How a Video Site Used AwayDDoS
to Balance Performance, Security & Cost
A video platform with average engineering and no dedicated security engineer was frequently attacked as it scaled. Its origin sat on a public cloud where both bandwidth and defense were expensive. On our advice, it prioritized cost, moved the origin to the US (lowest bandwidth cost), and onboarded a high-defense IP network where different IP segments provide natural isolation — minimizing daily O&M. We also configured a globally route-optimized network, finding balance across performance, security and cost. Here is its real story (client name withheld, figures illustrative).
Customer Background
This is a video site built around long-form VOD and live-stream rebroadcast. Video by nature is bandwidth-heavy, high-concurrency, and continuously busy on both up and down links: viewers generate large downstream flows, while live and uploads keep upstream busy. Any few minutes of stalling or outage shows up directly in churn. As content and audience grew, its traffic curve climbed steadily — and so did the probability of being attacked.
Like most growing sites, its engineering team was small and had no dedicated security engineer. Day to day it could just keep the product running; security relied on the cloud's "out-of-the-box" baseline protection, with nobody watching attacks 7×24. When a moderately sized attack hit, the team often only noticed once the site was already down, then scrambled to open a cloud ticket — exactly why professional protection had to come in.
Three Mountains: the hidden cost of scaling a video site
① High bandwidth cost: large-traffic business "metered" by cloud egress
Video is notoriously a bandwidth devourer. With the origin on a domestic cloud, all viewer downstream traffic went through the cloud's public egress bandwidth, billed by usage. At scale, the monthly bandwidth bill became a frightening fixed cost; worse, malicious attack traffic also counted as egress — you literally paid to push attack traffic out of the network.
② High defense cost: cloud native high-defense billed by attack peak
Cloud native high-defense / scrubbing typically bills dynamically by attack peak and duration beyond the protected quota. Video sites are easy targets for traffic-flooding attacks, so the extra scrubbing fees piled onto an already tight bandwidth budget, making security cost completely uncontrollable.
③ Nobody watching: no dedicated security engineer, attacks met only passively
This is the deadliest one. With no one dedicated to security, attacks were detected late and responded to slowly. Even when high-defense was bought, someone still had to tune the policy. For a team that could only just maintain the product, every attack was a "last-minute panic" disaster — draining dev focus and still not guaranteed to stop the loss in time.
The hidden threshold to scaling a video site was never "can it handle traffic", but "can it handle attacked traffic at an acceptable bandwidth and O&M cost — steadily".
AwayDDoS Solution: a cost-first "three-part combo"
Our first agreement with the client: the protection plan must prioritize cost and operability. We delivered a combo that "lowers the bill, reduces O&M, and stands up defense":
- Move the origin to the US for the lowest bandwidth cost — for bandwidth-heavy video, US data-center international bandwidth unit price is far below domestic cloud egress. Placing the origin and rebroadcast nodes in the US fundamentally cut the largest monthly cost line.
- Onboard a high-defense IP network with per-segment isolation — all business traffic flows in and out through AwayDDoS's high-defense IP network; we assign different IP segments to different businesses / regions, so one segment under attack does not affect others — isolation is itself defense.
- Configure globally optimized routing to balance performance / security / cost — layered with China-optimized routing (CN2 / CTGNet / CMI, etc.) and globally distributed PoPs for nearest access, so "putting the origin in the US" did not sacrifice China-return or overseas experience.
The whole setup is managed 7×24 by the AwayDDoS expert team, so the client needs no dedicated security engineer and daily O&M drops to a minimum.
How It Works: two-layer scrubbing + IP-segment isolation + route optimization
The design borrows a proven two-layer cleaning architecture (see diagram below): attack traffic is first diverted to the nearest scrubbing node for first-layer "near-source cleaning", diluting most volumetric floods; then traffic is sent back over the backbone to the access PoP for second-layer "deep cleaning", precisely identifying and blocking application-layer attacks like CC and slowloris, ensuring only the cleanest traffic is re-injected to the client.
Dilutes 90% volumetric
Blocks CC / slowloris
One hit, others safe
1. High-defense IP in/out
All business flows through AwayDDoS high-defense IPs; different businesses / regions use different IP segments. Attacks are locked to a single segment — natural isolation avoids "hit one, drop all".
2. Two-layer distributed scrubbing
Traffic is cleaned near the source at the edge and deep-cleaned again at the PoP, combining signature and behavior analysis to precisely filter DDoS / CC while keeping legit requests.
3. Global optimized rebroadcast
Different destinations get China-optimized / Asia-optimized / international routing, so the US origin's China-return and overseas access both take the best path — no performance trade-off.
Core Advantages
Lowest cost: US origin + 95th burstable billing
Move the bandwidth hog to the US with 95th-percentile burstable billing to cut the monthly bandwidth bill; protection is a fixed package, no peak surcharge during attacks.
IP-segment isolation: one hit, rest safe
Different businesses / regions get different high-defense IP segments; an attack confined to one segment leaves others running — isolation itself is a defense line.
No security engineer needed: managed 7×24
The AwayDDoS expert team manages and tunes policy around the clock; the client's engineering team needs no watch duty and no in-house security build-out.
Route optimization: balance all three
China-optimized (CN2 / CTGNet / CMI) + Asia-optimized + global PoPs keep China-return quality without giving up overseas coverage — all three at once.
Technical Specs & Use Cases
High-defense IP network and segment isolation
| Capability | Description | Value to video |
|---|---|---|
| High-defense IP in/out | Business flows through the high-defense IP network with Always-On protection; no manual activation on attack. | Video's heavy traffic is natively under the shield — no emergency response. |
| Per-segment isolation | Different business / region IP segments; an attack on one segment does not spill to the whole network. | Live, VOD and API don't drag each other down — one hit, others safe. |
| China / Asia optimized routing | Flexible mix of China-optimized (CN2 / CTGNet / CMI) and Asia-optimized routing. | US origin's China-return and Asia access take premium paths — no quality loss. |
Traffic Diversion
| Method | Description | Use case |
|---|---|---|
| DNS CNAME diversion | Smoothly steer traffic to the scrubbing center by changing DNS; simple, non-intrusive, fast switch / rollback. | Web, video, API services |
| BGP route diversion | For bare-IP business, dynamically announce target IP segments via BGP for transparent牵引, supporting huge-bandwidth real-time scrubbing. | High-defense IP network, hosters |
| Anycast IP diversion | Global anycast IP; user traffic auto-reaches the nearest scrubbing node by topology, millisecond diversion and cleaning. | Global acceleration, cross-border video |
Traffic Re-injection
| Method | Description | Use case |
|---|---|---|
| Static IP fixed re-injection | Fixed IP re-injection for traditional business; clean traffic returned via preset static public IP. | Fixed-IP origin, closed networks |
| Cloud connect /专线 / VPN Tunnel re-injection | A dedicated channel returns compliant clean traffic to origin — secure, stable, low latency. | US origin, cross-region |
Comparison: AwayDDoS vs Cloud Native (client's original)
| Dimension | AwayDDoS | Cloud native (client's original) |
|---|---|---|
| Bandwidth cost | US origin + 95th burstable billing, lowest unit price for heavy traffic, controllable monthly bill. | Cloud egress billed by usage; heavy video traffic bill is high. |
| Defense billing | Fixed protection package, no peak surcharge during attacks; malicious traffic not counted as client egress. | Native high-defense billed by attack peak / duration; spikes on attack. |
| Isolation | Different IP segments isolate naturally; one segment hit does not affect the whole. | Mostly a single high-defense instance; easy to be "swept" across segments. |
| Security staffing | 7×24 managed expert watch; client needs no dedicated security engineer. | Needs in-house config and watch; hard for a small team to sustain. |
| Route optimization | China / Asia optimized routing + global PoPs; balances performance, security and cost. | Cloud-internal network; cross-border China-return quality vs cost hard to balance. |
Results
After onboarding AwayDDoS, the video site moved from the "expensive bandwidth, expensive defense, nobody watching" trilemma to a steady state of "low cost, good isolation, someone watching". Key metrics (illustrative):
- Bandwidth bill halved — after moving the origin to the US with 95th burstable billing, the largest cost line dropped sharply, and attack traffic no longer counts as client egress.
- IP-segment isolation realized — live, VOD and API sit in separate high-defense segments; an attack on one is confined to that segment, so "one hit freezes the whole site" is history.
- No dedicated security engineer — fully managed by the AwayDDoS expert team, the client's engineers finally focus back on the product.
- No quality trade-off — global route optimization keeps the US origin's China-return and overseas access on premium paths, users barely notice.
ROI
For a video team that is "average in engineering, with no security engineer", AwayDDoS's value is not just "blocking attacks" but turning security and O&M into a budgetable, outsourced line item. Illustrative estimate:
| Item | Before (cloud native) | After (US origin + high-defense IP) |
|---|---|---|
| Monthly bandwidth | Egress by usage, scales with traffic | US origin + 95th burstable, much lower |
| Attack-month defense bill | Dynamic by peak, unpredictable | Within fixed package, no surge surcharge |
| Security staffing | Needs dedicated engineer (or frequent firefighting) | 0 (7×24 managed) |
| Annual total cost | Hard to predict (depends on attack frequency / scale) | Fixed & predictable (bandwidth + package) |
Conservatively: post-transformation annual total cost is fixed and predictable, versus the cloud-native "bandwidth + defense + firefighting labor" that routinely runs far higher in uncontrolled spend — saving a substantial budget every year. More importantly, the team returns from "held hostage by attacks" to "focused on business", with comprehensive ROI well above 3×. For a video team with no security engineer, this math is more real than any point solution.
The real payoff is the tech lead finally telling the boss: "Security is now outsourced to a pro team — the bill is down, the headcount is saved, and the business no longer splits focus over attacks."