Open API crippled by "slow attacks"
how to precisely separate real users from malicious traffic
A licensed financial exchange exposed its quote and order APIs directly to a large base of clients and third parties. Instead of flooding bandwidth, attackers used many low-rate, human-looking malicious requests to exhaust interface resources - causing timeouts and blocking real users from trading. Here is how it used AwayDDoS to block 99.9% of malicious requests while keeping real trades flowing (client name withheld, figures illustrative).
Customer Background
The client is a licensed financial exchange. Its core quote and order APIs are open to the public, serving a large base of individual investors, institutions and third-party integrations. APIs are the lifeblood of the business - any latency or timeout turns directly into failed orders, missed quotes, complaints and regulatory risk. And an open API is, by nature, the attacker's favorite entry point.
Its architecture follows a typical API-gateway shape: clients reach backend trading and quote services via an API gateway / WAF, backed by microservices + databases. Attackers need not saturate bandwidth; they only need to let malicious requests consume interface and connection resources "slowly" and "plentifully" - exactly why CC attacks and slow attacks are the hardest to defend.
The invisible killer of open APIs: CC and slow attacks
① Winning not by volume, but by "draining resources"
Unlike volumetric DDoS, CC and slow attacks do not aim to fill bandwidth. They use many low-rate, human-looking malicious requests to continuously drain the API's connections, threads and backend resources. Each request looks "like a person," so traditional firewalls and bandwidth protection struggle to tell apart - eventually the interface is crippled and times out.
② Real users "squeezed out", business directly hit
Once interface resources are filled by malicious traffic, real users' order and query requests are squeezed out, time out or fail. For an exchange this means customers cannot place orders or see quotes - directly turning into complaints, churn and potential compliance issues. Worse, attackers combine slow attacks (Slowloris-like), holding connections extremely slowly to stay under the radar.
The risk of an open API is not "how much traffic," but "they all look human" - when malicious requests look like real users, traditional protection either false-blocks or lets through, stuck both ways.
AwayDDoS Solution
We enabled AwayDDoS application-layer deep cleaning: at the scrubbing center, API traffic undergoes signature detection + behavioral analysis combined with customer-specific rules to precisely separate real users from malicious / slow requests. Malicious traffic is blocked at the edge; legitimate traffic returns via smart routing on the optimal path, keeping trading uninterrupted.
The key is customer-specific rules + expert tuning: together with the client we mapped the API's legitimate behavior baseline and set dedicated rules against CC and slow attacks; during attacks, security experts monitor 7×24 and adjust dynamically, ensuring zero false-blocks of real trades and high-precision blocking of malicious requests.
- Route traffic to the scrubbing center - via DNS / reverse proxy, API traffic is brought into the AwayDDoS center where application-layer deep cleaning analyzes requests by signature and behavior.
- Custom rules separate good from bad - combined with the client's API behavior baseline and dedicated rules, precisely identify CC and slow malicious requests without false-blocking real users.
- Smart routing back to origin - cleaned legitimate traffic returns via smart routing on the optimal path; API latency drops instead of rising.
How it works: a millisecond protection loop
Built on real-time Smart DNS probing and globally distributed scrubbing nodes, the system completes anomaly detection, traffic switching and clean re-injection in milliseconds, forming an automated protection loop that keeps the business interruption-free.
1. Smart detection & DNS switch
Continuously probes origin health; on anomaly it seamlessly switches the domain from the primary CNAME to the AwayDDoS backup node, blocking attacks from reaching the origin — no manual intervention.
2. Global node scrubbing
Traffic is pulled into distributed scrubbing clusters; using signature detection and behavioral analysis, it precisely filters DDoS, CC and other attacks while preserving legitimate requests and avoiding harm to real users.
3. Safe re-injection
Cleaned traffic is re-injected to the origin (WAF / SLB) via cloud interconnect or public IP; users notice nothing and business processing is unaffected.
Core advantages
Proactive defense, smart switching
Smart DNS health probing delivers second-level fault sensing and automatic traffic shifting, keeping access interruption-free and coping with node failures and traffic spikes without manual switchovers.
Controllable cost, elastic defense
No more "billing by peak." A fixed protection package allows a certain number of overage events, with advance confirmation before any extra — drastically lowering total TCO.
Seamless integration, no rework
Fully compatible with the existing cloud stack — no change to deployment logic. Onboard with a simple CNAME configuration; non-intrusive, zero impact on live business.
Global coverage, local scrubbing
Globally distributed high-defense nodes scrub attack traffic at the network edge, avoiding backhaul congestion; local scrubbing sharply reduces re-injection latency.
Technical specs & scenarios
Traffic diversion
| Method | Description | Best for |
|---|---|---|
| DNS CNAME diversion | Smoothly steer traffic to the scrubbing center by changing DNS records; simple, non-intrusive, fast to switch and roll back. | Websites, video, API services |
| BGP route diversion | For bare-IP services, dynamically announce target IP blocks via BGP for transparent牵引 (pull), supporting very large bandwidth in real time. | Hosting providers, financial trading |
| Anycast IP diversion | Global anycast IP; user traffic auto-connects to the nearest scrubbing node by topology, millisecond-level pull and scrub. | Global acceleration, cross-border SaaS |
Traffic re-injection
| Method | Description | Best for |
|---|---|---|
| Static IP fixed re-injection | Fixed-IP re-injection for legacy systems, returning cleaned traffic via a preset static public IP. | Fixed-IP origins, closed networks |
| Cloud interconnect / VPN tunnel | A dedicated channel returns compliant cleaned traffic to the origin — secure, stable, low-latency. | Private cloud, cross-region networks |
Comparison: AwayDDoS vs native cloud high-defense
| Dimension | AwayDDoS | Native cloud high-defense (client's prior setup) |
|---|---|---|
| Scrubbing | Two-layer, >99.9%: Layer 1 dilutes 90% volumetric at the edge; Layer 2 precisely scrubs CC / app-layer attacks. | Single layer, ~90%; limited app-layer scrubbing, users still feel pressure. |
| Blackhole | Never blackholes, no matter the attack size; origin stays online; regional isolation keeps the business interruption-free. | Protects only within quota; over the quota it blackholes the IP, taking the whole network down until you pay to lift it. |
| Expert service | Security experts deliver personalized analysis and dynamically tune policies. | Standardized self-service; rarely deep per-customer analysis. |
| Cost model | Fixed package with included overage; advance confirmation before any extra — never a surprise attack surcharge. | Billed by attack peak and duration; attacks trigger demands to pay for upgrades, or you get blackholed. |
| Global network | Integrates Tier-1 carriers (CTG, CMI, NTT) for strong volumetric scrubbing. | Mostly in-house clusters; prone to rate-limiting under multi-point global attacks. |
Protection Results
After onboarding AwayDDoS, the open API shifted from "crippled by malicious requests" to "precise good/bad splitting." Key metrics (illustrative):
- 99.9% malicious request block rate - CC and slow attacks precisely identified and blocked at the edge; origin interface resources no longer saturated.
- API latency down 40% - normal traffic returns via smart routing on the optimal path, actually faster and steadier than before protection.
- Zero false-block of real users - custom rules keep legitimate order and query requests flowing; business undisturbed.
Return on Investment (ROI)
For a financial exchange, the value of API protection is not "how many G blocked," but defending trading availability and the compliance baseline. Illustrative estimate:
| Item | Before | After (AwayDDoS) |
|---|---|---|
| Interface availability | Malicious requests fill resources; real users time out, cannot trade | Good/bad split; real trades flow, no false-block |
| Security spend | Reactive bandwidth / protection scaling, costly and passive | App-layer cleaning + custom rules, precise and elastic |
| Compliance & reputation | Order failures spark complaints and regulatory risk | Trading uninterrupted, compliance and trust defended |
| Ops burden | Incident-driven, manual firefighting | 7×24 expert watch, attacks neutralized on the spot |
Conservatively: a single API outage's complaints, churn and potential compliance cost far exceed a full year of API protection spend; AwayDDoS's 99.9% precise block + zero false-block of real users lets the exchange block malicious traffic without harming real trades. Just "avoiding one order incident" already yields an excellent return.
The real payoff: operations can finally tell the boss: "When the attack came, our users placed orders and noticed nothing."