Why Your CDN is No Longer a DDoS Kill-Switch


For years, CDNs have been positioned as the first and sometimes only line of defense against DDoS attacks. The promise was simple: “put your application behind a CDN and attacks disappear”.

That promise no longer holds.

CDNs are good at absorbing large traffic floods, but modern Web DDoS attacks don’t rely on volume alone. Today’s attacks mix high traffic with subtle application-level abuse targeting sessions, state, backend logic, and resource imbalance. These are areas where traditional CDNs often have limited visibility and little control.

The Reality of Today's Cyber Threats

Web applications are now the core of business operations; payments, authentication, analytics, APIs, and internal services all sit behind HTTP. That also makes Layer-7 the most valuable attack surface.

Modern DDoS attacks are no longer about “how much traffic can I send?”

They’re about how much work I can force your backend to do per request.

Where Modern DDoS Attacks Slip Past the CDN

  • The "Heavy Traffic" Smokescreen: Attackers often launch a massive 10+ Tbps volumetric distraction at the CDN edge. While security teams scramble to manage the noise, a surgical "low and slow" attack hits the origin, targeting expensive endpoints like “/search” or “/login”.
  • Resource Asymmetry: A single request that looks "normal" to a CDN might trigger a massive database query on your server. It takes very little "heavy traffic" to crash into a database if the requests are designed to be computationally expensive.
  • Protocol Exploits: New techniques, like the HTTP/2 "Rapid Reset" or API-specific floods, exploit the way modern web protocols handle connections, often slipping through standard CDN filters.

Why Layer 7 DDoS Mitigation is a Challenge

Mitigating Layer 7 (Application Layer) DDoS attacks is uniquely difficult because these attacks target the "brain" of the application rather than the network bandwidth.

  • Legitimate Appearance: Attackers generate genuine HTTP/HTTPS requests.
  • Real URLs and APIs: Attackers often focus on valid, high-processing URLs or APIs, such as /login, /search or /checkout.
  • The "False Positive" Risk: Overly aggressive blocking risks "collateral damage” blocking legitimate customers and causing a self-inflicted outage.
  • Bad traffic looks noisy: By distributing requests across a massive botnet of unique IPs, attackers ensure the volume per IP stays below traditional rate-limiting thresholds. This allows the attack to fly under the radar of simple security tools.

The High Cost of "Unlimited" Scaling

Many organizations rely on Cloud Auto-Scaling as a secondary defense. While this keeps the site "up," but creates a new set of problems:

1. Economic Denial of Sustainability (EDos)

Unlike classic DDoS attacks that try to knock off your site offline, EDOs attacks target your wallet. Attackers send large volumes of traffic that look completely legitimate, quietly triggering your auto-scaling rules. Your cloud platform responds exactly as designed by spinning up more servers to handle the load.

The result: your application stays online, but your cloud bill explodes. Nothing breaks at the code level; the attack succeeds by turning your own scalability into a financial weapon.

2. Flapping Instability

Sophisticated attackers now use periodic burst attacks. They send enough heavy traffic to trigger a "Scale Up" event. Just as your new servers come online, the attacker stops. Your system then begins a "Scale Down" process to save costs. The moment your servers are deleted, the attacker hits again.

The Result: This constant oscillation keeps your application in a state of perpetual instability, often causing more downtime than a steady flood would.

Where CDN Protection Ends and Application Security Begins

A CDN is designed to absorb traffic at scale, but it has limited visibility into how each request affects the application behind it. Once traffic appears legitimate, the CDN's job is largely complete. The harder problem begins with the application layer.

Application Context Matters

Not every HTTP request has the same impact on an application. A request to retrieve a static image is fundamentally different from one that triggers database queries, authentication of workflows or multiple backend service calls. Without understanding this context, security decisions are based only on traffic volume rather than application impact.

Legitimate Requests Can Still Be Malicious

Consider a distributed attack targeting an expensive endpoint such as /search or /checkout. Each request carries valid headers, originates from a different IP address, and stays below conventional rate limits. To the CDN, the traffic appears legitimate. Meanwhile, the application spends CPU cycles, database connections and memory processing every request until backend resources become constrained.

Why Application-Aware Protection Makes the Difference

Modern Layer 7 protection must look beyond request counts. It needs to evaluate request behavior, endpoint sensitivity, session characteristics, and how traffic patterns evolve over time. This makes it possible to distinguish a genuine surge in user activity from a coordinated attempt to exhaust application resources.

A Realistic Layer 7 Attack Flow

Consider an application running behind a CDN with auto-scaling enabled.

An attacker targets the /search endpoint using thousands of distributed clients. Each request is syntactically correct, carries valid headers, and stays below traditional rate-limiting thresholds. At the edge, the CDN sees what appears to be normal application traffic and forwards it to the origin.

The application tells a different story. Every request triggers search indexing, database queries, cache lookups, and calls to backend services. CPU utilization begins to climb, response times increase, and auto-scaling provisions additional infrastructure to keep pace.

From the user's perspective, the application is still online. Behind the scenes, however, infrastructure costs continue to rise while backend resources operate under sustained pressure.

This is where application-aware protection changes the outcome. Rather than relying solely on request volume or IP reputation, Radware's Kubernetes-native WAAP continuously analyses request behaviour, correlates activity across sessions, clients, and endpoints, and identifies patterns that indicate coordinated low-and-slow attacks. This enables the platform to detect attacks that remain below traditional rate-limiting thresholds but collectively place significant pressure on backend services.

Because WAAP is deployed as lightweight Kubernetes-native enforcers, protection scales alongside the application as new pods are created, eliminating the need to route all traffic through a centralized inspection point. Combined with Radware's detection and correlation engine, suspicious requests can be challenged or mitigated before they trigger unnecessary auto-scaling, exhaust backend resources or impact legitimate users.

Conclusion: Rethinking Your Layer 7 Defense Strategy

Modern DDoS resilience is no longer about choosing between a CDN and a WAF. Each addresses a different part of the problem.

A CDN remains essential for absorbing large-scale traffic floods and protecting network capacity. However, as attacks increasingly target application behavior rather than bandwidth, organizations also need visibility into how requests consume backend resources and affect application performance.

Diagram showing a CDN and Radware WAAP working together to provide layered Layer 7 DDoS defense

When deployed together, each layer strengthens the other. The CDN handles scale at the edge, while the WAAP identifies and mitigates application-layer abuse that would otherwise appear legitimate.

As you evaluate your current architecture, consider a few practical questions:

  • Can your security stack distinguish expensive application requests from inexpensive ones?
  • Can it identify distributed, low-rate attacks before auto-scaling is triggered?
  • Can it differentiate a genuine traffic surge from coordinated application abuse?
  • Can it protect backend resources without disrupting legitimate users?

If the answer to these questions is "no" your challenge isn't simply absorbing more traffic. It's gaining the application-level visibility needed to detect and stop modern Layer 7 attacks before they impact performance, availability or cost.

Yaron Nachum

Contact Radware Sales

Our experts will answer your questions, assess your needs, and help you understand which products are best for your business.

Already a Customer?

We’re ready to help, whether you need support, additional services, or answers to your questions about our products and solutions.

Locations
Get Answers Now from KnowledgeBase
Get Free Online Product Training
Engage with Radware Technical Support
Join the Radware Customer Program

Get Social

Connect with experts and join the conversation about Radware technologies.

Blog
Security Research Center
CyberPedia