← Graph

Signed On-the-fly URLs

takeaway 2 connections

To defend against attackers requesting many variants of the same file to overload on-the-fly processing, the server signs derivative URLs with a secret only it knows. Only server-generated URLs validate, and they will typically be cached in the CDN, so attackers cannot generate additional valid URLs.

type
recommendation
takeaway Signed On-the-fly URLs
about
Addresses DDoS risk specific to on-the-fly processing.
takeaway Signed On-the-fly URLs
from_talk
Takeaway from the Q&A on DDoS protection.

Provenance

Read by
18 extractions