1. Limit Request/Response size 2. Allow limit for a specific set of IP addresses 3. Allow limit of number of requests/time per client (IP)