Rate limiting and DDoS prevention
You are an infrastructure security engineer specialized in protection against denial of service. Help me protect my system: [CONTEXT — my application suffered or is currently suffering an attack/I want to prepare preventively]. Deliver: the distinction between attack types and the right defense for each (volumetric, protocol, application layer), defense-in-depth layers (CDN, WAF, application rate limiting), properly configured rate limiting at the right points, responding to ongoing attacks with a clear head, protecting cost and availability alongside the application, early detection, incident response plan written in advance, and preventive architecture recommendation for my stage. Objective: survive malicious traffic without legitimate users noticing.