Edge Computing with Cloudflare Workers & Deno · Lekcja

Ograniczanie przepustowości i ochrona przed DDoS

Skonfiguruj ograniczanie przepustowości i wykorzystaj funkcje bezpieczeństwa Cloudflare do ochrony przed nadużyciami i atakami DDoS

Lekcja 2 z 410 kroki

Ograniczanie przepustowości i ochrona przed DDoS to bezpłatna lekcja Edge Computing with Cloudflare Workers & Deno na CoddyKit. To lekcja 2 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej Edge Computing with Cloudflare Workers & Deno, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs Edge Computing with Cloudflare Workers & Deno zawiera 4 lekcji w sumie.

Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.

Edge Security: Rate Limiting & DDoS

Protecting your edge applications is crucial. In this lesson, we'll explore two powerful security mechanisms: Rate Limiting and DDoS Protection.

These features help keep your applications stable, secure, and available, even under heavy load or malicious attacks.

Why Rate Limit?

Rate limiting controls how many requests a user or IP address can make to your application within a specific timeframe. It's like a bouncer, ensuring fair access and preventing abuse.

  • Prevent Abuse: Stops bots and malicious actors from scraping data or brute-forcing logins.
  • Protect Resources: Reduces strain on your serverless functions and databases.
  • Control Costs: Limits excessive usage that could lead to higher billing.

Cloudflare's Rate Limiting Power

Cloudflare offers robust, configurable rate limiting directly at the edge. This means requests are evaluated and potentially blocked before they even reach your Worker or origin server.

You can define rules based on various criteria like URL path, HTTP method, IP address, and even custom headers.

Defining Your Rate Limiting Rules

When setting up a rate limit, you typically define:

  • Threshold: The maximum number of requests allowed (e.g., 100 requests).
  • Period: The time window over which the threshold applies (e.g., 60 seconds).
  • Action: What happens when the limit is exceeded (e.g., block, challenge, or log).
  • Matching Criteria: Which requests the rule applies to (e.g., specific URL, method).

Practical Rate Limit Example

Imagine you want to protect your login endpoint from brute-force attacks. You could set a rule like this:

If: 10 requests to "/api/login"
From: The same IP address
Within: 60 seconds
Then: Block the IP for 5 minutes

This simple rule significantly enhances your application's security against common threats.

Understanding DDoS Attacks

A Distributed Denial of Service (DDoS) attack aims to overwhelm your application or server with a flood of traffic, making it unavailable to legitimate users.

Unlike simple rate limiting, DDoS attacks often come from many different sources (a "botnet"), making them harder to defend against manually.

Cloudflare's DDoS Shield

Cloudflare provides always-on DDoS protection that automatically detects and mitigates attacks across its global network. This happens transparently, often without you needing to configure anything specific.

It works by analyzing traffic patterns, identifying malicious requests, and filtering them out before they reach your infrastructure.

Cloudflare Security Levels

Cloudflare offers different security levels you can adjust for your domain, impacting how aggressively it challenges suspicious traffic:

  • Essentially Off: Minimal protection.
  • Low: Challenges the most threatening visitors.
  • Medium: Challenges moderate threat visitors.
  • High: Challenges all visitors that have previously exhibited threatening behavior.
  • I'm Under Attack!: Challenges all visitors to mitigate advanced DDoS attacks.

Edge Security Check

Consider the following scenarios. Which security measure is best suited to address each?

Recap: Securing Your Edge

You've learned how Rate Limiting prevents abuse and resource exhaustion from individual sources, while DDoS Protection shields your application from large-scale, coordinated attacks.

Leveraging Cloudflare's edge capabilities for these features means your applications are more resilient, performant, and secure right where they need to be.

Bezpłatny start

Ucz się Edge Computing with Cloudflare Workers & Deno dzięki korepetycjom AI — za darmo

Pisz i uruchamiaj kod w przeglądarce, otrzymuj natychmiastową pomoc od korepetytora AI dostępnego 24/7 i kontynuuj naukę w sieci lub w aplikacji.

Kursy
12
Lekcje
47

Często zadawane pytania

Czy lekcja „Ograniczanie przepustowości i ochrona przed DDoS” jest bezpłatna?

Tak — pełny tekst „Ograniczanie przepustowości i ochrona przed DDoS” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu Edge Computing with Cloudflare Workers & Deno, przejdź na CoddyKit PRO. Kurs Edge Computing with Cloudflare Workers & Deno zawiera 4 lekcji w sumie.

Co nauczysz się w „Ograniczanie przepustowości i ochrona przed DDoS”?

Skonfiguruj ograniczanie przepustowości i wykorzystaj funkcje bezpieczeństwa Cloudflare do ochrony przed nadużyciami i atakami DDoS Ćwiczysz Edge Computing with Cloudflare Workers & Deno z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.

Czy potrzebuję doświadczenia, aby zacząć Edge Computing with Cloudflare Workers & Deno?

Nie wymagamy żadnego doświadczenia. Edge Computing with Cloudflare Workers & Deno w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 2 z 4.

Ile czasu zajmuje lekcja „Ograniczanie przepustowości i ochrona przed DDoS”?

Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.

Czy mogę pisać i uruchamiać kod w tej lekcji Edge Computing with Cloudflare Workers & Deno?

Tak. Każda lekcja Edge Computing with Cloudflare Workers & Deno zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.

Wszystkie lekcje w tym kursie

  1. Uwierzytelnianie i autoryzacja
  2. Ograniczanie przepustowości i ochrona przed DDoS
  3. Bezpieczne zarządzanie sekretami
  4. Sanityzacja danych wejściowych i zapobieganie injection
← Powrót do Edge Computing with Cloudflare Workers & Deno