# How Wallarm's API security platform relies on ClickHouse Cloud to detect and block attacks

DevFeed: [How Wallarm's API security platform relies on ClickHouse Cloud to detect and block attacks](<https://devfeed.tech/articles/how-wallarm-s-api-security-platform-relies-on-clickhouse-cloud-to-detect-and-block-attacks-5304.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/how-wallarms-api-security-platform-relies-on-clickhouse-cloud>)

Author: ClickHouse

Published: 2025-04-30T00:00:00Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [Security](<https://devfeed.tech/topics/security.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [real-time](<https://devfeed.tech/topics/real-time.md>), [Apache Cassandra](<https://devfeed.tech/topics/cassandra.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [api-security](<https://devfeed.tech/tags/api-security.md>), [cassandra](<https://devfeed.tech/tags/cassandra.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

The article describes how Wallarm's API security platform uses ClickHouse to support real-time analysis, threat detection, and attack blocking. It explains that Cassandra's eventual-consistency model was insufficient for real-time security and that Wallarm moved to a self-hosted ClickHouse deployment to reduce latency and analyze API sessions more effectively.

## Source excerpt

"We need our platform to operate in real time. The moment we detect suspicious activity, we aim to block the API user before they can attack the site or exploit a vulnerability." - Slava Yudanov, VP of Engineering, Wallarm