Customer Story

Flash sale "swarmed by mixed attack"
how to hold revenue with zero blackhole and zero surcharge

An e-commerce platform was hit by a simultaneous volumetric and application-layer mixed DDoS during the peak of a flash sale, and its ordering system nearly collapsed. Thanks to AwayDDoS protected nodes and elastic scrubbing bandwidth, it ran on fixed pricing through the attack — no blackhole, no surge charges — keeping security cost fully controllable and ending with a record sale day (client name withheld, figures illustrative).

Customer Background

The client is a fast-growing e-commerce platform. Flash sales and promotions are the dual peaks of annual traffic: instantaneous floods of orders, purchases and payments are the lifeline of revenue. E-commerce is extremely sensitive to order success rate and page availability — any lag or failed checkout turns directly into lost orders and bad word of mouth. The hype of a big promo also makes it a prime target for attackers' extortion and abuse.

Its architecture is a typical e-commerce shape: users reach order, catalog and payment services via CDN / load balancing, backed by microservices + databases. Without enough protective bandwidth reserved before a promo, a volumetric + application-layer mixed attack can instantly saturate the origin at the peak and bring the ordering system to the brink of collapse.

①① Zero blackhole throughoutProtected nodes held the ingress during the attack; the platform was never blackholed by the carrier, business uninterrupted.
②② Zero attack surchargeElastic scrubbing bandwidth auto-scales on fixed pricing; zero surprise security cost during the attack.
③③ Record sale revenueReal buyers checked out smoothly; the promo closed successfully with record revenue.

The double hit of flash sale: volumetric + application-layer mixed attack

① Volumetric flood saturates bandwidth, ordering system near collapse

During the flash-sale climax the attacker launched a volumetric DDoS, instantly filling the platform's ingress bandwidth with massive traffic, causing pages that won't open, order timeouts and stuck payments. The goal is simple and brutal — if real users can't get in, the whole promo is wasted.

② Application-layer attack slips in, draining resources precisely

Harder to defend is the overlaid application-layer attack: malicious requests mimic real purchase behavior, slowly and in volume draining the connections and compute of order and payment interfaces. While the origin is busy serving these "human-looking" requests, real buyers get squeezed out and can't check out. Attackers also strike at the final volume-surge moment of the promo to maximize damage.

The risk of a big promo is not "will it be attacked," but "can the business finish the sale without blackholing or surcharging when attacked." One failed promo costs not just that day's revenue but the brand's trust.

AwayDDoS Solution

We enabled AwayDDoS protected nodes + elastic scrubbing bandwidth: attack traffic is absorbed and scrubbed at the protected-node edge, the massive volumetric flood diluted at the edge, and application-layer malicious requests precisely identified and blocked at the scrubbing center, with clean traffic re-injected to the origin. The whole process needs zero origin rework — the e-commerce backend is untouched.

Most important is fixed pricing with no surge charges during attacks: AwayDDoS's elastic scrubbing bandwidth auto-scales during the attack, so the platform is never blackholed by the carrier and is never extra-billed for the attack — security cost stays fully predictable and controllable. Security experts monitor and tune 7×24, ensuring every wave of the promo is steadily caught.

  1. Pre-stage protected nodes — before the promo, onboard the platform ingress to AwayDDoS protected nodes, reserve elastic scrubbing bandwidth so the flash sale starts already protected.
  2. Edge flood absorption + center precision — volumetric floods are diluted and absorbed at edge nodes; application-layer malicious requests are precisely blocked at the center via signature and behavioral analysis.
  3. Fixed pricing, no surcharge — elastic bandwidth auto-scales during the attack; no blackhole, no attack surcharge, security cost fully controlled throughout.

How it works: a millisecond protection loop

Built on real-time Smart DNS probing and globally distributed scrubbing nodes, the system completes anomaly detection, traffic switching and clean re-injection in milliseconds, forming an automated protection loop that keeps the business interruption-free.

1. Smart detection & DNS switch

Continuously probes origin health; on anomaly it seamlessly switches the domain from the primary CNAME to the AwayDDoS backup node, blocking attacks from reaching the origin — no manual intervention.

2. Global node scrubbing

Traffic is pulled into distributed scrubbing clusters; using signature detection and behavioral analysis, it precisely filters DDoS, CC and other attacks while preserving legitimate requests and avoiding harm to real users.

3. Safe re-injection

Cleaned traffic is re-injected to the origin (WAF / SLB) via cloud interconnect or public IP; users notice nothing and business processing is unaffected.

Core advantages

Proactive defense, smart switching

Smart DNS health probing delivers second-level fault sensing and automatic traffic shifting, keeping access interruption-free and coping with node failures and traffic spikes without manual switchovers.

Controllable cost, elastic defense

No more "billing by peak." A fixed protection package allows a certain number of overage events, with advance confirmation before any extra — drastically lowering total TCO.

Seamless integration, no rework

Fully compatible with the existing cloud stack — no change to deployment logic. Onboard with a simple CNAME configuration; non-intrusive, zero impact on live business.

Global coverage, local scrubbing

Globally distributed high-defense nodes scrub attack traffic at the network edge, avoiding backhaul congestion; local scrubbing sharply reduces re-injection latency.

Technical specs & scenarios

Traffic diversion

MethodDescriptionBest for
DNS CNAME diversionSmoothly steer traffic to the scrubbing center by changing DNS records; simple, non-intrusive, fast to switch and roll back.Websites, video, API services
BGP route diversionFor bare-IP services, dynamically announce target IP blocks via BGP for transparent牵引 (pull), supporting very large bandwidth in real time.Hosting providers, financial trading
Anycast IP diversionGlobal anycast IP; user traffic auto-connects to the nearest scrubbing node by topology, millisecond-level pull and scrub.Global acceleration, cross-border SaaS

Traffic re-injection

MethodDescriptionBest for
Static IP fixed re-injectionFixed-IP re-injection for legacy systems, returning cleaned traffic via a preset static public IP.Fixed-IP origins, closed networks
Cloud interconnect / VPN tunnelA dedicated channel returns compliant cleaned traffic to the origin — secure, stable, low-latency.Private cloud, cross-region networks

Comparison: AwayDDoS vs native cloud high-defense

DimensionAwayDDoSNative cloud high-defense (client's prior setup)
ScrubbingTwo-layer, >99.9%: Layer 1 dilutes 90% volumetric at the edge; Layer 2 precisely scrubs CC / app-layer attacks.Single layer, ~90%; limited app-layer scrubbing, users still feel pressure.
BlackholeNever blackholes, no matter the attack size; origin stays online; regional isolation keeps the business interruption-free.Protects only within quota; over the quota it blackholes the IP, taking the whole network down until you pay to lift it.
Expert serviceSecurity experts deliver personalized analysis and dynamically tune policies.Standardized self-service; rarely deep per-customer analysis.
Cost modelFixed package with included overage; advance confirmation before any extra — never a surprise attack surcharge.Billed by attack peak and duration; attacks trigger demands to pay for upgrades, or you get blackholed.
Global networkIntegrates Tier-1 carriers (CTG, CMI, NTT) for strong volumetric scrubbing.Mostly in-house clusters; prone to rate-limiting under multi-point global attacks.

Protection Results

After onboarding AwayDDoS, the flash sale shifted from "near collapse" to "stable throughout with controllable cost." Key metrics (illustrative):

0blackhole penalty
0attack surcharge
Recordsale revenue
7×24expert watch
  • Zero blackhole throughout — protected nodes held the ingress during the attack; the platform was never blackholed, ordering system online the whole time.
  • Zero attack surcharge — elastic scrubbing bandwidth auto-scales on fixed pricing, making security cost fully predictable, never held hostage by the attack.
  • Record sale revenue — real buyers completed orders and payments smoothly; the promo closed successfully with revenue at a new high.

Return on Investment (ROI)

For e-commerce, the value of promo protection is not "how many G blocked," but defending revenue and brand trust while locking security cost. Illustrative estimate:

ItemBeforeAfter (AwayDDoS)
Business availabilityMixed attack at promo, ordering near collapse, revenue zeroedProtected nodes hold; zero blackhole, orders flow
Security costRetroactive scaling surcharged, cost out of controlFixed pricing, zero surcharge during attack
Revenue & reputationFailed orders cause churn and bad reviewsReal buyers flow, revenue hits record high
Ops burdenPromo firefighting, stretched staff7×24 expert watch, attacks neutralized on the spot

Conservatively: a promo collapse from attack — lost orders plus brand damage — far exceeds a full year of protection spend; AwayDDoS's fixed pricing + zero blackhole + zero surcharge lets the platform both withstand the attack and lock security cost in a predictable range. Just "saving one promo's revenue" already yields an excellent return.

The real payoff: operations can finally tell the boss, "Under a mixed-attack swarm at the promo, we were neither blackholed nor surcharged — and revenue hit a record."