Detect and Defend a Government Portal Against Application-Layer DDoS
Overview
What this challenge is about.
Detect and Defend a Government Portal Against Application-Layer DDoS. Advanced challenge in design. Designing real products under real constraints, earn a bl...
The Brief
What you'll do, and what you'll demonstrate.
The portal cannot reliably tell an attacker's application-layer flood apart from a legitimate announcement-day traffic surge in time to respond before citizens are locked out.
This is not a design exercise. It is the work a product designer does between a brief and a shipped interface. That distinction matters to every hiring manager who has seen candidates redesign Spotify's homepage and none who have worked under real product constraints.
When you finish, you will have something most graduates do not: a real-world deliverable, verified by Ewance, that you can show to a hiring manager and say "I did this. Here is the proof."
Earning criteria — what you'll demonstrate
- Distinguish application-layer DDoS patterns from legitimate traffic surges using real log signals
- Author Sigma detection rules tuned for high recall on attacks and low false positives on baseline traffic
- Design a layered, reversible WAF and Shield Advanced response that an on-call engineer can execute under pressure
- Run a tabletop exercise that converts a simulated incident into prioritized, owned remediation actions
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Ddos Defense
Apply ddos defense to solve real industry problems and demonstrate production-level capability.
- Detection Engineering
Apply detection engineering to solve real industry problems and demonstrate production-level capability.
- Waf
Apply waf to solve real industry problems and demonstrate production-level capability.
- Incident Response
Apply incident response to solve real industry problems and demonstrate production-level capability.
- Siem
Apply siem to solve real industry problems and demonstrate production-level capability.
- Protocol Security
Apply protocol security to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Detection Engineer
This challenge mirrors the core detection-engineering loop: turn real attack telemetry into tuned, portable rules and validate them against baseline traffic. You leave with a Sigma rule library and tuning rationale that demonstrate you can build coverage without drowning the SIEM in false positives.
This challenge sharpens
- detection-engineering
- siem
- ddos-defense
Incident Response Engineer
You produce and pressure-test an on-call runbook through a tabletop exercise, exactly as an incident responder must. The sequenced, reversible response design and the gap-to-owner output show you can lead a team through a live availability crisis calmly.
This challenge sharpens
- incident-response
- ddos-defense
- waf
Cloud Security Engineer
Designing layered defenses across CloudFront, WAF, and Shield Advanced for a real AWS architecture is the daily work of a cloud security engineer. You bridge edge protection, traffic analysis, and protocol-level detection into one coherent, operable stack.
This challenge sharpens
- waf
- protocol-security
- detection-engineering