Reference library
Akamai Security Products — In-Depth Technical Reference
A working engineer's reference to the Akamai edge security portfolio — how each product detects, decides and mitigates — combined with the protocol and DDoS fundamentals you need to reason about the traffic those products see.
How to read this library
The library is organised in three layers. Products describe what Akamai ships and how the engines actually make decisions. Engines (API Security, Behavioral DDoS) go one level deeper into detection scope, learning windows and tuning levers. Fundamentals cover the protocols and attack classes that the products exist to defend, so that a finding in a report can be traced back to a packet or a request.
App & API Protector
Adaptive Security Engine, WAF rule groups, rate & slow-POST controls, client reputation, penalty box, match targets and policy evaluation order.
API Security
The four pillars in depth: Discovery, Posture, Runtime Detection & Response, and Testing — plus Recon, Learning timelines, obfuscation modes and source-code scanning.
Behavioral DDoS Engine
Hostname-centric ML baselining, 12 profiles per hostname, sensitivity levels, exceptions and rollout methodology.
Prolexic
Network-layer DDoS scrubbing: BGP and GRE routing, flowspec, always-on vs on-demand, zero-second SLA.
Edge DNS & DNS Security
Authoritative anycast DNS, DNSSEC, zone apex, DNS flood defence, protective DNS and recursive filtering.
Account Protector
User & population risk scoring, account takeover, credential stuffing, MFA-fatigue and account-opening abuse.
Content Protector
Scraper detection, protocol/application/user-behaviour/browser-fingerprint evaluations and risk-tiered responses.
Client-Side Protection & Compliance
Script inventory and behaviour, Magecart/formjacking defence, PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1.
AI Bots & Agentic Security
Agentic Security Framework, AI crawler visibility, monetization signals and Web Bot Auth.
Core Concepts
DNS resolution, server types, IP addressing, UDP, TCP/IP, HTTP/1.1 vs 2 vs 3, HTTPS, mixed content.
DDoS Attack Encyclopedia
L3/L4 and L7 attacks: SYN, UDP, DNS, ACK, QUIC floods, HTTP floods, amplification and IP spoofing.
Zero Trust
Never trust, always verify: principles, microsegmentation, least privilege, ZTNA versus VPN.
Where each product sits in the stack
OSI layer Threat Akamai control
--------------- ------------------------------------ -------------------------------------
L3/L4 network SYN/UDP/ACK floods, amplification, Prolexic (BGP/GRE scrubbing),
reflection, IP fragmentation Edge platform absorption
L4 DNS DNS flood, NXDOMAIN, water torture Edge DNS (anycast), DNS Shield,
Protective/Recursive DNS
L7 web HTTP flood, injection, RCE, LFI App & API Protector (ASE + WAF)
L7 behavioural Low-and-slow DDoS, brute force, Behavioral DDoS Engine, Rate Controls,
parameter fuzzing Slow POST protection
L7 automation Credential stuffing, scraping, Bot Manager, Account Protector,
inventory hoarding, AI crawlers Content Protector
L7 API Shadow APIs, BOLA/BFLA, data leakage API Security (Discovery/Posture/
Runtime/Testing)
Browser Magecart, formjacking, skimming Client-Side Protection & Compliance
Cross-cutting design principles
1. Detect at the edge, decide with context
Every Akamai security product runs on the same distributed edge platform, so decisions are made in the first millisecond of the request, close to the client, before the origin ever sees traffic. What differs between products is the context each engine adds: reputation history (Client Reputation), behavioural baselines (BDE), API schema knowledge (API Security), or population-level identity signals (Account Protector).
2. Scope your counting narrowly, scope your mitigation narrowly
The single largest cause of false-positive pain is a mitigation scope that is wider than the detection scope. Rate Controls historically counted per client identifier across an entire security policy; BDE deliberately narrows both counting and mitigation to HTTP method + hostname + path. Narrow scope means a misclassification affects one endpoint for ten minutes rather than an entire property.
3. Learn before you enforce
Behavioural systems — BDE, API Security Learning, Account Protector user risk — all require a clean traffic window before their output is trustworthy. Enabling mitigation during learning produces noise and destroys stakeholder confidence. The consistent guidance across products is: alert mode first, 7–14 days of clean traffic, review reports, tune, then enforce.
4. Feed the models clean data
Baselines learn from what reaches them. If bot traffic, scrapers and credential-stuffing noise are merely monitored rather than blocked, the baseline absorbs that noise as “normal”. Tuning Bot Manager, Client Reputation and the WAF into blocking mode is therefore not optional hygiene — it is a prerequisite for accurate behavioural detection.
5. Obfuscate sensitive data at capture time
API Security hashes sensitive values with a salt before they are stored, so investigators can correlate the same value across incidents without ever seeing it. The same philosophy shows up in Account Protector (identity signals are hashed) and Client-Side Protection (script behaviour is recorded, not user data).
Quick glossary
| Term | Meaning |
|---|---|
| ASE | Adaptive Security Engine — the scoring detection engine inside App & API Protector. |
| Match target | The set of hostnames/paths/file extensions that binds a security policy to traffic. |
| Penalty box | A temporary (10 minute) deny state applied to a client identifier after a trigger. |
| Client identifier | The key used for counting: IP, IP+User-Agent, or a bot/session cookie. |
| DAN table | Akamai's internal table of commonly observed, benign TLS fingerprints / clients. |
| Consumer | In API Security, a distinct API caller identity (token, key, user) used for learning thresholds. |
| CT log | Certificate Transparency log — public record of issued TLS certificates, used for passive subdomain discovery. |
| WSA | Web Security Analytics — the analytics surface used to validate triggers and hunt false positives. |