How a Business-Travel Platform Turned
Unpredictable Security Bills into a Predictable Cost
A global B2B travel-booking platform serving corporate clients runs high-concurrency flight and hotel search and checkout on a public cloud. Its security relied entirely on the cloud provider's native DDoS protection, and no CDN was deployed. In the past, any large attack meant the cloud provider would either force an expensive upgrade or blackhole the IP outright — taking the whole business offline within minutes and causing heavy loss. Here is how it used AwayDDoS to escape that dilemma (client name withheld, figures illustrative).
Client background
The platform mainly serves corporate travel clients, covering flights, hotels, train tickets and car rentals — a classic high-frequency search + real-time transaction website. Users search, compare and book at any moment, so even a few minutes of downtime turns directly into cancellations and complaints. Traffic peaks during weekday working hours and travel seasons, with a meaningful share coming from overseas.
The network follows a typical public-cloud shape: global users go directly through cloud SLB / WAF into multiple cloud-host origin servers, with no CDN deployed. Security relied entirely on the cloud provider's native DDoS protection. It works fine day to day, yet it exposed two fatal weaknesses the moment an attack hit — exactly why AwayDDoS was brought in.
Two hidden risks: the "hostage dilemma" of native cloud protection
① Blackhole threat: over the limit means offline, loss by the minute
The cloud provider's native high-defense is not unlimited — it is a subscription with a hard protection-bandwidth cap. Once attack traffic exceeds the purchased quota, the provider does not "absorb it for free" — it blackholes your IP, discarding all traffic to that IP at the network layer. To the outside world, the business goes unreachable across the entire network instantly: users can't open the site, orders can't be placed, APIs hang. For a travel platform that must take bookings around the clock, every minute of downtime is real refund and complaint loss.
② Cost extortion: attacked means forced to pay more, or get blackholed
Worse, the provider's "solution" is usually just one thing — when an attack hits, it demands the customer pay to upgrade the protection package / expand bandwidth. Don't pay, and the IP gets blackholed; pay, and the monthly bill spikes. The business is trapped in a passive loop: either absorb an uncontrollable bill spike, or absorb an all-network outage — kidnapped either way. Over time, security spend is completely unpredictable, and finance is forever guessing "how much will the next attack cost."
The real risk is not "attacks will come" — it is that, when attacked, the cloud provider either forces you to pay more or blackholes your IP. You can neither keep the business up nor control the cost.
AwayDDoS solution: smart DNS + two-layer scrubbing
We enabled AwayDDoS Smart DNS: it monitors each region in real time, and the moment a region is attacked, it automatically points that region's CNAME to the AwayDDoS scrubbing node, filters the traffic, then re-injects clean traffic back to the original WAF / SLB. The whole process is invisible to the origin — not a single line of business code on the existing cloud stack had to change.
Assume "Region A" is under attack. The flow is:
- Pre-configure the backup record — set the CNAME provided by AwayDDoS as the domain's backup resolution record in advance, enabling second-level switching on attack, with no reliance on manual emergency fixes.
- Automatic smart rerouting — Smart DNS detects the attack on Region A and automatically shifts that region's DNS weight to the AwayDDoS scrubbing node.
- Clean re-injection — malicious traffic is identified and filtered at the scrubbing node; the cleaned legitimate business traffic is re-injected to the original WAF / SLB via cloud interconnect / public IP, keeping the service available.
How it works: a millisecond protection loop
Built on real-time Smart DNS probing and globally distributed scrubbing nodes, the system completes anomaly detection, traffic switching and clean re-injection in milliseconds, forming an automated protection loop that keeps the business interruption-free.
1. Smart detection & DNS switch
Continuously probes origin health; on anomaly it seamlessly switches the domain from the primary CNAME to the AwayDDoS backup node, blocking attacks from reaching the origin — no manual intervention.
2. Global node scrubbing
Traffic is pulled into distributed scrubbing clusters; using signature detection and behavioral analysis, it precisely filters DDoS, CC and other attacks while preserving legitimate requests and avoiding harm to real users.
3. Safe re-injection
Cleaned traffic is re-injected to the origin (WAF / SLB) via cloud interconnect or public IP; users notice nothing and business processing is unaffected.
Core advantages
Proactive defense, smart switching
Smart DNS health probing delivers second-level fault sensing and automatic traffic shifting, keeping access interruption-free and coping with node failures and traffic spikes without manual switchovers.
Controllable cost, elastic defense
No more "billing by peak." A fixed protection package allows a certain number of overage events, with advance confirmation before any extra — drastically lowering total TCO.
Seamless integration, no rework
Fully compatible with the existing cloud stack — no change to deployment logic. Onboard with a simple CNAME configuration; non-intrusive, zero impact on live business.
Global coverage, local scrubbing
Globally distributed high-defense nodes scrub attack traffic at the network edge, avoiding backhaul congestion; local scrubbing sharply reduces re-injection latency.
Technical specs & scenarios
Traffic diversion
| Method | Description | Best for |
|---|---|---|
| DNS CNAME diversion | Smoothly steer traffic to the scrubbing center by changing DNS records; simple, non-intrusive, fast to switch and roll back. | Websites, video, API services |
| BGP route diversion | For bare-IP services, dynamically announce target IP blocks via BGP for transparent牵引 (pull), supporting very large bandwidth in real time. | Hosting providers, financial trading |
| Anycast IP diversion | Global anycast IP; user traffic auto-connects to the nearest scrubbing node by topology, millisecond-level pull and scrub. | Global acceleration, cross-border SaaS |
Traffic re-injection
| Method | Description | Best for |
|---|---|---|
| Static IP fixed re-injection | Fixed-IP re-injection for legacy systems, returning cleaned traffic via a preset static public IP. | Fixed-IP origins, closed networks |
| Cloud interconnect / VPN tunnel | A dedicated channel returns compliant cleaned traffic to the origin — secure, stable, low-latency. | Private cloud, cross-region networks |
Comparison: AwayDDoS vs native cloud high-defense
| Dimension | AwayDDoS | Native cloud high-defense (client's prior setup) |
|---|---|---|
| Scrubbing | Two-layer, >99.9%: Layer 1 dilutes 90% volumetric at the edge; Layer 2 precisely scrubs CC / app-layer attacks. | Single layer, ~90%; limited app-layer scrubbing, users still feel pressure. |
| Blackhole | Never blackholes, no matter the attack size; origin stays online; regional isolation keeps the business interruption-free. | Protects only within quota; over the quota it blackholes the IP, taking the whole network down until you pay to lift it. |
| Expert service | Security experts deliver personalized analysis and dynamically tune policies. | Standardized self-service; rarely deep per-customer analysis. |
| Cost model | Fixed package with included overage; advance confirmation before any extra — never a surprise attack surcharge. | Billed by attack peak and duration; attacks trigger demands to pay for upgrades, or you get blackholed. |
| Global network | Integrates Tier-1 carriers (CTG, CMI, NTT) for strong volumetric scrubbing. | Mostly in-house clusters; prone to rate-limiting under multi-point global attacks. |
Results
After onboarding AwayDDoS, defense shifted from "taking hits passively + bill shocks" to "proactive rerouting + predictable cost." Key metrics (illustrative):
- No more blackholing; regional isolation realized — when a region is attacked, its traffic auto-shifts to AwayDDoS scrubbing nodes, so the cloud provider can no longer blackhole your IP; other regions are unaffected, and the old "one attack takes everything down" is history.
- Zero origin rework — only one backup CNAME was added; the existing cloud-host / WAF / SLB stayed untouched. Go-live was non-intrusive to live traffic.
- Overseas UX unchanged or better — local scrubbing plus smart backhaul routing made "protected" actually faster and steadier than "unprotected."
Return on investment (ROI)
For businesses whose revenue depends on online availability, the value of security is not "how many Gbps you blocked," but turning uncontrollable risk into a predictable cost. Illustrative estimate:
| Item | Before (native high-defense) | After (AwayDDoS fixed package) |
|---|---|---|
| Normal security cost | Usage-based, fluctuates (spikes on attack) | Included in annual fee |
| Attack-month bill peak | Peak-based, unpredictable | Within fixed package, advance notice before overage, no surprise surcharge |
| Outage risk | Over quota → blackholed, whole network down (lift only by paying) | Regional isolation + second-level switch, 0 outages |
| Annual security spend | Hard to estimate (attack-dependent) | Fixed & predictable (with overage allowance) |
Conservatively: an annual fixed package avoids the unpredictable attack-bill spikes and, more importantly, averts at least one peak-season / promotion outage (GMV loss in the millions) — plus 7×24 expert watch. Just the "no bill spike" benefit already makes a strong return; counting business-continuity value, the combined ROI exceeds 10×.
The real payoff: finance can finally tell the boss, "Our security budget is this number — it won't move just because we got attacked."