---
title: "Prevent HTTP DDoS With Cloudflare - Black Friday DDoS Defense Notes"
description: "A real-world account of an e-commerce site responding to DDoS attacks during Black Friday, showing how to configure allowlists, blocklists, country challenges, and rate limiting in Cloudflare WAF for successful defense."
canonical_url: "https://blog.markkulab.net/en/post/prevent-ddos-part2-20221128"
author: "Mark Ku"
author_url: "https://blog.markkulab.net/en/author/mark-ku"
site: "Mark Ku's Tech Notes"
date_published: "2022-11-28 01:01:01 +0800"
category: "Security"
tags: ["ddos", "cloudflare", "waf", "security", "black friday", "ecommerce", "firewall"]
language: "en"
license: "CC BY 4.0"
license_url: "https://creativecommons.org/licenses/by/4.0/"
attribution: "when reusing or quoting, credit the author and link back to the original"
---

# Prevent HTTP DDoS With Cloudflare - Black Friday DDoS Defense Notes

## Background
I currently work at an e-commerce company whose products mainly serve the US, Germany, and Canada. A few days before Black Friday, we noticed that the site was constantly being hit by DDoS attacks. One day the site went down completely, which is when we started a deeper investigation.

[I previously wrote an article](https://blog.markkulab.net/2022/01/16/prevent-ddos/) on DDoS defense concepts. This post applies those defense rules in Cloudflare WAF.

### Reviewing Cloudflare's security report, on the 12th we received roughly 20 million malicious requests targeting our site.
![Cloudflare Firewall Events dashboard with DDoS traffic by country and time graph](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/nANZAqj.png)  
![Cloudflare WAF report detailing 21.44 million requests, 8.52 million](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/pmtPE3Z.png)

### At the time many questions came to mind. Why would a single IP make such a huge volume of requests?
![UI showing top IP addresses by malicious request count](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/ZZcMKIn.png)

### And why are there so many countries we don't even operate in sending heavy traffic to our site?
![Cloudflare dashboard table of top threat countries and request counts](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/fd3Hjn1.png)

### Although we use the Enterprise tier of Cloudflare, the default settings - while blocking most DDoS - still let some attacks slip through given the sheer volume. I spent a lot of time learning Cloudflare, reviewed every setting, discussed with my boss, and then put together a DDoS prevention plan using Web Application Firewall rules to protect our business during Black Friday, with our US boss's approval.
![Cloudflare DDoS prevention rules for festival and last resort scenarios](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/Gd5SfbS.png)

### To avoid false positives that hurt the business, we only blocked single IPs making excessive requests. Below is the block screen.
![Mobile display of Cloudflare Access denied error 1020 block page](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/DhNvfeN.png)

### To avoid false positives, before adding an IP to the blocklist we look it up and report it on [abuseipdb](https://www.abuseipdb.com/check/34.121.210.98).
![AbuseIPDB report for IP 34.121.210.9](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/m3kgWmU.png)

### For other rules, to avoid false positives that affect orders, we only enable human verification. Users must pass it before entering the site.
![Mobile screen showing hCaptcha human verification security check](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/icKvFKYl.png)

![Mobile CAPTCHA challenge to select hot air balloons from a grid](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/ZrxS5ZUl.png)

## Now let's start creating WAF rules - Create Firewall rules
### Go to Cloudflare admin > Security > WAF > Create firewall rule
![Cloudflare WAF firewall rules page with Create firewall rule button emphasized](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/W9JrIh1.png)

#### Rule 1. Allowlist - White List
![Cloudflare WAF rule editor showing allowlist for known and verified bots](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/jCN1Q5Q.png)

#### Rule 2. Blocklist - IP Block (attacker)
![Cloudflare WAF editor showing IP Block attacker rule blocking source IPs](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/CggFyEH.png)

#### Rule 3. Country challenge
![Cloudflare WAF rule challenging traffic from specific countries](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/CnZ7q6V.png)

#### Rule 4. IP Challenge (suspicious)
![Cloudflare WAF editing an IP Challenge rule for suspicious IPs](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/4dMWWvS.png)

#### Rule 99. Bot challenge - Automated (last resort)
![Cloudflare WAF rule editor configuring bot score and country conditions](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/b8SdAzv.png)

#### Rule 99. Likely automated challenge (last resort)
![Cloudflare WAF editing a Likely automated firewall rule](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/1PDyWAK.png)

#### Rule 99. Request rate limit (last resort)
![Cloudflare WAF editing rate limiting rule for DDoS defense](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/7yXmDJ1.png)

#### Rule 100. Only allow operating countries - Non-operating country
![Cloudflare WAF rule blocking traffic not from Canada, Germany, US](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/ktMCQCe.png)

#### You can also tune DDoS sensitivity (Security > Settings > DDoS > Configure > Security Level > Medium)
![Cloudflare dashboard showing DDoS L7 ruleset configuration with medium sensitivi](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/QfPWICC.png)

#### If nothing else holds, you can turn on "I'm Under Attack" mode. All users wait five seconds before entering the site. Remember to switch it back when done. Security > Settings > DDoS > Configure > Security Level > Enable I'm Under Attack mode
![Cloudflare security settings with I'm Under Attack mode enabled](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/jOQpWzY.png)

## Effectiveness
Across Thanksgiving and Black Friday (three days), we faced 7 DDoS attacks totaling more than 13 million malicious requests, with the highest single burst hitting 3 million requests at once. After the fifth attack the site stalled for about 30 seconds. The reports showed the attack pattern shift from concentrated IPs and countries to small, dispersed traffic. We finally decided to leverage Cloudflare's machine-learning-based rules. Without hurting the business, only single IPs sending massive request volumes were outright blocked, while everything else was sent to human verification. We made it through this year's Black Friday smoothly. It was a pretty intense Black Friday - many external services also experienced anomalies.

### A total of 13.63 million requests received
![Cloudflare dashboard showing Black Friday firewall events and DDoS defense](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/RZijw3y.png)

### WAF helped block over 5 million requests
![Cloudflare WAF rules table showing activity and challenges](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/yLnNpgS.png)

### Bot analytics report
![Security bot analytics dashboard showing requests by score over time](https://blog.markkulab.net/content/markku/posts/prevent-ddos-part2-20221128/images/q9OEuh6.png)

---

## About this article and its author

Originally published on [Mark Ku's Tech Notes](https://blog.markkulab.net/en/post/prevent-ddos-part2-20221128)

License: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/) — when reusing or quoting, credit the author and link back to the original

### About the author

**[Mark Ku](https://blog.markkulab.net/en/author/mark-ku)** — Software Solution Provider

- 10+ years senior software engineer, now an AI Builder
- Focused on large-platform architecture — North-American e-commerce, AI SaaS subscription billing
- Combining AI Agents and automation to build evolvable product foundations

### Free tools built by the author

All of these are free to use:

- [Free PDF Sign Tool](https://blog.markkulab.net/en/tools/pdf-sign): Online PDF sign tool — draw, type, or upload a signature, then drag, resize, and download. Everything runs in your browser; nothing is uploaded.
- [VS Code Refactory](https://blog.markkulab.net/en/tools/refactory): Refactory is a VS Code refactoring extension: 34 actions plus a 37-rule code-smell inspection layer with a Code Health dashboard, across 18 languages, backed by 534 tests. It learns your repo's conventions: where interfaces live, where DI is registered, whether 'use client' belongs. It ranks files by git churn × complexity so you know what to fix first, and hands any smell to the Claude Code already on your machine. Free to use, and your source never leaves your computer.
- [DB-Kit Database Manager](https://blog.markkulab.net/en/tools/db-kit): DB-Kit is a lightweight, cross-platform database manager built with Tauri + Rust + React. Manage MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, MongoDB, Redis, Kafka, Elasticsearch and RabbitMQ from one consistent interface: passwords encrypted in the OS keychain, SSH tunnels, full CRUD, a visual query builder, stacked multi-statement result sets, cross-connection data transfer and compare/sync, Excel / CSV import & export, visualized execution plans, ER diagrams, scheduled backups, SQL stress testing with p50–p99 latency percentiles, a 15-rule SQL review engine, Kafka message browsing with monitoring & alerts, a bilingual UI (Traditional Chinese / English), a built-in AI assistant (natural-language SQL, AI review and tuning advice) and the dbk CLI. Free and open source (MIT), with installers for Windows, macOS and Linux.
- [VS Code Super Mermaid](https://blog.markkulab.net/en/tools/super-mermaid): Super Mermaid is a VS Code extension for beautiful Mermaid diagrams out of the box: auto-colored live preview, mouse pan & zoom, high-res PNG / SVG export, 21 templates and multiple themes. Free and open source (MIT).
- [React Super Mermaid](https://blog.markkulab.net/en/tools/react-super-mermaid): react-super-mermaid is an open-source React component library: render beautiful Mermaid diagrams with a single <MermaidViewer>, with built-in colorful / sketch themes, pan & zoom, in-diagram search, and high-res SVG / PNG export. Lightweight, SSR-safe, fully typed. Free and open source (MIT).
- [Jira / Confluence Super Mermaid](https://blog.markkulab.net/en/tools/jira-super-mermaid): An Atlassian Forge app: write Mermaid syntax directly inside a Jira issue or a Confluence page and get flowcharts, sequence diagrams, state machines and Gantt charts. 11 diagram types, SVG / PNG export, light and dark themes, full CJK support. Runs on Atlassian: your diagrams live in your own site and the app calls no third-party service. Free, coming soon to the Atlassian Marketplace.
- [Mermaid Live Preview](https://blog.markkulab.net/en/tools/mermaid-preview): Write Mermaid in your browser, see it render instantly, and share the whole diagram as a single link. No sign-up, nothing uploaded to a server, and mermaid.live share links work as-is.
- [React Intl Phone Number](https://blog.markkulab.net/en/tools/react-intl-phone-number): react-intl-phone-number is an open-source React component: framework-agnostic and antd-free, with E.164 in/out, a searchable flag / country-code dropdown, configurable validation levels (strict / mobile-strict / loose), themeable CSS, and i18n — phone logic powered by google-libphonenumber. Lightweight and fully typed. Free and open source (MIT).
- [Uptime Kuma Cluster](https://blog.markkulab.net/en/tools/uptime-kuma-cluster): Turn single-node Uptime Kuma into a highly available cluster: OpenResty + Lua smart load balancing, shared MariaDB state, health checks and automatic failover, plus cluster-management REST APIs. One Docker Compose command to start. Free and open source (MIT).
- [Special Education](https://blog.markkulab.net/en/education): Learning materials crafted for special education students

### Daily podcasts

- [Mark's Tech Insights — Daily AI News](https://blog.markkulab.net/en/category/tech-news): Daily curated AI and tech trends. Catch the latest developments via audio summaries — covering AI applications, software architecture, DevOps, and engineering practice. — RSS: https://blog.markkulab.net/feed.xml
- [AI股市蝦聊](https://blog.markkulab.net/en/category/ai-stock-chat): Every trading day, an AI-analyzed take on the Taiwan stock market, delivered as a two-host conversation covering the session and the next-day outlook. — RSS: https://blog.markkulab.net/ai-stock-chat/feed.xml
- [開源好物週報](https://blog.markkulab.net/en/category/open-source-weekly): A weekly two-host pick of free open-source tools surfaced from real Hacker News, GitHub, and Reddit buzz — what pain they solve and the fastest way to get started. — RSS: https://blog.markkulab.net/open-source-weekly/feed.xml

### Newsletter

[Subscribe to the newsletter](https://blog.markkulab.net/en/subscribe) — Be the first to know about new posts. No spam, unsubscribe anytime.
