Inside Pega Enterprise Infrastructure: Security and Encryption / Layered DDoS Protection

Continuing our series of posts on Enterprise Infrastructure capabilities, featured in a dedicated tab within the Blueprint dashboard, this post explores the Layered DDoS Protection.

Layered Distributed Denial of Service (DDoS) Protection in Pega Cloud provides comprehensive, multi-layer defense mechanisms that protect your applications from volumetric, protocol-based, and application-layer DDoS attacks at network, infrastructure, and application levels.

:white_check_mark: What it Means:

  • DDoS protection is a multi-layered defense strategy that automatically detects, filters, and mitigates malicious traffic floods designed to overwhelm your application’s availability.
  • Pega Cloud uses a combination of edge-level filtering, geographic traffic distribution, intelligent rate limiting, and behavioral analysis to defend against attacks while allowing legitimate traffic to flow uninterrupted.
  • If attack traffic arrives → it is filtered and dropped
  • If legitimate traffic arrives → it reaches your application

:white_check_mark: What It Does: It protects against multiple types of DDoS attacks:

  • Volumetric attacks: Detects and absorbs massive traffic floods (UDP floods, DNS amplification, ICMP floods)
  • Protocol attacks: Mitigates SYN floods, fragmented packet attacks, and malformed packets
  • Application-layer attacks: Filters HTTP/HTTPS floods, Layer 7 attacks, and bot traffic
  • Intelligent rate limiting: Throttles excessive requests from suspicious sources while whitelisting known good traffic
  • Geographic distribution: Absorbs attacks across multiple edge locations globally to avoid impact on your region
  • Real-time monitoring: Continuously analyzes traffic patterns for anomalies and generates alerts

:white_check_mark: How It Works

DDoS protection operates automatically across three defensive layers:

  • Network Edge Layer: Global edge servers filter volumetric and protocol attacks before they reach your infrastructure
  • Infrastructure Layer: Stateful firewalls and load balancers detect and drop malformed packets and connection floods
  • Application Layer: Web Application Firewall (WAF) and bot detection identify and block HTTP-based attacks and suspicious behavioral patterns
  • Behavioral Analysis: Machine learning models analyze traffic patterns to distinguish legitimate users from automated attack sources
  • Capacity Scaling: Pega Cloud automatically scales resources to absorb attack traffic while maintaining service availability for legitimate users

:white_check_mark: Best Practices

  • Configure IP Allow Lists to restrict access to trusted networks and reduce attack surface
  • Enable geographic restrictions if your application doesn’t require global access
  • Use custom rate limiting rules tailored to your application’s normal traffic patterns
  • Monitor DDoS protection logs to understand attack patterns and adjust defenses accordingly
  • Test your application resilience during approved vulnerability testing windows (with Pega support coordination)
  • Maintain an incident response plan and contact Pega Support if you experience sustained attacks

:open_book: Technical Documentation available here