A retail website is hit with a high-volume Layer 7 HTTP request flood. The traffic is intercepted by an Anycast network (e.g. Cloudflare) that rate-limits suspicious request spikes and triggers CAPTCHA challenges, ensuring genuine traffic reaches the servers.
// Example: Express API Gateway Rate Limiter Config
import rateLimit from 'express-rate-limit';
export const apiLimiter = rateLimit({
windowMs: 15 * 60 * 1000, // 15 minutes window
max: 100, // Limit each IP to 100 requests per window
message: {
error: 'Too many requests from this IP, please try again after 15 minutes.'
},
standardHeaders: true, // Return rate limit info in standard headers
legacyHeaders: false, // Disable older X-RateLimit headers
});Visual representation of control loops, memory layout, and execution flow for Network Security: Firewalls, WAF, HTTPS & DDoS Mitigation.
Block all network ports except essential ones (e.g., 80/443), and route management traffic (SSH) via VPN/Bastion hosts.
Establish an encrypted tunnel using cryptographic certificates and key exchanges (Diffie-Hellman).
Deploy a Web Application Firewall (WAF) to inspect Layer 7 HTTP payloads for malicious patterns.
Distribute incoming network traffic using Anycast routing and block volumetric flood packets at the network edge.
| Feature / Dimension | Traditional Firewall (Layer 3/4) | Web Application Firewall (WAF - Layer 7) |
|---|---|---|
| OSI Layer | Operates at Layer 3 (Network) and Layer 4 (Transport) | Operates at Layer 7 (Application Layer) |
| Inspection Focus | Inspects IP addresses, port numbers, and protocol types | Inspects HTTP headers, URL parameters, cookie contents, and payloads |
| Primary Protection | Prevents unauthorized port access (e.g. blocking DB port 5432) | Blocks SQL injection, XSS payloads, file uploads, and web scraping |
Detailed answers, interviewer pro tips, key takeaway summaries, and code examples formulated for technical rounds.
✅ Correction: HTTPS only encrypts data in transit to prevent sniffing. If the backend code has SQLi or XSS vulnerabilities, they can still be exploited over an encrypted HTTPS connection.
✅ Correction: Keep database servers on private subnets. Access them only through localized VPN, bastion tunnels, or security group authorization rules.
Core mechanisms protecting data transmission paths and service availability.