Plateforme Edge Cloud de Fastly

Solutions numériques innovantes

Revenir au blog

Suivre et s’abonner

Disponible uniquement en anglais

Cette page n'est actuellement disponible qu'en anglais. Nous nous excusons pour la gêne occasionnée, merci de revenir sur cette page ultérieurement.

Preventing Automated Security Decisions from Impacting Critical Events

David King

Responsable marketing produit de groupe, sécurité

Tin Zaw

Staff Technical Product Manager, Security (DDoS)

When your company hosts a big moment – a Black Friday sale, streaming the World Cup championships, or your company’s version of the Super Bowl – the last thing anyone wants to worry about are false positives (inaccurate security blocks) stopping customers from driving value for your business. But as security teams lean on AI and automation, how do you stay protected without your automation mistaking a global traffic surge for an attack?

While minimizing false positives has always been a core focus for Fastly DDoS Protection, knowing that a tool will hold up during a high-stakes event requires more than assurances – it requires complete visibility and control. Here’s what we’re doing about it.

Fastly DDoS Protection’s New Action

We’re excited to introduce a new Challenge action to Fastly DDoS Protection. Leveraging our Dynamic Challenges functionality behind the scenes, the Challenge action can be applied holistically to your service or the rules being automatically generated to mitigate attacks on it. As your organization heads into the holiday season or other high traffic periods, you can quickly flip Fastly DDoS Protection’s action to Challenge to maintain your security posture while eliminating any chance of false positives incorrectly blocking legitimate traffic.

What are Dynamic Challenges?

Dynamic Challenges is a security response that automatically optimizes for the best experience while maintaining your security posture. It serves the most optimal client-challenge based on the context of who or what is making the request. Think of it as a continuum where if you’re human, you receive the least interactive challenge (Javascript, computational in the background). Malicious bots get an interactive CAPTCHA and all other interactions including API to API are dynamically served the most security- and experience-optimized response.  

Best of all, Fastly is one of two authorized Private Access Token (PAT) token issuers, meaning we can uniquely validate a portion of human traffic without serving a traditional challenge at all. By leveraging Dynamic Challenges as an action for services, Fastly DDoS Protection prevents automated security decisions from impacting critical events.

How it works

Enabling the Challenge response is as simple as picking it from the dropdown at a service or rule level.

As your team heads into high value periods, consider:

  1. Do we expect large fluctuations in legitimate traffic like a sale, global update, or big game? These spikes can appear as DDoS attacks and you may benefit from moving to the Challenge response in the moments before the event kicks off.

  2. What is our risk tolerance to legitimate traffic? If you want minimized risk, the Challenge response is optimal!

  3. Do we expect the spike to be localized to a specific service? This response can be leveraged at the service-level so you can use the Challenge response while maintaining your security posture across the rest of your attack surface.

Automatically Mitigate Disruptive and Distributed Attacks

Fastly DDoS Protection is the automatic solution to mitigate application DDoS attacks. Whether you choose to use the Challenge response, outright block, or a combination, it protects your applications and APIs from volumetric threats attempting to impact performance or inflate operational expenses. Let our adaptive technology absorb the next spike so you don't have to. Contact our team or start your free trial today.

Prêt à commencer ?

Contactez-nous dès aujourd’hui