BLUEPRINT #06Production Case Studies
Design a Resilient Bot Defense & Sybil-Resistant Registration Architecture — Production Case Study
Referenced Architecture Primitives (8)
Click any primitive to study its algorithmic deep dive#02Distributed Rate Limiting#03Bloom Filters & Counting Filters#14API Gateway & Reverse Proxy#25Bot Defense, Sybil Resistance & Registration Abuse#26Honeypot Fields & Canary Traps#27Disposable Email & Domain Blocklists#28Cloudflare Turnstile & Managed Challenges#29Google reCAPTCHA v2 & Enterprise Risk Analysis
10-Stage Structure:1. Requirements→2. Sizing→3. Topology→4. Data Model→5. AWS Topology→6. Deep-Dive→7. Failures→8. SRE Playbooks
1. Problem Statement & Mission
System Mission
Design the ingress protection and anti-abuse architecture for a high-growth developer platform (e.g. AI algorithmic mastery & coding sandbox, cloud compute provider, or developer API) offering free compute coins upon signup and referral bonuses () per colleague invited.
The system must withstand coordinated bot attacks generating up to 500,000 automated registration attempts per hour, eliminate compute token farming, protect email sender reputation on Amazon SES (), and preserve zero-friction onboarding for legitimate software engineers.
Functional Requirements
- Frictionless Human Registration: Legitimate engineers must sign up in without solving visual puzzles or image captchas.
- Automated Bot Interception: Intercept and neutralize headless browser clusters (Playwright, Puppeteer, Selenium), residential proxy networks, and disposable email pools.
- Sybil-Resistant Referral Qualification: Referrer rewards unlock only when referred accounts complete authentic platform engagement milestones.
- Email Reputation Protection: Prevent mass email bombing through email verification throttles and throwaway inbox filtering.
Non-Functional Requirements (SLAs & SLOs)
- Edge Latency Overhead: for legitimate users at the edge layer.
- False Positive Rate: (legitimate engineers must never be falsely blocked).
- High Availability: uptime for the authentication and registration service.
2. Capacity & Scale Estimation (Back-of-the-Envelope Math)
Attack Surge Volume
- Peak Attack Rate: .
- Legitimate Peak Traffic: .
- Peak Ingress Load during Surge: directed at
/api/auth/signup.
Database & Cache Sizing
- Active IP / Subnet Rate Limits in Redis:
- Track active IPs over a 15-minute sliding window.
- .
- Each Redis sliding window key (Sorted Set of timestamps): .
- Memory Required: (negligible footprint for ElastiCache
cache.t4g.microor Redis cluster).
- Disposable Email Domain Bloom Filter:
- disposable domains with false positive probability.
- Memory: (in-memory, sub-millisecond lookup).
Part 2: Production Deep-Dive Locked1 Coin = 24 Hours
Unlock Complete Architecture & Production Runbooks
Your Balance:40 Coins
You have explored the free architectural preview (~37%). Spend 1 Coin to unlock the remaining 3 production deep-dive sections for a full 24 hours.
Sections Included in This 24-Hour Pass:
3. End-to-End System Architecture
4. Detailed Component Implementation
5. Summary of Key Architectural Decisions
Keeps page unlocked for exactly 24 hoursSpend coins to fund LLM & compute infrastructure