Imagine your service being down due to a DDoS attack while your WAF blocks legitimate users. We build ML systems that adapt to attackers in real time. This article breaks down how we distinguish bots from humans by behavior and shows the code of a detector that differentiates HTTP flood from normal traffic. We use machine learning for traffic classification—this allows detecting even complex L7 attacks mimicking real users. We have delivered 12+ projects in fintech, e-commerce, and gaming; each traffic pattern is unique, and each system adapts to its specifics. Our certified engineers guarantee a reduction of false positives to 2% and reliable protection based on years of experience.
How ML Classification Distinguishes Bots from Humans
L7 attacks differ from legitimate traffic in behavior. ML features fall into three groups:
Request-level
- Request rate (req/s per IP/subnet)
- URL distribution (attack hits one endpoint, users hit various)
- User-Agent diversity (attack has limited set, humans have variety)
- Referer patterns
- HTTP method distribution
Session-level
- Session duration (bots are short or intentionally long for Slowloris)
- Page flow (bots don't follow normal navigation)
- JavaScript execution (headless browsers detected via Canvas fingerprint)
IP-level
- ASN distribution (attacks from datacenters vs. residential)
- Geographic distribution vs. typical traffic
- New vs. known IPs
- Request timing distribution
class L7DDoSDetector: def __init__(self, window_seconds=60): self.window = window_seconds self.model = ort.InferenceSession("ddos_detector.onnx") def score_ip(self, ip: str, traffic_stats: dict) -> float: features = [ traffic_stats['req_per_sec'], traffic_stats['unique_urls_ratio'], traffic_stats['user_agent_entropy'], traffic_stats['session_duration_avg'], traffic_stats['asn_risk_score'], traffic_stats['is_new_ip'], traffic_stats['req_timing_cv'] ] score = self.model.run(None, {"features": [features]})[0][0] return float(score) Why Adaptive Defense Is More Effective Than Static Rules
Attacks change in real time when they encounter mitigation. Static rules lag behind. An adaptive system operates cyclically:
- Detection of attack onset (anomaly in traffic patterns)
- Classification of attack type
- Selection of mitigation strategy (rate limit / challenge / block)
- Monitoring mitigation effectiveness
- Automatic adjustment if bypassed
For advanced scenarios, we use reinforcement learning—but this requires a traffic simulator to safely train policies.
Integration with Infrastructure
WAF (Web Application Firewall). ModSecurity + Nginx: dynamic rule addition via API upon attack detection. IP blocklist updates through nftables in <100ms.
CDN. Cloudflare Workers / Akamai EdgeWorkers: ML scoring at the edge, no traffic to origin.
BGP Flowspec. For volumetric attacks: automatic Flowspec rule announcement via BIRD or ExaBGP for null-routing attack traffic at the AS level. BGP Flowspec allows flexible traffic filtering without changing router configurations.
Scrubbing center. Integration with traffic scrubbing centers for network-level filtering is possible.
Practical Case: HTTP Flood on a Gaming Project
Attack details
Online game with 50,000 active players. HTTP flood: 280,000 req/sec against a norm of 12,000 req/sec. Botnet of 14,000 residential IPs. Mimics real users: random URLs, diverse User-Agents.| Parameter | Value |
|---|---|
| Attack | HTTP flood 280,000 req/sec |
| Botnet | 14,000 residential IPs |
| Detection time | 90 seconds |
| Neutralization time | 3 minutes |
| Affected legitimate users | 2.1% |
ML detector:
- Identified the attack by URL distribution pattern (focus on /api/leaderboard)
- Discovered behavioral fingerprint: bot request interval CV=0.04 (uniform), player CV=0.8+
- Activated challenge (proof-of-work) for suspicious sessions
- Legitimate players passed challenge via JS, bots did not
Comparison of Mitigation Strategies
| Strategy | Reaction Time | User Impact | Applicability |
|---|---|---|---|
| Rate limiting | <1 min | 5–10% false positives | All L7 attacks |
| Challenge (proof-of-work) | 2–3 min | <1% false positives | HTTP flood, slow attacks |
| BGP Flowspec | 1–2 min | 0% (network level) | Volumetric attacks > 100 Gbps |
What the Work Includes
We deliver turnkey:
- Analysis of your project's normal traffic and extraction of a representative sample
- Development of an ML detector with architecture selection (XGBoost, LightGBM, or neural network)
- Integration with WAF (ModSecurity, nginx, Cloudflare) and CDN via API
- Load testing and threshold calibration
- Operational documentation and team training
Monitoring and Attack History
Every attack provides data to improve the model. We log: type, vectors, duration, mitigation effectiveness. Quarterly retraining on new attacks. We participate in industry feeds (Shadowserver, Team Cymru) for IP reputation enrichment.
Timelines: 2–4 weeks for an L7 ML detector integrated with an existing WAF, 8–14 weeks for an adaptive system with automatic mitigation and BGP integration. We will assess your scenario—contact us for a consultation. Reduction in cloud resource costs after implementation reaches 40%. Order implementation, and your infrastructure will gain protection that learns along with attacks. Get a consultation on your scenario—we guarantee an individual approach.







