DDoS Protection Readiness: Charting the Shift in Attack Patterns
Distributed denial-of-service (DDoS) attacks now span a wide spectrum of sizes, durations, and levels of persistence, making protection a core requirement for nearly any online operation. For security and risk management professionals evaluating defenses, the key differentiators tend to come down to network capacity, management capabilities, global reach, alerting, and reporting. A recent Gartner report, "Solution Comparison for DDoS Cloud Scrubbing Centers" (ID G00467346), assesses leading vendors against 23 criteria, with Cloudflare earning more "High" ratings than the six other DDoS vendors in the comparison.
The reality of the threat landscape is that the economics of launching an attack have shifted considerably. The low cost of entry has fueled a marked increase in network-level attacks smaller than 10 Gbps—a size still large enough to take down a significant portion of the websites operating today.

That is not to suggest the threat of large volumetric events has diminished. In March 2020 alone, Cloudflare observed numerous attacks exceeding 300 Gbps, with the largest peaked at 550 Gbps. Gartner echoes this observation in its findings, stating, "In speaking with the vendors for this research, Gartner discovered a consistent theme: Clients are experiencing more frequent smaller attacks versus larger volumetric attacks." The report goes on to note, "For enterprises with Internet connections up to and exceeding 10 Gbps, frequent but short attacks up to 10 Gbps are still quite disruptive without DDoS protection. Attacks over 500 Gbps are still common."
Application-layer attacks present a different kind of complexity. One HTTP DDoS attack mitigated by Cloudflare involved a peak of 1.4M requests per second—not rate-intensive by volumetric standards, but notable because all 1.1M source IPs were unique and legitimate. Each IP was an actual client able to complete full TCP and HTTPS handshakes, making the attack difficult to filter based on connection legitimacy.

Evaluating Architectural and Operational Requirements
When assessing DDoS mitigation options, Gartner recommends that organizations "choose a provider that offers scrubbing capacity of three times the largest documented volumetric attack on your continent." Beyond sheer scrubbing volume, the architectural approach matters in an environment where attacks originate from millions of distributed IPs rather than a handful of botnets.
A provider that can mitigate threats at the edge—closer to the source—offers advantages over traditional centralized scrubbing centers that require traffic hauling. With full mitigation capabilities deployed across 200 cities, Cloudflare claims more points of presence than the six leading DDoS vendors combined. The company's automated, edge-based enforcement aims to keep typical time-to-mitigation under 10 seconds.
Cloudflare highlights several operational attributes of its DDoS solution:
- Network capacity: Over 35 Tbps of capacity, which Cloudflare contends is roughly equivalent to the total scrubbing power of the six other major DDoS vendors combined.
- Integration: DDoS protection is designed to work alongside other services like WAF, Bot Management, and CDN, requiring no tradeoff between security and performance.
- Predictable pricing: Unlimited and unmetered DDoS mitigation, a model that avoids the "surge pricing" that can hit businesses during an attack.
DDoS protection is included across all Cloudflare service tiers. Enterprise-level plans add advanced mitigation controls, detailed reporting, enriched logs, and productivity features, along with direct access to dedicated customer success and solution engineering resources.



