Slide 18 of 28
Part 4 · PreventionSlide 18
PART 4
Prevention
Slides 18–26 · Seven mitigations + the full picture
Slide 18 · Prevention Overview
Seven ways to fix unrestricted resource consumption.
Limits on frequency. Limits on size. Limits on cost. Monitoring when limits are hit.
⏱️
MIT 01 — Rate Limiting
Enforce a maximum number of requests per client per time window. Per user, per IP, per API key.
📏
MIT 02 — Maximum Page Size
Server-enforced cap on paginated results. Client asks for 999999 — server returns max 100. Ignore the rest.
📦
MIT 03 — Payload Size Limits
Reject uploads and request bodies above a defined size. Prevents memory exhaustion from oversized input.
MIT 04 — Execution Timeouts
Kill long-running requests after a timeout. Prevents connections from being held indefinitely by slow queries or large operations.
🧩
MIT 05 — GraphQL Query Complexity Limits
Restrict nesting depth and total field count in GraphQL queries. One deeply nested query can generate thousands of database calls.
💰
MIT 06 — Cost-Based Throttling
Per-user quotas on expensive third-party operations: AI calls, SMS sends, video encoding. Separate limit from request rate.
🚨
MIT 07 — Anomaly Monitoring & Alerting
Alert when consumption patterns deviate significantly from baseline. Catch scraping and abuse before the full damage is done.
← Back MIT 01: Rate limiting →