logo
Introducing the Application Delivery Top 10

Introducing the Application Delivery Top 10

Tahawul Tech31-01-2025
Lori MacVittie, F5 Distinguished Engineer, discusses the top challenges organisations encounter on their journey to deliver and secure every application and API, anywhere.
There are a lot of 'top 10' lists in the industry. Predictions, mostly, but the ones that stick are the ones that provide insight into the top challenges faced by organisations trying to deliver and secure applications and APIs.
Well, to be fair, most of the best-known top 10 lists are about security.
The Open Worldwide Application Security Project (OWASP) has built and maintained several lists that help organizations every day keep their applications, APIs, and now LLMs, secure from the incredibly robust array of attacks that threaten to disrupt business.
But no one to date has a top 10 list of challenges that threaten the delivery of applications, APIs, and, yes, generative AI.
Until now.
Application delivery may have started with the simple—but powerful—load balancing proxy, but it has evolved along with applications to incorporate a wide array of capabilities designed to ensure availability, enhance performance, and secure the increasingly important digital assets that power today's Internet economy.
F5 has been there through every major application shift since the early days of the Internet. We've seen it all through the eyes of our customers. From that experience we've come to understand the most common challenges organisations face—and how to solve them.
Based on that, we decided it was time to share that knowledge. And, thus, was born the Application Delivery Top 10.
The Application Delivery Top 10 is a list of the top 10 challenges organisations encounter on their journey to deliver and secure every application and API, anywhere.
It is our belief that sharing such a list will enable organisations to address—or even better, avoid struggling with—the challenges of delivering and securing a hybrid, multicloud application and API portfolio.
Like the OWASP Top 10, this list is not designed to be a 'one and done' effort or encompass every delivery challenge organisations will face.
That's why we plan to reexamine the list and, if necessary, update it on an annual basis.
Weak DNS Practices
The Domain Name System (DNS) is a critical component of the internet's infrastructure, translating domain names into IP addresses to route user requests to the appropriate servers. However, weak DNS practices can compromise application performance, availability, and scalability.
It can also significantly degrade application performance by increasing query response times and causing delays in resolving domain names. When Time-to-Live (TTL) settings – numerical values that indicate how long a data packet or record should exist on a network before it is discarded – are too low, DNS queries must be resolved more frequently. This increases the load on DNS servers and slows down application response time.
Additionally, improperly configured DNS servers or the lack of DNS security features like DNS Security Extensions (DNSSEC) can introduce delays by allowing unauthorized users to hijack or redirect traffic to slower or malicious servers.
Weak DNS practices can severely impact the performance, availability, scalability, and operational efficiency of applications. However, by implementing DNSSEC, optimising TTL settings, and securing dynamic DNS updates, organisations can mitigate these risks and create a more reliable DNS infrastructure.
Lack of Fault Tolerance and Resilience
The lack of fault tolerance and resilience in application delivery strategies can lead to significant performance issues, reduced availability, and scalability limitations. By implementing load balancing, failover mechanisms, and programmable infrastructure, organisations can create a more resilient system that supports continuous availability and optimal performance, even under challenging conditions. Emphasizing fault tolerance enhances user experience, reduces operational overhead and supports efficient scalability, ensuring that applications can meet the demands of today's fast-paced digital environment.
Incomplete Observability
Observability is a critical aspect of modern application delivery, providing visibility into the health, performance, and usage of applications and infrastructure.
Poor visibility becomes particularly problematic in complex environments, such as AI-driven applications, where real-time insights are essential.
Ultimately, incomplete observability in application delivery can lead to performance degradation, reduced availability, limited scalability, and operational inefficiencies. By implementing comprehensive monitoring and logging, adopting standardised observability with OpenTelemetry, and utilizing dynamic alerting with automated responses, organisations can overcome these challenges.
Insufficient Traffic Controls
Effective traffic management is essential for delivering a seamless user experience, particularly as applications scale to support larger audiences and more dynamic workloads. However, insufficient traffic controls can lead to issues like overloading backend services, susceptibility to Distributed Denial of Service (DDoS) attacks, and inefficient resource usage.
By implementing rate limiting, throttling, and caching mechanisms, organisations can manage traffic more effectively, prevent service disruptions, and support scalable growth.
Emphasising robust traffic management practices is essential for delivering high-performance, resilient applications that can adapt to changing user demands and provide a consistent experience across diverse environments.
Unoptimised Traffic Steering
Unoptimised traffic steering—caused by static routing policies, lack of dynamic decision-making, or insufficient load-balancing algorithms—can lead to performance bottlenecks, inconsistent availability, and limited scalability.
In AI-driven applications, where processing needs can vary based on data types and user demand, efficient traffic steering is essential for maintaining responsiveness.
By adopting best practices such as dynamic routing, intelligent load balancing, and programmable ADCs, organisations can optimize traffic flows, improve resource utilisation, and ensure that applications meet variable demand.
Inability to Handle Latency
Latency is a key factor affecting application delivery, particularly in data-intensive environments like AI applications. The inability to handle latency effectively can lead to performance issues, reduced availability, and limited scalability, especially as applications grow and user demands fluctuate. Latency bottlenecks result from various issues, such as suboptimal data routing, inefficient processing, and inadequate resource allocation.
By implementing optimized data routing, edge computing, and adaptive resource allocation, organisations can mitigate latency challenges and support a high-performance, resilient infrastructure.
Incompatible Delivery Policies
In hybrid multicloud environments, incompatible delivery policies can pose significant challenges to application performance, availability, scalability. It can also lead to soaring operational overheads. Incompatibilities of this nature often arise when organisations use multiple cloud providers, each with unique traffic routing, security, and data handling protocols.
According to LoadView, a leading cloud-based load testing platform, applications with inconsistent delivery policies across multiple regions experience 50% more latency in cross-border data transfers than those with region-specific optimisations.
By standardising metrics, aligning service capabilities, and leveraging programmable infrastructure, organisations can overcome these challenges.
Emphasising consistency and flexibility in delivery policies ensures that applications can maintain high performance, availability, and scalability across a hybrid multicloud infrastructure.
Lack of Security and Regulatory Compliance
As governments worldwide enforce stricter laws on data sovereignty, security, and privacy, regulatory compliance has become essential. Organisations failing to meet these regulations exposes applications to security vulnerabilities and introduces performance bottlenecks and scalability constraints. These challenges are particularly prevalent in AI-driven applications.
By implementing strong encryption, utilizing Federal Information Processing Standards (FIPS)-compliant devices, and adopting automated compliance tools, organisations can address these risks and support secure, scalable, resilient and compliant application delivery.
Bespoke Application Requirements
As digital applications become increasingly specialised, organisations are often faced with unique requirements that standard infrastructure cannot support.
Programmability within the application delivery infrastructure offers a powerful solution to such challenges, enabling organisations to tailor their infrastructure to support complex, customised requirements.
Bespoke application requirements often challenge traditional application delivery solutions, as they require customisation that standard infrastructure cannot provide. By leveraging programmability within the application delivery infrastructure, organisations can adapt to these unique demands, ensuring high performance, availability, and scalability.
Furthermore, programmable infrastructure enables seamless transitions, integrates new services efficiently, and supports custom load balancing, allowing organisations to deliver reliable and responsive services that meet the specific needs of their users.
Poor Resource Utilisation
Many organisations struggle with resource inefficiencies due to mismatched distribution algorithms or inadequate health check mechanisms.
These inefficiencies can lead to wasted compute power, increased operational overhead, and strained infrastructure, ultimately impacting performance, availability, and scalability.
By leveraging programmability, intelligent health checks, and dynamic traffic steering, organisations can optimise resource usage, improve application performance, and enhance scalability.
Full details of the Application Delivery Top 10, including mitigation best practices, can be found here: https://www.f5.com/resources/articles/the-application-delivery-top-10
Image Credit: F5
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Starlink power cuts reveal vulnerabilities of space-based internet systems
Starlink power cuts reveal vulnerabilities of space-based internet systems

The National

time10 hours ago

  • The National

Starlink power cuts reveal vulnerabilities of space-based internet systems

Two major power cuts on Elon Musk's Starlink have shown how vulnerable satellite internet systems can be, especially when compared to the more resilient fibre and mobile networks most people rely on. Even though these systems, which Jeff Bezos's Amazon is also developing through its Project Kuiper constellation, are helping to revolutionise global connectivity by reaching remote areas, the recent blackouts show they are still prone to disruptions. Starlink users across several continents lost service in July for more than an hour after a technical issue in the company's network software. Another power cut on Monday left thousands of customers in North America without internet access until engineers restored the system. More than 8,000 Starlink satellites operate 550km above Earth. Users connect to them with their own dish, which links to a satellite overhead before the signal is passed to ground stations that plug into the wider internet. Updated satellites also use laser links to transfer data between each other in space, which helps SpaceX reduce its reliance on ground stations and improve coverage in remote areas and over oceans. Why are space-based systems less reliable? Dr Sarath Raj, director of the satellite ground station at Amity University in Dubai, said a Starlink power cut is a reminder of the difference between centralised and decentralised systems. 'Terrestrial networks like fibre and mobile are designed with multiple redundant pathways and local rerouting, so a cut cable or a downed tower typically only affects a limited area,' he told The National. 'Starlink, on the other hand, despite having thousands of satellites, depends heavily on its centralised control software. A single software glitch or misconfigured update can disrupt connectivity worldwide, creating a single point of failure.' Dr Raj said power cuts in traditional telecoms are usually caused by physical problems such as damaged cables, fallen towers or power failures, which tend to be limited to one area. But in low-Earth orbit constellations like Starlink, disruptions are more prone to be global and systemic, with the greater risks coming from software glitches or cyber attacks rather than individual satellites. 'The vast number of satellites in Starlink's constellation provides impressive physical coverage, but that alone does not guarantee reliability,' said Dr Raj. 'The real vulnerabilities lie in the ground-based infrastructure and control software, which act as the network's brains. 'Cyber attacks on centralised routing systems, disruptions at ground gateways that link satellites to the global internet, or even exploits in user terminals could all degrade or shut down service on a large scale.' How important is Starlink? Starlink was a crucial communications lifeline for Ukraine's military after Russia's invasion, restoring internet access where traditional networks had been destroyed. But when the service was first activated in 2022, Mr Musk warned it could also be hit by cyber attacks. Mr Musk posted on X at the time: 'Important warning: Starlink is the only non-Russian communications system still working in some parts of Ukraine, so probability of being targeted is high. Please use with caution.' Xianbin Wang, research chairman at the Trusted Communications and Computing at Western University, Canada, said low-Earth orbit (Leo) systems are less robust overall. 'As a standalone internet service provider, Leo networks are much less resilient than fibre and mobile networks,' he said. 'Traditional telecom systems are developed with highly redundant capacity and architecture. As a comparison, Leo satellite networks have very limited capacity and redundancy. 'Consequently, the outage probability in such networks is expected to be much higher.' Dr Raj echoed Mr Wang's comments and said that Starlink does provide 'impressive coverage' but the real vulnerabilities lie in its ground-based infrastructure and control software, which act as the network's 'brains'. 'Cyber attacks on centralised routing systems, disruptions at ground gateways that link satellites to the global internet, or even exploits in user terminals could all degrade or shut down service on a large scale,' he said. What are the advantages? Despite these risks, the internet satellites do still fill a crucial gap, especially in remote and conflict-hit areas where terrestrial networks are unavailable. 'The advantage of the satellite communication is its global coverage, including remote but critical areas,' Mr Wang said. 'Depending on the needs and situations, Leo satellite networks could play a critical role.' Mr Raj said that because of the growing reliance on these systems, internet satellites should be considered part of a country's critical infrastructure. 'Starlink has evolved from an innovative service into a strategic asset, relied upon by remote communities and even militaries in conflict zones such as Ukraine,' he said. 'For this reason, it should be treated as critical infrastructure, similar to power grids, water systems and terrestrial telecom.' Regulating such a system, however, is complicated because Starlink is a private company serving a global customer base. 'This creates jurisdictional challenges as it is unclear which authorities set the rules and ensure compliance when the service spans multiple countries,' said Dr Raj.

Starlink cut: users around the world report connectivity problems
Starlink cut: users around the world report connectivity problems

The National

time3 days ago

  • The National

Starlink cut: users around the world report connectivity problems

Users of Starlink, the maker of internet connectivity devices and low-earth-orbit (LEO) satellites, reported problems gaining access to the internet on Monday. It was the latest in a string of cuts for Elon Musk's SpaceX, which owns and operates Starlink. Downdetector, which reports global internet problems, confirmed that Starlink users around the world were having trouble with their devices. "You're not alone," Downdetector posted to its social media account. "Downdetecter users have been reporting problems since 5.35 GMT." NetBlocks, which tracks cybersecurity and digital governance, also confirmed a significant blackout. "The incident is the second observed in the last month," the organisation said. Starlink is the dominant player in LEO internet services, and has secured approval in various countries around the world to provide connectivity. It is not yet clear what caused the cut to services. Users on X, also owned by Mr Musk, responded to posts from Starlink with reports of not being able to connect. Starlink has not yet responded to The National 's requests for comment on this story. The company's standard antennae devices, which connect to its LEO satellites, weigh less than 3kg, contain no moving parts and can withstand strong winds. Unlike traditional communications satellites, which orbit Earth in the range of 20,000km to 35,000km, Starlink's thousands of satellites orbit at about 550km, increasing internet speeds and cutting back on latency. In contrast to 5G or broadband internet, the satellite version does not depend on mobile towers or high-speed data lines, making connection possible in remote areas.

Mobile phone subscriptions in Oman up 15.7%
Mobile phone subscriptions in Oman up 15.7%

Zawya

time4 days ago

  • Zawya

Mobile phone subscriptions in Oman up 15.7%

Muscat - The total number of mobile telecom subscriptions in the Sultanate of Oman reached 8,033,008 by the end of June, registering a 15.7 percent increase compared to the end of June 2024. The latest statistics issued by the National Center for Statistics and Information show that the number of active mobile broadband subscriptions has risen to 5,516,530 by the end of June 2025. Active postpaid mobile subscriptions in the Sultanate of Oman increased by 5.3 percent to reach 1,236,561 subscriptions by the end of June 2025, compared to the same period in 2024. Active prepaid mobile subscriptions also increased by 3.6 percent to reach 5,236,191 subscriptions. Internet of Things (M2M) subscriptions achieved exceptional growth of 118.6 percent, reaching 1,560,256 subscriptions by the end of June 2025. Meanwhile, active fixed broadband subscriptions increased by 2.2 percent, reaching 588,477 subscriptions compared to the same period in 2024. Fiber optic (FTTH/B) subscriptions grew by 10.3 percent, reaching 339,309 subscriptions, while fixed 5G subscriptions increased by 1.5 percent, reaching 215,434 subscriptions by the end of June 2025. Meanwhile, fixed 4G subscriptions declined by 31.7 percent, reaching 20,952 subscriptions. ADSL subscriptions decreased by 52 percent, reaching 11,289 subscriptions, while satellite subscriptions increased by 8.5 percent, reaching 724 subscriptions. Other subscriptions (which include Internet via power lines, Ethernet, and leased Internet lines) decreased by 11.2 percent, reaching 769 subscriptions by the end of June 2025, compared to the same period in 2024. 2025 © All right reserved for Oman Establishment for Press, Publication and Advertising (OEPPA) Provided by SyndiGate Media Inc. (

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store