Schedule icon
Webhook icon
Script icon
Process icon
Query icon
If icon
SlackIncomingWebhook icon
Log icon

ClickHouse Real-Time API Rate Limit and Abuse Guard

Detect API spikes and bot attacks with sliding-window Z-score analysis in ClickHouse. Generate quarantine manifests and alert SecOps in Slack.

Categories
CoreDataInfrastructureinfrastructure

Modern web APIs and SaaS backends are vulnerable to sudden volumetric floods, credential stuffing attacks, and aggressive web scraping. Traditional static rate-limiters (such as fixed leaky-bucket limits) either fail to detect distributed slow-burn attacks or accidentally throttle legitimate enterprise customers during normal promotional spikes.

Detecting sophisticated abuse requires evaluating traffic dynamically: computing population averages, error ratios, and standard scores (Z-scores) across sliding 10-minute micro-batches.

This blueprint implements a real-time API abuse and volumetric anomaly guard. Ingested API gateway request logs are analyzed using high-performance columnar analytical queries (compatible with ClickHouse and in-memory DuckDB). The workflow computes client-level request velocity, measures error rates on authentication endpoints, and calculates statistical Z-scores against population baselines. When an IP exceeds the anomaly threshold, Kestra automatically compiles a quarantine_ips.csv blocklist manifest, generates an incident brief, and alerts security teams in Slack.

How it works

  1. generate_mock_traffic_batch (scripts.python.Script): Generates realistic gateway request logs containing normal background activity across distributed subnets and an injected credential stuffing attack against /api/v1/auth/login.
  2. analyze_sliding_window_anomalies (jdbc.duckdb.Query): Executes an embedded columnar query calculating mean request volume, standard deviation, and Z-scores per IP to identify statistical outliers.
  3. enforce_quarantine_gate (core.flow.If):
    • Anomaly Detected (Abusive Count > 0): Generates api-abuse-quarantine-brief.md and quarantine_ips.csv for firewall ingestion, dispatching an alert card to #security-ops in Slack.
    • Nominal State: Logs normal traffic metrics without triggering alerts or modifying blocklists.
  4. alert_on_failure (errors block): Catches unexpected query or processing failures and notifies the SecOps engineering channel.
  5. Triggers: Scheduled 5-minute sliding-window sweep (disabled: true by default) plus an authenticated Webhook trigger for API gateway log shipping.

What you get

  • Dynamic statistical abuse detection adapting to legitimate traffic scaling.
  • Automated WAF blocklist generation with configurable quarantine TTLs.
  • Zero external database footprint when running with embedded DuckDB.

Who it's for

  • Security Operations (SecOps), Platform Security, and SRE teams.
  • API Gateway and Reverse Proxy Engineers (Kong, Envoy, Cloudflare, Traefik).
  • Application Security (AppSec) teams defending login and checkout endpoints.

Why orchestrate this with Kestra

Hardcoding rate-limit logic inside gateway Lua scripts or edge workers causes latency spikes and lacks centralized audit trails. Kestra provides declarative DAG orchestration, decoupled asynchronous log analysis, artifact persistence, and native Slack escalations.

Prerequisites

  • API gateway or load balancer shipping request access logs.
  • Slack incoming webhook endpoint for security alerts.

Secrets

  • SLACK_WEBHOOK_URL: Slack Incoming Webhook URL for security ops channels.
  • WEBHOOK_KEY: Authentication secret for event-driven webhook invocation.

Quick start

  1. Set SLACK_WEBHOOK_URL and WEBHOOK_KEY in your Kestra namespace secrets.
  2. Click Execute in the Kestra UI to run the blueprint with default simulated traffic.
  3. Download quarantine_ips.csv from the Outputs tab and review the Slack notification.

How to extend

  • Connect io.kestra.plugin.core.http.Request tasks inside enforce_quarantine_gate to push the generated blocklist directly to Cloudflare IP Access Rules or AWS WAF IP sets.
  • Point analyze_sliding_window_anomalies to a live ClickHouse cluster using io.kestra.plugin.jdbc.clickhouse.Query for billion-row log processing.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.