AWS Architecture Blog

Ben "Fuzzy" Shonaldmann

Author: Ben "Fuzzy" Shonaldmann

Ben "Fuzzy" Shonaldmann (he/him) is a software engineer with a decade of experience architecting, building, scaling, and securing new products. In addition to a background in industry and startups, he has worked on Democratic and progressive campaigns, voter engagement nonprofits, and political technology vendors.

How Scale to Win uses AWS WAF to block DDoS events

In this post, you’ll learn how Scale to Win configured their network topology and AWS WAF to protect against DDoS events that reached peaks of over 2 million requests per second during the 2024 US presidential election campaign season. The post details how they implemented comprehensive DDoS protection by segmenting human and machine traffic, using tiered rate limits with CAPTCHA, and preventing CAPTCHA token reuse through AWS WAF Bot Control.