Purpose
This demonstration visualizes how cyberattacks evolve and how the Akamai Edge Platform protects applications before malicious traffic reaches the customer's infrastructure. The simulation progressively introduces increasingly sophisticated attack techniques and shows how additional Akamai security capabilities mitigate each one.
How to use the demo
- Click CLOSE to return to the map.
- The simulation starts automatically and advances through seven attack phases.
- Watch the animated traffic paths: red represents malicious traffic, blue represents legitimate traffic, and Akamai Edge PoPs appear once protection is deployed.
- Read the left-hand event panel to understand the attacker's action and Akamai's response.
- Use the live ticker underneath it to see requests being passed, blocked, challenged, or denied.
- Click PAUSE SIM when you want to stop on a phase and explain it. Click RESUME SIM to continue.
- Click RESTART at any time to replay the complete scenario from the beginning.
- Click HOW TO USE in the top-right corner to reopen this guide.
Walkthrough
Phase 1 – Direct DoS Attack
- The origin server is directly exposed to the Internet.
- Attack traffic reaches the application without protection.
- The origin begins to saturate, showing how traditional infrastructure can be overwhelmed by volumetric attacks.
Phase 2 – Akamai Edge Platform
- The application is placed behind the Akamai Edge Platform.
- Traffic is routed through the nearest Akamai Edge Point of Presence.
- Threat intelligence and Client Reputation identify malicious sources before they reach the customer infrastructure.
Phase 3 – Distributed DDoS
- The attacker launches a distributed attack from multiple global locations.
- Akamai absorbs traffic across its distributed network and applies Adaptive Rate Control while legitimate users continue to access the application.
Phase 4 – Bot Attack
- The attacker switches to residential botnets designed to imitate real users.
- Akamai Bot Manager analyzes behavioral telemetry and challenges suspicious clients without disrupting legitimate traffic.
Phase 5 – Web Application Exploitation
- The attacker attempts SQL Injection after failing to disrupt availability.
- Akamai Adaptive Security Engine detects and blocks malicious payloads before they reach the application.
Phase 6 – API Abuse
- The attacker targets APIs and probes for unauthorized access and BOLA vulnerabilities.
- API Security discovers APIs, detects abnormal behavior, and blocks malicious requests before they reach backend services.
Phase 7 – AI Protection
- The attacker targets the AI application with prompt injection attempts.
- Akamai Firewall for AI detects jailbreak attempts and prevents malicious prompts from compromising the LLM or exposing sensitive data.
Key message: Every new attack vector requires a different layer of protection. Akamai provides these capabilities across the same globally distributed edge network, stopping attacks before they affect the origin while preserving legitimate user traffic.