Continuing our series of posts on Enterprise Infrastructure capabilities, featured in a dedicated tab within the Blueprint dashboard, this post explores the Layered DDoS Protection.
Layered Distributed Denial of Service (DDoS) Protection in Pega Cloud provides comprehensive, multi-layer defense mechanisms that protect your applications from volumetric, protocol-based, and application-layer DDoS attacks at network, infrastructure, and application levels.
What it Means:
- DDoS protection is a multi-layered defense strategy that automatically detects, filters, and mitigates malicious traffic floods designed to overwhelm your application’s availability.
- Pega Cloud uses a combination of edge-level filtering, geographic traffic distribution, intelligent rate limiting, and behavioral analysis to defend against attacks while allowing legitimate traffic to flow uninterrupted.
- If attack traffic arrives → it is filtered and dropped
- If legitimate traffic arrives → it reaches your application
What It Does: It protects against multiple types of DDoS attacks:
- Volumetric attacks: Detects and absorbs massive traffic floods (UDP floods, DNS amplification, ICMP floods)
- Protocol attacks: Mitigates SYN floods, fragmented packet attacks, and malformed packets
- Application-layer attacks: Filters HTTP/HTTPS floods, Layer 7 attacks, and bot traffic
- Intelligent rate limiting: Throttles excessive requests from suspicious sources while whitelisting known good traffic
- Geographic distribution: Absorbs attacks across multiple edge locations globally to avoid impact on your region
- Real-time monitoring: Continuously analyzes traffic patterns for anomalies and generates alerts
How It Works
DDoS protection operates automatically across three defensive layers:
- Network Edge Layer: Global edge servers filter volumetric and protocol attacks before they reach your infrastructure
- Infrastructure Layer: Stateful firewalls and load balancers detect and drop malformed packets and connection floods
- Application Layer: Web Application Firewall (WAF) and bot detection identify and block HTTP-based attacks and suspicious behavioral patterns
- Behavioral Analysis: Machine learning models analyze traffic patterns to distinguish legitimate users from automated attack sources
- Capacity Scaling: Pega Cloud automatically scales resources to absorb attack traffic while maintaining service availability for legitimate users
Best Practices
- Configure IP Allow Lists to restrict access to trusted networks and reduce attack surface
- Enable geographic restrictions if your application doesn’t require global access
- Use custom rate limiting rules tailored to your application’s normal traffic patterns
- Monitor DDoS protection logs to understand attack patterns and adjust defenses accordingly
- Test your application resilience during approved vulnerability testing windows (with Pega support coordination)
- Maintain an incident response plan and contact Pega Support if you experience sustained attacks
Technical Documentation available here