4 ms·
PM for GCE Autoscaling here. On protection from malicious traffic spikes - you can set a max-instances threshold to prevent over-spend which you can change at a
by ajessup 12y ago
PM for GCE Autoscaling here. On protection from malicious traffic spikes - you can set a max-instances threshold to prevent over-spend which you can change at any time.
Ultimately though, from an instance's perspective, there's not a lot of difference between a malicious DDoS and a genuine traffic spike. You can mitigate this (a) by setting low max-instances thresholds when you aren't expecting high traffic, and (b) upstream filtering or QOS management to filter our DDoS traffic from legitimate traffic.
- _dark_matter_ 12y agoDo you have models for traffic pattern differences between spikes and DDoS attacks? It seems that a DDoS attack would have different patterns (quicker spike, no buildup, etc.). Just speculation here.
- ajessup 12y agoAutoscaler will respond differently to different traffic patterns, but won't go as far as identifying a particular traffic pattern as malicious and refusing to grow resources to accommodate it (most architectures filter malicious requests upstream of the instance itself, eg. at the load balancer or via a proxy). Even if you could identify malicious usage, it's still a matter of policy on how you want to respond to it - given that if it can reach your VM it will likely be affecting legitimate traffic too.
- jbkkd 12y agoWould it be possible in the future to set the thresholds based on time? Say I expect high traffic only during mornings, and not want to handle it during the evening if it occurs. Any chance this is in the making?