Network Protection

2 minute read

Protecting the perimeter and the pipes: DDoS, WAF, segmentation, and the VPN→Zero-Trust evolution.

DDoS — Distributed Denial of Service

Attackers flood you from many sources; the target is availability.

Layer Attack Mitigation
L3/L4 (volumetric) UDP/SYN floods — saturate bandwidth Anycast scrubbing (Cloudflare, Cloud Armor), provider absorbs it
L4 (state exhaustion) connection-table floods SYN cookies, conn limits
L7 (application) expensive endpoints hammered (“HTTP flood”) WAF + rate limiting + autoscaling + caching

You cannot absorb a volumetric DDoS yourself — it’s an upstream bandwidth problem; that’s why scrubbing services exist. L7 attacks are your problem: rate limits, CAPTCHAs, caching, cheap 404/401 responses.

WAF — Web Application Firewall

Inspects L7 traffic for attack signatures (SQLi, XSS, path traversal) before the app sees it — Cloudflare WAF, AWS WAF, ModSecurity.

  • Managed rulesets (OWASP CRS) + custom rules (geo, bot, rate)
  • It’s a compensating control, not the fix — false positives happen, bypasses happen; patch the vuln, use the WAF for coverage/response time
  • Virtual patching: block exploit of a known CVE while the fix ships

Network Segmentation

Internet ──> LB ──> public subnet ──> app subnet ──> data subnet
                        │               │               │
                   WAF/IDS        no public IPs    DB: no ingress
                                                 except app subnet
  • Private subnets, no public IPs on backends/databases
  • Firewall rules deny by default; allow only required flows
  • Blast-radius control: a compromised web tier can’t reach the DB directly without the app-tier hop
  • mTLS between services so network location isn’t the only check

VPN vs Zero Trust / IAP

Traditional perimeter model (VPN): authenticate once at the boundary, then the internal network is flat and trusted — “hard shell, soft center.” Lateral movement after breach is the classic failure.

Zero Trust model: never trust, always verify — every request is authenticated and authorized regardless of network location.

VPN:       user ──> VPN gateway ──> "inside" = broad network access

Zero Trust user ──> IAP/IdP check (identity + MFA + device + policy)
    :                 ──> only the specific app/VM requested

Google’s BeyondCorp pioneered this; Identity-Aware Proxy (IAP) is the GCP implementation — per-request auth, IAM-checked, backend stays private, no VPN needed. Full flow in SSO.

Benefits: least-privilege by default, auditable per-request decisions, works for remote workforce, blast radius is one app not the network.

Malicious-code & supply-chain protection

  • Dependency scanning (SCA), pinned versions, artifact signing
  • Sandbox/egress-limit untrusted code paths
  • EDR/CSPM at runtime for detection since prevention is never complete

DRM — Digital Rights Management

Content-protection layer (licensed decryption keys + attested playback): Widevine (Android/Chrome), FairPlay (Apple), PlayReady. Worth knowing exists for streaming design; encrypting the stream ≠ controlling playback.