LiveShield Public API: Automating Anti-DDoS Protection in Operator Processes

LiveShield Public API: Automating Anti-DDoS Protection in Operator Processes


The Public API is an open LiveShield interface that lets an operator build anti-DDoS protection into its own business processes. New services and customers can be brought under protection automatically, without manual work in the administration panel.

What does the Public API give an operator in an anti-DDoS system?


The Public API allows protection settings to be managed from systems the operator already uses. Protection stops being a separate administrative task and becomes part of standard customer handling.

From a business perspective, this means:

  • Scalability - the number of protected customers can grow without a proportional increase in the technical team's workload.
  • Repeatability - every customer receives a configuration based on the same approved patterns.
  • Lower risk of errors - a configuration prepared by an automated process does not depend on manual data entry.
  • Consistency with company processes - anti-DDoS protection can be launched together with service activation instead of as a separate request.
Which processes in a telecommunications company can be improved?

The API most often supports customer service, network maintenance and configuration quality oversight. The documentation gives "Customer provisioning" as an example integration, meaning automatic protection of new customers.

Practical uses:

  • Launching protection together with the service - a new customer is brought under protection as part of the standard activation process.
  • Uniform protection packages - templates define protection levels that the operator can offer as part of its portfolio.
  • Control and audit - data on prefixes, profiles and BGP routers can be retrieved for reporting and compliance reviews.
  • Integration with the existing environment - the API is built on standard solutions (HTTP, JSON, OpenAPI), so it works with tools the team already knows.
Attack notifications are still handled by Event Pipelines. The Public API is responsible for configuration, while Event Pipelines handle event notifications.

How does LiveShield keep control over configuration changes?


Changes made through the API do not reach the protection automatically. They wait for approval. This is a separate step that leaves the timing of deployment to the operator and allows an internal approval process.

Approval requires a separate permission. An integration can therefore prepare the configuration, while a designated person or another controlled process handles its deployment. Before approval, you can check what is in the change queue.

Note that approval covers all pending changes, including those made in the panel or by other integrations.

How is access to the API secured?


Access is based on tokens created only by the Administrator, with permissions granted individually. This gives each integration access only to what it needs.

Rules that organize access management:

  • each token has a name, a scope of permissions and an optional expiry date,
  • the full token is shown only once, at creation,
  • a token can be revoked at any time, which immediately cuts off the integration,
  • the panel shows the permission scope of each token and the time of its last use.
API tokens work independently of panel user permissions. Disabling an employee's access does not revoke their integration, so the token list must be reviewed separately when organizational changes occur.

Which resources can be managed through the API and which are read-only?


The API allows full management of prefixes and prefix templates: creating, reading, editing and deleting. These are the areas that change most often as the customer portfolio changes.

Advanced Filtering profiles, Blackholing profiles, BGP routers (used to deploy FlowSpec rules and blackholing) and Event Pipelines are available as read-only. Manual Rules are not available through the API. Elements that matter more for the protection architecture remain under the team's control in the Manager panel.

Changes to detection thresholds and related settings require submitting the complete dataset rather than individual corrections. The integration should be designed to first retrieve the current configuration and only then modify it.

How do you start using the Public API in LiveShield?


The Public API is part of LiveShield Manager and works with Analyser version 1.3.1 or newer. Launching an integration comes down to a few organizational decisions and one step on the Administrator's side.

Recommended sequence:

  1. Decide which processes will use the API and what scope of permissions they need.
  2. Create a token with the minimum required permissions and set its expiry date.
  3. Use the built-in Swagger documentation and OpenAPI specification, available on your own Manager at /api/v1/docs and /api/v1/openapi.json.
  4. Assign panel users access to prefixes, profiles, templates and pipelines according to the team structure.
  5. Decide who approves changes and in which process.
The full interface description is available in the documentation: https://docs.liveshield.net/publicapi.html

Summary


The LiveShield Public API lets you build DDoS protection into an operator's daily processes while keeping control over permissions and change approval. For companies expanding their security offering, it is a way to scale protection without increasing the burden on the technical team.

More information: office@liveshield.net

Don't wait for the next DDoS attack.
Contact us today!

Please check filled in fields for errors. If problem persists, contact us directly at office@liveshield.net

Thank you for reaching out to us!

Your message has been successfully sent.
We will get back to you as soon as possible.

Or call us directly

(+48) 880 779 307