全部文章
SécuritéDDoSRéseau

我们如何打造自研 Anti-DDoS

发布于 2023年3月7日 · 阅读约 9 分钟

本文提供法语和英语版本。

How we built our in-house anti-DDoS

In 2022, the volume of attacks targeting our customers tripled. Off-the-shelf solutions were either too expensive or too slow to react. So we built our own. Here's what we learned.

A three-layer architecture

Layer 1 — Edge filtering. Our border routers apply rate-limiting and ACLs against trivial signatures (NTP, SSDP, CLDAP amplification). 80% of attack volume is absorbed here, with zero added latency.

Layer 2 — Behavioral detection. An eBPF pipeline continuously samples traffic and builds a per-customer-IP baseline. Any deviation — SYN floods, malformed packets, abnormal UDP patterns — triggers mitigation in under 800 ms.

Layer 3 — Application scrubbing. For L7 attacks, a mitigation reverse proxy applies TLS fingerprinting and adaptive JavaScript challenges.

2024 in numbers

  • Largest attack absorbed: 412 Gbps (memcached amplification)
  • Longest campaign: 11 days of intermittent flooding against a gaming customer
  • Median mitigation time: 740 ms
  • Observed false positives: 0.02% of legitimate traffic

Why it's included in every plan

DDoS protection shouldn't be a paid add-on: the infrastructure should absorb attacks, not the customer. Since January 2024, all three layers protect every VPS, from Apex to Singularity, at no extra cost.