07/09/2026

From the Field: What a 2M RPS HTTPS Flood can teach us about modern DDoS Protection

I came across an interesting customer story this week, and I thought it was worth sharing because there's an important lesson behind it.

A few days ago, a regional government in Europe, responsible for the country's largest province, came under a large-scale HTTPS flood attack.

This wasn't "just another website." The organization provides digital services that millions of citizens and businesses rely on every day, including tax services, official procedures, and access to personal records. Losing availability would have had a real impact on people's daily lives.

The attack was launched by a globally distributed botnet with more than 1,600 source IPs and generated 2 million HTTPS requests per second for 30 consecutive minutes, nearly 20,000 times the organization's normal HTTPS traffic.

Fortunately, Behind the scenes, AI-powered traffic baselining and automatically generated mitigation signatures made it possible to block only the malicious traffic while legitimate users continued using the services without interruption.

What I find most interesting about this story isn't the scale of the attack. It's the nature of HTTPS flood attacks.

Unlike traditional volumetric attacks, the malicious requests often look almost identical to legitimate user traffic. The challenge isn't simply blocking traffic. It's identifying the malicious requests while allowing legitimate users to continue accessing critical services without interruption.

If there's one takeaway I'd encourage every organization to think about, it's this:

Successful DDoS protection isn't measured by how much traffic you can block. It's measured by whether legitimate users can continue doing what they came to do, even while an attack is in progress.

That's why it's worth asking yourself:

  • Can you distinguish legitimate users from bots in real time?

  • How quickly can mitigation happen without human intervention?

  • Would your critical services remain available during an HTTPS flood attack?

I'd love to hear how your organization approaches this challenge.

Regards,

Haim

 

10
49 replies