How we built our in-house anti-DDoS
In 2022, the volume of attacks targeting our customers tripled. Off-the-shelf solutions were either too expensive or too slow to react. So we built our own. Here's what we learned.
A three-layer architecture
Layer 1 — Edge filtering. Our border routers apply rate-limiting and ACLs against trivial signatures (NTP, SSDP, CLDAP amplification). 80% of attack volume is absorbed here, with zero added latency.
Layer 2 — Behavioral detection. An eBPF pipeline continuously samples traffic and builds a per-customer-IP baseline. Any deviation — SYN floods, malformed packets, abnormal UDP patterns — triggers mitigation in under 800 ms.
Layer 3 — Application scrubbing. For L7 attacks, a mitigation reverse proxy applies TLS fingerprinting and adaptive JavaScript challenges.
2024 in numbers
- Largest attack absorbed: 412 Gbps (memcached amplification)
- Longest campaign: 11 days of intermittent flooding against a gaming customer
- Median mitigation time: 740 ms
- Observed false positives: 0.02% of legitimate traffic
Why it's included in every plan
DDoS protection shouldn't be a paid add-on: the infrastructure should absorb attacks, not the customer. Since January 2024, all three layers protect every VPS, from Apex to Singularity, at no extra cost.