No Scrubs: The Architecture That Made Unmetered Mitigation Possible

Published on by John Graham-Cumming.

When building a DDoS mitigation service it’s incredibly tempting to think that the solution is scrubbing centers or scrubbing servers. I, too, thought that was a good idea in the beginning, but experience has shown that there are serious pitfalls to this approach. A scrubbing server is a dedicated

The Internet is Hostile: Building a More Resilient Network

Published on by Jérôme Fleury.

In a recent post we discussed how we have been adding resilience to our network. The strength of the Internet is its ability to interconnect all sorts of networks — big data centers, e-commerce websites at small hosting companies, Internet Service Providers (ISP), and Content Delivery Networks (CDN) — just to name

How Cloudflare's Architecture Allows Us to Scale to Stop the Largest Attacks

Published on by Matthew Prince.

The last few weeks have seen several high-profile outages in legacy DNS and DDoS-mitigation services due to large scale attacks. Cloudflare's customers have, understandably, asked how we are positioned to handle similar attacks. While there are limits to any service, including Cloudflare, we are well architected to withstand these recent