Hi, everyone. Welcome back. I'm Osman Celik from KuppingerCole Analysts.
Today, we are doing again a short but practical conversation on Content Delivery Network, also known as CDNs. What it is, why do you need it, and how it fits into modern security needs. And a quick note before we start, today's videocast is sponsored by Qrator Labs. This is the fourth video we are doing together, and I'm again joined by Andrey Leskin, CTO at Qrator Labs.
Hi, Andrey. Welcome. Hello. Thank you very much for a lovely introduction.
Yeah, it's great to have you again here. For anyone who may not know Qrator Labs yet, this company is around since 2010, and they are known for a cloud-based WAF platform. We worked together in the last years, and I included them in my several research papers, and they offer solutions in the areas like DDoS mitigation, bot protection, DNS protection, and of course, CDN.
Right, Andrey? Yes, it is. All right.
So, as I said in the beginning, let's start with the basics. And then, what do we mean by CDN or Content Acceleration in 2026 terms? Because I think we need to redefine so many things after we start implementing AI everywhere, right?
So, let's talk about CDN in 2026, and when should people think about using a CDN, if it is a must-have or a nice-to-have solution today? What do you think, Andrey?
Well, it is indeed not only nice to have nowadays, it's more or less obligatory, because if you want to compete with different companies, you are mostly dependent on milliseconds. And by milliseconds, I mean how fast your website loads at your customer.
So, content, and here content delivery networks come into place. So, they are mostly geo-distributed systems of caching nodes that serve content from the location closest to the end-users, and this is their main goal.
So, this is a kind of server that sits almost near the end-user and allows him to get your information as fast as possible. Mostly, we are talking about static content, but dynamic can be cached as well with some remarks.
So, the core capabilities of it is HTTP request caching and content prefetching as well. CDN may serve nowadays lots of different purposes. For example, it may compress your data on its own and provide your customers the compression algorithms they support. There are some of them that are quite hard to compute on the server side.
So, if you will do it on your own, your servers might overflow with requests. And as well, CDN nodes, as they serve HTTP traffic, they can filter traffic to some extent.
So, we are talking about rate limiting, geo-balancing, geo-routing, and so on. Yeah, and I also like to frame CDN always like this. It's not just a faster website. I think it also gives the organization a greater stability under the peak times, under load, and also keeping other services reachable. And speaking of other services, I know that your solution, Curator Labs, is often perceived as a web application protection tool or a DDoS protection tool. And how do you position the CDN inside this platform in a broader sense, let's say? What capabilities do you typically bundle under CDN?
Is it a standalone solution? Well, we have a bundle solution.
So, it might look like it is separate products, but it's not, to say the truth. So, by design, CDN networks, if we compare CDN and DDoS mitigation web application firewall, they have a little bit different purpose. The one is security protection. The other one is delivery content. And their goal is somewhat controversial.
So, the CDN has to serve as much as possible without limitations. But CDN nodes has a downside of getting overflown really, really easy. Uh-huh.
So, what we decided to implement is to build CDN network with the security in mind. So, like, it secures CDN from the ground up, not the other way around.
So, first, let's start with CDN and then add some filtration and application firewall to that. That doesn't address the main issue of DDoS attacks, like the traffic overflow, when you have huge, huge attacks that are going to overflow the whole of your network and you have to somehow balance.
So, that's probably it. Yeah, when I was doing my research on the web application firewalls, or in a broader sense, web application and API protection tools, I often see the customers and users mix CDN and DDoS mitigation because they are kind of overlapping in some areas. And I would say that CDN is primarily about delivery and distribution. And DDoS mitigation is about filtering and stopping malicious traffic. And they maybe complement each other in real work. Do you think that this is a fair summary from your end as well?
Well, of course, it is to some extent. There are lots of different details we can address.
So, for example, let's consider the way both of these networks are built and grow. So, for DDoS mitigation network, there is a different placement logic for that.
So, scrubbing centers for DDoS mitigation are at the traffic concentration points, at the backbone of the whole internet. On the other hand, CDN nodes must be closer to the users, to the edge, to the internet exchanges, and it's kind of different flow of traffic. This is slight nuances, but when you're under attack, these nuances grow enormously. And you have to address attack vector that you're encountering at the moment of the attack.
Yeah, speaking of attack vectors, by the way, also in the last couple of months, I was also personally doing a research on the AI's impact on attack vectors. And I think that the landscape is changing drastically, isn't it? And speaking of the attack vectors of today, so what are the biggest advantages of having a CDN in place for customers then? I know that you're working with customers, so could you maybe give us some examples from real life scenarios they have encountered?
Well, if we have CDN network without any like mitigation, high request level mitigation rate limits and so on, that's a huge security issue for it because it can be overflown by malicious botnet with quite an ease. But even if you consider that you have some sort of rate limitation and filtering on the CDN nodes, there are new ways of attack if you have CDN implemented in your network. So for example, as we call it, that's an attack, not on your infrastructure, that's an attack on your wallet. So it works like that. Malicious actor requests lots of traffic that is not cached.
So it's cache miss attack, cache busting attack. So there are different names for that. And it forces CDN nodes to bypass this request to your own infrastructure. And first of all, it might be overwhelmed with the amount of requests. On the other hand, CDNs usually build traffic on their requests so different other or the traffic that are going back and forth from your infrastructure and to the uplink and the back. And you certainly are going to pay for this extra traffic that is going through your infrastructure.
And I think that we just talked about how it differentiates from DDoS protection, but we see an overlapping factor here. Then some of the DDoS attack vectors could be and also an attack factor for the CDN use case. Of course it is. So you can't forget about DDoS attacks as a whole because usually the CDN nodes are located at quite narrow places because they have to be close to the user. If we're not talking about exchanges, but geographically far away nodes are at narrow location traffic wise and they can be easily overwhelmed.
Best scenario is to get rid of this node if it's under attack and serve the traffic from elsewhere. If you have any kind of location near wise or if you have a huge Anycast network that can process all the traffic that we have here.
Yeah, I just also wanted to talk a bit about the technical aspects of this discussion. And could you maybe give us some examples of this attack factors like maybe an HTTP float or something like this? What could be the top five attack vectors that you encounter?
Well, let's divide them into two groups. The first one is the volumetric and network wise. These are the attacks that you have like authentication attacks, scene flood attacks, like X flood attacks. So we're talking about network level, not your HTTP request on level seven on the OC model. But here you have usually a huge amount of bandwidth, not a request, just bandwidth. And with this huge force, normal force, your servers or even your uplinks get overwhelmed and your customers can't reach you. The other group that we need to address are their level seven attacks.
So these are application level attacks. So yeah, if we're, if we are going to like brute force, these are HTTP floods that you mentioned, different kind of slow low risk attacks. When you have, when you have HTTP requests going like drop by drop, they like, as a result, they overflow your amount of connection and your servers and servers that they drown of these connections. Moving forward, there is your application with its own vulnerabilities.
So for example, if you have a very heavy loaded request, for example, search over your database, the malicious actor may just call this endpoint multiple times and thus render your server unavailable. So these are like the most basic ones. There are more of them, quite a lot of them. But the deeper we go, the upper we go on the OC level and your application, the more specific and more tailored attacks are required to perform. The application layer, right? Yes.
All right, so I think that the customers would like to know this kind of details because they are the ones facing those attacks in their daily life and we are the one trying to help them overcome it, right? And yeah, so speaking of the customers again, then they should see some value when they are purchasing, procuring a solution, right? And if I'm a security or infrastructure leader, or if I'm the CISO of a company, when evaluating CDN, what benefits I should expect from such solutions?
Well, if you're a CISO of the company, your main concern is the security. So let's mention the business aspect of the CDN. So this is the content delivery speed. So you can get your images as fast as possible to your customer. So this is like what CDN networks are built for. The next kind of positive impact on your infrastructure is that you reduce load on your backbone. So you have many, many requests that are settled outside of your network on the CDN nodes.
And just a part of this request goes into your infrastructure and in fact, we do know a couple of companies that can't handle the amount of requests that they have across all the infrastructure with our CDN networks. So as you grow, that might be an issue that you have to consider and you have to like diversify your CDN risks and maybe get some additional providers for the service. Next thing, let's get back to security. And security-wise, CDN nodes are like the nodes that serve HTTP traffic.
And you can set up different filter rules, for example, rate limit rules, or you can even fingerprint your customers and get some data from your customer's machine and mitigate, for example, malicious botnets and the ones that are not going to overwhelm your traffic, but maybe some scrapers and so on and so forth. So you can address this issue as well on the CDN. But you have to consider security-wise that how this CDN infrastructure is built. So for example, we have CDN with the security bolt on.
This is completely different when we have a security company that incorporated security as a base design under infrastructure. So that's how we built our CDN. So first we have a security core, mitigation core of the network, and then we add additional CDN nodes with security in mind at first place. And what we are going to do if this node becomes unavailable due to some cosmic reasons.
Yeah, and also speaking of, again, the customer's value proposition, I think that some, especially some SMBs would like to see the impact of a solution immediately or right after they acquire or procure it. Let's say if a customer's starting from scratch, what is the first practical steps for them to follow? What should they monitor? What should they measure in the first days, first weeks, so that they see that the CDN is delivering value? Just really short, just a short answer. The short answer would be you have to monitor your round trip time.
So this is the time the packets reach, the packets from customers reach the nearest node that you have on your website. The second one is time to render. So the amount of time that your website is, like from start of load to the finish loading of the web page and the customer sees everything. So these are basically two that are the major ones that you have to consider. And I think that with this question, I think we covered most of the fundamental questions, right? For a customer who are interested in having a CDN solution or start with their organization CDN journey.
Any final reminders or notes for our audience? Be like aware of your infrastructure and address the risks that you have.
All right, correct. Then this was again a very helpful and informative discussion for me, Andrej, as always. And thank you for keeping it short and practical and simple for our audience. And thanks to Curator Labs again for sponsoring today's video cast and making it possible for everyone out there, our audience and to everyone watching it. This video, if you enjoy this format, I think that we will continue doing this with the Curator Labs if time allows, of course.
And please like, subscribe and share it with your colleagues, this video, with the colleagues who might be interested in this context, of course. And we will be back soon, hopefully with another short session. Until then, take care. Thank you very much. Bye-bye. Bye-bye.