I've read the full blog post, I am not convinced it's a DDoS attack. Traffic patterns for web analytics will come from over the place and will look like a DDoS when it's not. For example, a customer misplacing their analytics in a JS loop and having a moderate traffic blog will generate billions of requests from all over the globe. Event tracking can be billions of requests as well by themselves. Never attribute to malice that which is adequately explained by simpler means.
> * With zero access logs, there was no way to find patterns in the attack, and we had no way to block it
It's a loss of time and energy. Your system should be able to handle these billions of requests.
> * We were then able to identify a pattern and block the attack on Saturday
Was it specific accounts?
> * Without access logs (even redacted ones), this wasn't possible
You can one-way hash the IP. So you can still look for pattern but you've lost the actual IP. And same one-way hash IP can block whichever IP seems devious in your firewall. (like md5 can be enough.)
> But if you know a more privacy-focused way to block these attacks, I'm sure I'll buy you a few beers when we hang out.
Haha no need to. But come say hi if you ever in Austin. julien _at_ serpapi.com.