Home/Labs/DDoS Scrubbing Capacity
All 280 Labs
INTERACTIVE LAB🌊

Layer 3/4 vs Layer 7 DDoS Mitigation Lab (Interactive)

Flood the edge with terabits, SYN storms, and Slowloris; watch what reaches origin. Model volumetric and application attacks against Anycast PoP counts, SYN cookies, JS challenges, and proxy buffering to compute origin saturation and bot block rates.

DDoS Scrubbing Capacity Lab

Pick a flood class, dial its intensity and your edge topology, and watch what actually reaches the origin.

Forged victim-source queries to open Memcached ports return ~50,000x the request bytes — a tiny botnet becomes a terabit wall.

Load reaching origin0.0 / 20 Gbps

Mitigated — service intact3 Tbps diffused over 150 PoPs = 10.0 Gbps each — every edge node scrubs its slice at wire speed with eBPF/XDP driver drops.

Interview split to state out loud: L3/4 floods (Gbps/Mpps) are defeated by physics — BGP Anycast diffusion plus driver-level XDP drops — while L7 attacks (RPS) require semantics: rate limiting, behavioral rules, and challenges. The hard part of L7 mitigation is not blocking bots, it is the false-positive tax on humans behind carrier NAT.

How It Works Under the Hood

Volumetric attacks are physics: a 3 Tbps memcached reflection (50,000x amplification from forged UDP probes) can only be survived by diffusing it across hundreds of BGP Anycast points of presence and dropping junk packets at wire speed with eBPF/XDP, because a single 20 Gbps origin pipe is arithmetically hopeless. TCP SYN floods target kernel state instead of bandwidth, and SYN cookies answer with a zero-RAM handshake proof. Layer 7 floods target semantics: cheap-to-send, expensive-to-serve requests that mimic real users, defeated by WAF rules and invisible proof-of-work challenges whose hidden cost is false positives on humans behind carrier NAT. The lab lets you dial each attack and each defense to see the surviving load.

Core Architectural Principles

  • Anycast divides the flood by PoP count; each edge node must scrub its slice under 40 Gbps.
  • SYN cookies encode connection state in the ISN, so spoofed SYNs allocate zero socket memory.
  • Slowloris is neutralized by event-loop proxies with strict header/body timeouts, not bandwidth.
Interview Round Script

Split L3/4 versus L7 immediately: volumetric is answered by capacity and Anycast diffusion plus upstream scrubbing, while application floods are answered by rate limiting, behavioral detection, and challenges. Mention SYN cookies by name, amplification factors for UDP reflection, and honestly quote the challenge false-positive tax for NAT users.

Key Trade-Offs

Edge scrubbing defeats bits but not semantics; L7 defenses always trade bot block rate against human friction.

Related Curriculum Chapter

DDoS Protection: Layer 3/4 vs Layer 7 Attacks

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs