compliant cleaned traffic to the origin — secure, stable, low-latency.Private cloud, cross-region networks

Comparison: AwayDDoS vs native cloud high-defense

DimensionAwayDDoSNative cloud high-defense (client's prior setup)
ScrubbingTwo-layer, >99.9%: Layer 1 dilutes 90% volumetric at the edge; Layer 2 precisely scrubs CC / app-layer attacks.Single layer, ~90%; limited app-layer scrubbing, users still feel pressure.
BlackholeNever blackholes, no matter the attack size; origin stays online; regional isolation keeps the business interruption-free.Protects only within quota; over the quota it blackholes the IP, taking the whole network down until you pay to lift it.
Expert serviceSecurity experts deliver personalized analysis and dynamically tune policies.Standardized self-service; rarely deep per-customer analysis.
Cost modelFixed package with included overage; advance confirmation before any extra — never a surprise attack surcharge.Billed by attack peak and duration; attacks trigger demands to pay for upgrades, or you get blackholed.
Global networkIntegrates Tier-1 carriers (CTG, CMI, NTT) for strong volumetric scrubbing.Mostly in-house clusters; prone to rate-limiting under multi-point global attacks.

Protection Results

After deploying AwayDDoS tunnel protection, the B2B API shifted from "exhausted by abuse" to "precise good/bad splitting." Key metrics (illustrative):

97%abnormal traffic cut
100%legit reachability
Whole nettunnel protection
0infra rework
  • 97% abnormal traffic cut — botnet abusive requests precisely identified and blocked at the edge by L7 cleaning; whole-network resources no longer saturated.
  • 100% legitimate customers reachable — legitimate enterprise calls flow without error; SLA and customer trust steadily held.
  • Whole-network tunnel protection, zero rework — GRE / BGP tunnel shields the entire network; the customer's existing infrastructure is completely untouched.

Return on Investment (ROI)

For SaaS / API businesses, the value of protection is not "how many G blocked," but defending customer SLA and renewals while not touching existing architecture. Illustrative estimate:

ItemBeforeAfter (AwayDDoS)
API availabilityBotnet abuse exhausts resources, legit calls failGood/bad split, legit customers 100% reachable
Infra costTraditional protection needs big re-architectingGRE/BGP tunnel, zero-rework onboarding
SLA & renewalCall failures trigger breach and churnLegitimate reachable, SLA and trust defended
Ops burdenReactive firefighting, manual IP blocking7×24 expert monitoring, abuse blocked on the spot

Conservatively: a single SLA breach and customer churn caused by API abuse costs far more than a full year of protection spend; AwayDDoS's whole-network tunnel protection + L7 precise cleaning lets the SaaS block botnet abuse without re-architecting. Just "saving one major customer renewal" already yields an excellent return.

The real payoff: operations can finally tell the boss, "Our B2B API was abused by a botnet — we shielded the whole net without touching the customers' infrastructure."