Can you elaborate on Fastly exposing the origin servers to DDoS? Is there a link to learn more about that?
From there you can force requests to hit the origin server by first purging the data from the cache and then requesting it.
Unrelated to DDoS I've also seen issues with the Fastly routing- it doesn't always pick the greatest end node to have a client connect to.
[1] https://stackoverflow.com/questions/26898052/how-to-force-im...