TR7 Add-ons — specialized capability modules that plug into the bundles.

PREMIUM ADD-ON

L7 DDoS Protection

Adaptive defense that understands application-layer attacks by behavior and answers with the right action.

Application-layer attacks rarely look like obvious attacks. HTTP floods, Slowloris, low-and-slow, credential stuffing, and targeted API attacks can behave like valid HTTP requests. The traffic is protocol-compliant — but it drains the application's resources, hammers the login screen, chokes API endpoints, or slows the real user experience.

TR7 L7 DDoS Protection doesn't just watch a requests-per-second threshold. For every vService, it observes traffic behavior: connection rate, request rate, path density, error rate, session behavior, IP reputation, bot score, and application response are evaluated together.

Not every high-volume burst is an attack, and not every low-rate stream is safe. TR7 analyzes the behavior; based on the attack pattern, it applies the right action — deny, rate-limit, redirect, controlled content, or local CAPTCHA.

Watch the behavior, not just the speed.

L7 DDoS Protection separates application-layer attacks more accurately using per-service traffic profiles, combined conditions, and adaptive actions. The goal is not just to stop the attack, but to keep the application running while protecting the real user.

PROTECTION LAYERS

Three-Layer Adaptive Defense for the Application Layer

L7 DDoS Protection combines behavioral analysis, per-service thresholds, and adaptive actions. That approach catches attacks that damage the application while looking protocol-compliant — more accurately than a single static threshold can.

Behavioral Scoring Engine

The attack decision is not made on a single metric. TR7 evaluates several signals at once to understand whether traffic is normal, suspicious, or an attack.

  • Request rate, connection count, session length, and request/response behavior monitored together
  • Path density, HTTP method distribution, and body size behavior evaluated
  • IP reputation, internal lists, and a dynamic risk score used as signals
  • Bot score and behavioral fingerprint included in attack detection
  • Rising 4xx and 5xx error rate tracked as an early attack signal

Per-Service Adaptive Threshold

Every application has different normal traffic. A login page, an API endpoint, a payment screen, and a static content service can't be protected by the same threshold. TR7 builds a separate traffic profile for every vService.

  • Separate baseline-learning model per vService
  • With Smart Learning, the system first learns the normal traffic, then proposes a policy
  • The operator can review, approve, or adjust the proposal
  • Thresholds can be retuned as the traffic profile changes over time
  • Combined conditions enable more precise attack policies in AND/OR/NOT logic

Adaptive Action

Not every attack gets the same answer. An obvious attack can be blocked; suspicious traffic can be slowed; a client thought to be a bot can be sent to CAPTCHA. The goal is to stop the attack without putting unnecessary friction in front of real users.

  • Deny — hard block on clear attack signals
  • Rate-limit — speed limiting when specific conditions are met
  • Redirect — steering traffic into a controlled or restricted flow
  • Controlled content — neutralizing the attacker without revealing the response
  • Local CAPTCHA — human/bot separation without a third-party SaaS
ARCHITECTURE

Runs in the Same Policy Chain as TR7 WAAP

L7 DDoS Protection is not a separate appliance, separate service, or separate cloud layer. It is a premium protection layer that runs on TR7 WAAP. Application security, bot management, API protection, and L7 DDoS defense unify under the same policy chain.

  • Runs on TR7 WAAP — no separate L7 DDoS appliance or cloud service required
  • Smart Learning and combined conditions give the operator applicable policy recommendations
  • Actions are defined inside the TR7 policy language — one UI, one operating model
  • Bot-management score and API attack context can be included as L7 DDoS decision signals
  • Attack events can be streamed to SIEM
  • Which attack pattern was answered with which action can be reported
  • Local CAPTCHA is part of the TR7 platform; a third-party CAPTCHA SaaS is not required
USE-CASE SCENARIOS

4 Critical Battlefields Where L7 DDoS Protection Steps In

L7 DDoS Protection delivers value in application-layer attacks that are hard to separate with classic rate limits or static WAF rules.

Slowloris and low-and-slow attacks

Scenario

The attacker opens many connections and trickles data into each, draining server resources. Because requests-per-second stays low, a classic rate threshold catches the attack late.

Solution

TR7 evaluates abnormal session length, low request/response ratio, and growing active-connection behavior together. The attack traffic is filtered or rate-limited; the application's connection pool is preserved.

Credential stuffing and login attacks

Scenario

The attacker distributes stolen username/password pairs to the login screen from a wide IP pool. Because each IP stays at a low rate, the attack is hard to separate with rate-limit alone.

Solution

TR7 evaluates login-path density, rising 4xx errors, IP reputation, bot score, and distributed-source behavior together. Suspicious traffic is sent to CAPTCHA or rate-limit; an obvious attack is blocked.

Bot-driven API attack

Scenario

Automation or an AI-assisted bot sends API requests at human-like rates. A single IP or a single speed signal may not clearly indicate the attack.

Solution

TR7 analyzes bot score, behavioral fingerprint, path density, and API usage pattern together. Suspicious clients can be moved into rate-limit, CAPTCHA, or block.

Campaign-day traffic surge

Scenario

Environments like e-commerce, ticketing, or application portals see traffic climb very quickly. Static thresholds can either block real users or fail to separate the attack.

Solution

TR7 evaluates expected peak periods more accurately with per-service baselines. Real user traffic is preserved while bot, scraping, or attack traffic is separated.

CAPACITY OPTIONS

Licensed by vService Count

L7 DDoS Protection is licensed by the number of vServices to be protected. It scales from small deployments to multi-application enterprise environments and service-provider scenarios.

Included with the Bundle — No Add-on Needed
7 vServices
Included with every ADC license
Adaptive L7 DDoS protection ships with every ADC license at standard limits.
7 vServices
Included with every WAAP license
Adaptive L7 DDoS protection ships with every WAAP license at standard limits.

Every ADC and WAAP license ships baseline adaptive L7 DDoS protection for a standard number of vServices. For broader scope, the capacity tiers below take over.

1
vService
10
vServices
25
vServices
100
vServices
1000
vServices
Unlimited
Protection

For PAYG customers, L7 DDoS Protection can be delivered with L4 DDoS and L7 Reporting capabilities together as part of the PAYG Extra Pack.

COMPLIANCE

A Strong Layer for Service Continuity, Account Security, and Application Protection

L7 DDoS Protection provides a strong additional security layer for service continuity, account security, blocking automated attacks, and auditable incident records on sensitive web applications.

GDPR Article 32

Supports technical measures for service continuity and data security on systems that process personal data. Protects against account takeover and automated attack waves.

SOX & Financial-System Audit

Provides defense against application-layer attacks and event traceability for online banking, customer portals, and financial applications.

Financial-System Abuse Protection

Adds a behavioral protection layer against automated attempts, bots, and abuse aimed at financial transaction systems.

PCI DSS 4.0.1

Provides additional defense against automated attack waves, bot traffic, and application-layer abuse on systems that access the cardholder data environment.

LICENSING

Premium Add-on — Expanded L7 DDoS Scope

L7 DDoS Protection is available as a Premium add-on for all four TR7 bundles (Base, Geo, Secure, and Enterprise). Behavioral analysis, per-service baselines, combined conditions, adaptive actions, rate-limit, and local CAPTCHA are included in the add-on scope.

  • Attaches to all four bundles — Base, Geo, Secure, and Enterprise
  • Runs on a hardware appliance or a virtual machine
  • Works integrated with TR7 WAAP, bot management, and API protection layers
  • Central Management can standardize policy and visibility across multi-region environments
  • Local CAPTCHA is included — a third-party CAPTCHA SaaS is not required

Stop Application-Layer Attacks by Behavior

Let's walk through an L7 DDoS Protection demo against your own scenario: which vServices will be protected, which traffic behavior counts as normal, which actions will be applied, and how the integration with WAAP policies will work.

Licensing Guide