Evaluating DDoS protection beyond bandwidth
Gbps, packet rate, connection counts and HTTP request rates describe different pressures. Combine them with traffic direction, legitimate bandwidth and origin health when evaluating protection.
Contents of this article
A single peak does not describe the whole load
Network-layer and application-layer attacks consume different resources. Volume can fill a link, small packets can stress packet processing, connection churn consumes connection resources, and costly HTTP requests can overload a database. Identify the bottleneck before choosing the metric.
Read four groups of metrics together
Track bandwidth, packets per second, active and new connections, and HTTP request rates with errors. Interpret request volume alongside endpoint cost: a static image and a complex query can impose very different origin loads at the same QPS. Capacity at one layer cannot be directly converted into capacity at another.
Confirm traffic direction and legitimate bandwidth
Confirm the mitigation scope, traffic direction, legitimate bandwidth and origin path separately. WAFPRO Hong Kong high-defense IP plan figures apply to CN-direction attacks. Unmetered overseas-direction defense is an optional add-on; it means no extra billing by attack count or volume within the service scope, not infinite physical mitigation capacity.
Users must still complete their tasks after mitigation
Test critical journeys such as page access, login, core APIs and payment callbacks, measuring success, latency and false positives. Validate APIs, game protocols and browser pages separately. Restrict origin ingress according to the deployment design so attackers cannot simply bypass the protected address.
Keep evidence that supports an incident review
Align alerts, policy changes, origin load and user errors on one timeline. During an incident, identify whether the constrained resource is the link, connections, application processing or a downstream dependency before changing controls. Run validation only in owned or authorized test environments with agreed traffic limits and stop conditions.
