Customer Story · 客戶案例

How a Video Site Used AwayDDoS
to Balance Performance, Security & Cost

A video platform with average engineering and no dedicated security engineer was frequently attacked as it scaled. Its origin sat on a public cloud where both bandwidth and defense were expensive. On our advice, it prioritized cost, moved the origin to the US (lowest bandwidth cost), and onboarded a high-defense IP network where different IP segments provide natural isolation — minimizing daily O&M. We also configured a globally route-optimized network, finding balance across performance, security and cost. Here is its real story (client name withheld, figures illustrative).

Customer Background

This is a video site built around long-form VOD and live-stream rebroadcast. Video by nature is bandwidth-heavy, high-concurrency, and continuously busy on both up and down links: viewers generate large downstream flows, while live and uploads keep upstream busy. Any few minutes of stalling or outage shows up directly in churn. As content and audience grew, its traffic curve climbed steadily — and so did the probability of being attacked.

Like most growing sites, its engineering team was small and had no dedicated security engineer. Day to day it could just keep the product running; security relied on the cloud's "out-of-the-box" baseline protection, with nobody watching attacks 7×24. When a moderately sized attack hit, the team often only noticed once the site was already down, then scrambled to open a cloud ticket — exactly why professional protection had to come in.

①Lowest bandwidth costMoving the origin to the US cuts international bandwidth unit price far below cloud egress — directly lowering the single biggest cost line.
②IP-segment isolationDifferent businesses / regions get different high-defense IP segments; an attack on one segment never spills to the whole network.
③No security headcount7×24 managed expert watch means the client needs no dedicated security engineer, freeing the team to focus on the product.

Three Mountains: the hidden cost of scaling a video site

① High bandwidth cost: large-traffic business "metered" by cloud egress

Video is notoriously a bandwidth devourer. With the origin on a domestic cloud, all viewer downstream traffic went through the cloud's public egress bandwidth, billed by usage. At scale, the monthly bandwidth bill became a frightening fixed cost; worse, malicious attack traffic also counted as egress — you literally paid to push attack traffic out of the network.

② High defense cost: cloud native high-defense billed by attack peak

Cloud native high-defense / scrubbing typically bills dynamically by attack peak and duration beyond the protected quota. Video sites are easy targets for traffic-flooding attacks, so the extra scrubbing fees piled onto an already tight bandwidth budget, making security cost completely uncontrollable.

③ Nobody watching: no dedicated security engineer, attacks met only passively

This is the deadliest one. With no one dedicated to security, attacks were detected late and responded to slowly. Even when high-defense was bought, someone still had to tune the policy. For a team that could only just maintain the product, every attack was a "last-minute panic" disaster — draining dev focus and still not guaranteed to stop the loss in time.

The hidden threshold to scaling a video site was never "can it handle traffic", but "can it handle attacked traffic at an acceptable bandwidth and O&M cost — steadily".

AwayDDoS Solution: a cost-first "three-part combo"

Our first agreement with the client: the protection plan must prioritize cost and operability. We delivered a combo that "lowers the bill, reduces O&M, and stands up defense":

  1. Move the origin to the US for the lowest bandwidth cost — for bandwidth-heavy video, US data-center international bandwidth unit price is far below domestic cloud egress. Placing the origin and rebroadcast nodes in the US fundamentally cut the largest monthly cost line.
  2. Onboard a high-defense IP network with per-segment isolation — all business traffic flows in and out through AwayDDoS's high-defense IP network; we assign different IP segments to different businesses / regions, so one segment under attack does not affect others — isolation is itself defense.
  3. Configure globally optimized routing to balance performance / security / cost — layered with China-optimized routing (CN2 / CTGNet / CMI, etc.) and globally distributed PoPs for nearest access, so "putting the origin in the US" did not sacrifice China-return or overseas experience.

The whole setup is managed 7×24 by the AwayDDoS expert team, so the client needs no dedicated security engineer and daily O&M drops to a minimum.

How It Works: two-layer scrubbing + IP-segment isolation + route optimization

The design borrows a proven two-layer cleaning architecture (see diagram below): attack traffic is first diverted to the nearest scrubbing node for first-layer "near-source cleaning", diluting most volumetric floods; then traffic is sent back over the backbone to the access PoP for second-layer "deep cleaning", precisely identifying and blocking application-layer attacks like CC and slowloris, ensuring only the cleanest traffic is re-injected to the client.

Attack traffic
Divert to nearest node
Layer 1 · Near-source
Dilutes 90% volumetric
→
Backbone return
Access PoP
Layer 2 · Deep clean
Blocks CC / slowloris
→
Clean traffic
Re-inject US origin
Per-segment isolation
One hit, others safe

1. High-defense IP in/out

All business flows through AwayDDoS high-defense IPs; different businesses / regions use different IP segments. Attacks are locked to a single segment — natural isolation avoids "hit one, drop all".

2. Two-layer distributed scrubbing

Traffic is cleaned near the source at the edge and deep-cleaned again at the PoP, combining signature and behavior analysis to precisely filter DDoS / CC while keeping legit requests.

3. Global optimized rebroadcast

Different destinations get China-optimized / Asia-optimized / international routing, so the US origin's China-return and overseas access both take the best path — no performance trade-off.

Core Advantages

Lowest cost: US origin + 95th burstable billing

Move the bandwidth hog to the US with 95th-percentile burstable billing to cut the monthly bandwidth bill; protection is a fixed package, no peak surcharge during attacks.

IP-segment isolation: one hit, rest safe

Different businesses / regions get different high-defense IP segments; an attack confined to one segment leaves others running — isolation itself is a defense line.

No security engineer needed: managed 7×24

The AwayDDoS expert team manages and tunes policy around the clock; the client's engineering team needs no watch duty and no in-house security build-out.

Route optimization: balance all three

China-optimized (CN2 / CTGNet / CMI) + Asia-optimized + global PoPs keep China-return quality without giving up overseas coverage — all three at once.

Technical Specs & Use Cases

High-defense IP network and segment isolation

CapabilityDescriptionValue to video
High-defense IP in/outBusiness flows through the high-defense IP network with Always-On protection; no manual activation on attack.Video's heavy traffic is natively under the shield — no emergency response.
Per-segment isolationDifferent business / region IP segments; an attack on one segment does not spill to the whole network.Live, VOD and API don't drag each other down — one hit, others safe.
China / Asia optimized routingFlexible mix of China-optimized (CN2 / CTGNet / CMI) and Asia-optimized routing.US origin's China-return and Asia access take premium paths — no quality loss.

Traffic Diversion

MethodDescriptionUse case
DNS CNAME diversionSmoothly steer traffic to the scrubbing center by changing DNS; simple, non-intrusive, fast switch / rollback.Web, video, API services
BGP route diversionFor bare-IP business, dynamically announce target IP segments via BGP for transparent牵引, supporting huge-bandwidth real-time scrubbing.High-defense IP network, hosters
Anycast IP diversionGlobal anycast IP; user traffic auto-reaches the nearest scrubbing node by topology, millisecond diversion and cleaning.Global acceleration, cross-border video

Traffic Re-injection

MethodDescriptionUse case
Static IP fixed re-injectionFixed IP re-injection for traditional business; clean traffic returned via preset static public IP.Fixed-IP origin, closed networks
Cloud connect /专线 / VPN Tunnel re-injectionA dedicated channel returns compliant clean traffic to origin — secure, stable, low latency.US origin, cross-region

Comparison: AwayDDoS vs Cloud Native (client's original)

DimensionAwayDDoSCloud native (client's original)
Bandwidth costUS origin + 95th burstable billing, lowest unit price for heavy traffic, controllable monthly bill.Cloud egress billed by usage; heavy video traffic bill is high.
Defense billingFixed protection package, no peak surcharge during attacks; malicious traffic not counted as client egress.Native high-defense billed by attack peak / duration; spikes on attack.
IsolationDifferent IP segments isolate naturally; one segment hit does not affect the whole.Mostly a single high-defense instance; easy to be "swept" across segments.
Security staffing7×24 managed expert watch; client needs no dedicated security engineer.Needs in-house config and watch; hard for a small team to sustain.
Route optimizationChina / Asia optimized routing + global PoPs; balances performance, security and cost.Cloud-internal network; cross-border China-return quality vs cost hard to balance.

Results

After onboarding AwayDDoS, the video site moved from the "expensive bandwidth, expensive defense, nobody watching" trilemma to a steady state of "low cost, good isolation, someone watching". Key metrics (illustrative):

↓ 60%+monthly bandwidth bill cut
0dedicated security engineer
Per-segmentIP isolation, no drag
7×24managed expert watch
  • Bandwidth bill halved — after moving the origin to the US with 95th burstable billing, the largest cost line dropped sharply, and attack traffic no longer counts as client egress.
  • IP-segment isolation realized — live, VOD and API sit in separate high-defense segments; an attack on one is confined to that segment, so "one hit freezes the whole site" is history.
  • No dedicated security engineer — fully managed by the AwayDDoS expert team, the client's engineers finally focus back on the product.
  • No quality trade-off — global route optimization keeps the US origin's China-return and overseas access on premium paths, users barely notice.

ROI

For a video team that is "average in engineering, with no security engineer", AwayDDoS's value is not just "blocking attacks" but turning security and O&M into a budgetable, outsourced line item. Illustrative estimate:

ItemBefore (cloud native)After (US origin + high-defense IP)
Monthly bandwidthEgress by usage, scales with trafficUS origin + 95th burstable, much lower
Attack-month defense billDynamic by peak, unpredictableWithin fixed package, no surge surcharge
Security staffingNeeds dedicated engineer (or frequent firefighting)0 (7×24 managed)
Annual total costHard to predict (depends on attack frequency / scale)Fixed & predictable (bandwidth + package)

Conservatively: post-transformation annual total cost is fixed and predictable, versus the cloud-native "bandwidth + defense + firefighting labor" that routinely runs far higher in uncontrolled spend — saving a substantial budget every year. More importantly, the team returns from "held hostage by attacks" to "focused on business", with comprehensive ROI well above 3×. For a video team with no security engineer, this math is more real than any point solution.

The real payoff is the tech lead finally telling the boss: "Security is now outsourced to a pro team — the bill is down, the headcount is saved, and the business no longer splits focus over attacks."