Back to articles
Technology Insight

Building a Private CDN to Mitigate Layer 7 DDoS: A Comprehensive Guide Using Apache Traffic Server and CrowdSec

June 2, 2026

Introduction: The Growing Threat of Layer 7 DDoS Attacks

In the modern enterprise landscape, web application availability is directly tied to business continuity. As organizations increasingly rely on cloud infrastructure, they face an evolving threat landscape where Layer 7 (Application Layer) Distributed Denial of Service (DDoS) attacks have become highly sophisticated. Unlike Layer 3 or Layer 4 attacks that attempt to overwhelm network bandwidth, Layer 7 attacks mimic legitimate human traffic. They target specific application endpoints—such as database queries, login portals, or search functions—consuming server CPU and memory resources until the service becomes unresponsive.

While commercial Content Delivery Networks (CDNs) offer mitigation strategies, they often come with high recurring costs, data privacy concerns, and rigid configuration limits. For enterprise architectures requiring granular data sovereignty, custom traffic routing, and cost optimization, a private, self-hosted CDN represents a highly effective alternative. This comprehensive technical guide details how to build an enterprise-grade private CDN utilizing Apache Traffic Server (ATS) for high-performance caching and reverse proxying, integrated with CrowdSec for proactive, behavior-based Layer 7 security filtering.

The Architectural Core: Why Apache Traffic Server and CrowdSec?

Building an effective edge defense network requires two foundational pillars: extreme throughput capabilities and intelligent threat detection. The combination of Apache Traffic Server and CrowdSec creates a powerful synergy that addresses both requirements seamlessly.

Apache Traffic Server (ATS)

Originally developed by Inktomi and Yahoo, Apache Traffic Server is a fast, scalable, and extensible HTTP/HTTPS caching proxy server. It is trusted by major global telecom providers and content providers to handle massive volumes of concurrent traffic. Key advantages of ATS for a private CDN include:

  • Asynchronous Event-Driven Architecture: Utilizing a multi-threaded, non-blocking I/O model, ATS handles tens of thousands of concurrent connections with minimal RAM and CPU overhead.
  • Advanced Cache Management: Its sophisticated hierarchical caching and raw disk storage capabilities ensure that static and dynamic content are delivered at near wire-speed, drastically offloading origin servers.
  • Plugin Extensibility: ATS features a robust C/C++ API allowing developers to intercept, modify, and filter requests at various states of the HTTP transaction lifecycle.

CrowdSec and the CrowdSec Bouncer

Traditional signature-based Web Application Firewalls (WAFs) struggle against sophisticated Layer 7 attacks because malicious requests often appear structurally valid. CrowdSec revolutionizes this paradigm through behavioral analysis and crowdsourced threat intelligence.

CrowdSec reads logs from various components of your stack (such as ATS, system logs, or application logs), parses them using specialized parsers, and runs them against a suite of scenarios. If an IP exhibits malicious behavior—such as HTTP request flooding, aggressive scanning, or credential stuffing—CrowdSec detects it locally. Furthermore, the IP is cross-referenced with a global, decentralized reputation database. The CrowdSec Bouncer acts as the enforcement arm, dropping or challenging malicious connections directly at the CDN edge before they ever reach the application logic.

Step-by-Step Implementation: Deploying the Edge Node

To establish your private CDN edge node, you must first install and configure Apache Traffic Server to act as a reverse proxy, followed by integrating CrowdSec for real-time traffic analysis.

1. Prerequisites and Environment Setup

For optimal performance, it is recommended to provision a Linux server (Ubuntu 22.04 LTS or Debian 12) situated in a geographic region closest to your target user base. Ensure that your firewall permits traffic on ports 80 (HTTP), 443 (HTTPS), and 6062 (the default local API port for CrowdSec).

2. Installing and Configuring Apache Traffic Server

Begin by updating your package manager and installing Apache Traffic Server:

sudo apt-get update
sudo apt-get install trafficserver -y

Once installed, the primary configuration files are located within the /etc/trafficserver/ directory. To configure ATS as a reverse proxy, you must define the mapping between your public edge domains and your backend origin servers in the remap.config file:

# Mapping rule: map incoming public requests to the private origin server
map [https://cdn.yourdomain.com/](https://cdn.yourdomain.com/) [http://origin.internal.local/](http://origin.internal.local/)
map [http://cdn.yourdomain.com/](http://cdn.yourdomain.com/) [http://origin.internal.local/](http://origin.internal.local/)

Next, tune the caching parameters in records.config to ensure the server optimizes resource allocation under heavy traffic conditions. Adjust the thread configurations and enable SSL termination:

# Enable HTTP/2 for reduced latency
CONFIG proxy.config.http.http2.enabled INT 1

# Configure disk cache size (e.g., 20 GB)
CONFIG proxy.config.cache.ram_cache.size INT 2147483648

# Define SSL certificate paths
CONFIG proxy.config.ssl.server.cert.path STRING /etc/trafficserver/ssl/
CONFIG proxy.config.ssl.server.private_key.path STRING /etc/trafficserver/ssl/

Restart the service to apply the modifications: sudo systemctl restart trafficserver.

3. Deploying CrowdSec for Behavioral Analysis

With the caching engine operational, install the CrowdSec Security Engine to begin monitoring traffic patterns. Execute the official installation script:

curl -s [https://install.crowdsec.net/core/crowdsec_setup.sh](https://install.crowdsec.net/core/crowdsec_setup.sh) | sudo sh
sudo apt-get install crowdsec -y

CrowdSec automatically detects installed services, but you must ensure it accurately monitors the Apache Traffic Server log output (typically written to /var/log/trafficserver/squid.blog or custom text logs). Configure the acquisition file /etc/crowdsec/acquis.yaml:

filenames:
  - /var/log/trafficserver/access.log
labels:
  type: apache2
---

Install the specific scenario collections designed to catch Layer 7 DDoS and aggressive scanning attempts:

sudo cscli collections install crowdsecurity/http-cve
sudo cscli collections install crowdsecurity/base-http-scenarios
sudo systemctl reload crowdsec

Integrating the CrowdSec Bouncer with Apache Traffic Server

Detection is only half the battle; remediation must happen instantaneously at the edge. To achieve this, we deploy a CrowdSec Bouncer capable of communicating with Apache Traffic Server.

While CrowdSec offers specialized bouncers for Nginx and HAProxy, an ATS integration can be accomplished using the CrowdSec Lua Bouncer via the ATS Lua plugin, or by employing the CrowdSec Firewall Bouncer (iptables/nftables) directly on the edge host machine. Utilizing the Firewall Bouncer is highly effective for DDoS mitigation, as it drops malicious packets at the network layer before the ATS application layer spends any CPU cycles parsing the HTTP request header.

To install the Firewall Bouncer:

sudo apt-get install crowdsec-firewall-bouncer-iptables -y

The bouncer automatically registers with the local CrowdSec API. When a Layer 7 DDoS scenario is triggered—such as a single IP executing more than 100 requests per second across specific endpoints—CrowdSec instructs the firewall bouncer to drop all incoming packets from that IP for a designated duration (e.g., 4 hours). This immediately neutralizes the threat, preserving the integrity of the ATS caching layer and the backend origin.

Testing and Optimizing the Architecture

To guarantee that your private CDN effectively mitigates Layer 7 attacks without generating false positives for legitimate users, structural verification is necessary.

Simulating a Layer 7 Request Flood

Using an HTTP benchmarking tool like vegeta or wrk from an external testing machine, simulate a low-level application layer flood targeting your CDN endpoint:

echo "GET [https://cdn.yourdomain.com/](https://cdn.yourdomain.com/)" | vegeta attack -rate=150 -duration=10s | vegeta report

Monitor your edge server's reaction in real time. Execute sudo cscli alerts list to confirm that CrowdSec has flagged the testing machine's IP address. Running sudo iptables -L -n -v will verify that the Firewall Bouncer has dynamically injected a rule to block the offending source traffic.

Performance Tuning for Maximum Resilience

To maximize the efficiency of your private CDN under stress, consider the following optimization strategies:

  1. Aggressive Caching Policies: Configure ATS to cache error responses (e.g., 404, 500) for short periods. If an attacker targets non-existent URLs to bypass the cache, ATS will serve a cached 404 response rather than querying the origin server repeatedly.
  2. Keep-Alive Settings: Optimize connection reuse parameters within records.config to reduce the overhead of TCP handshakes during an ongoing surge in volume.
  3. Upstream Rate Limiting: Use ATS plugins to enforce basic connection limits per client IP, providing an initial buffer while CrowdSec processes the logs to perform a definitive block.

Conclusion

Building a private CDN using Apache Traffic Server and CrowdSec gives enterprises total control over their edge security framework. By offloading content delivery to a highly optimized caching engine and pairing it with crowdsourced, behavior-based threat intelligence, you establish a resilient defense mechanism against disruptive Layer 7 DDoS attacks. This architecture not only reduces operational costs associated with commercial network providers but also ensures that your critical web applications remain stable, performant, and secure in an increasingly volatile digital landscape.

Building a Private CDN to Mitigate Layer 7 DDoS: A Comprehensive Guide Using Apache Traffic Server and CrowdSec | DPTCloud