Inside Pega Enterprise Infrastructure: Security and Encryption / Distributed Denial of Service

Continuing the series of posts related to the Enterprise Infrastructure capabilities which are captured as a dedicated tab within the Blueprint dashboard. This post is focused on the Distributed Denial of Service.

Layered Distributed Denial of Service Protection in Pega Cloud

Layered Distributed Denial of Service (DDoS) Protection in Pega Cloud helps protect applications from high-volume attacks through a multi-layered architecture that detects, mitigates, and absorbs malicious traffic while maintaining service availability.

:white_check_mark: What it means

  • Pega Cloud provides layered protection and counterstrategies to help protect against Distributed Denial of Service (DDoS) attacks.

  • DDoS protection is a shared responsibility between Pega and the client.

:white_check_mark: What it does

  • Uses a multi-layered architecture to prevent and mitigate DDoS attacks.

  • Includes auto-scaling of environments and DNS management.

  • Provides detection, mitigation, monitoring, firewall, IPS, network ACLs, and allow-list capabilities.

:white_check_mark: How it works

  • Scalability of environments, load balancers, and DNS infrastructure.

  • Always-on detection and automatic inline mitigations.

  • Web application firewall and host-based IPS.

  • Real-time monitoring and alarms.

  • Least-privileged firewall rules and network ACLs.

  • Client-defined allow list.

:white_check_mark: Protected layers

  • Layer 7 (application layer)

  • Layer 6 (presentation layer/TLS)

  • Layer 4 (transport layer/SYN flood)

  • Layer 3 (network layer/UDP reflection)

  • Traffic scaling and geographic traffic dispersion

:white_check_mark: Best practices

  • Reduce the attack surface where possible.

  • Publicly exposed applications have greater risk.

  • Consider additional third-party DDoS protection services depending on risk profile and public exposure.

:open_book: Technical Documentation available here