DDoS Defense: Ready

Anti-DDoS — stay online

Protection for IP networks, websites and APIs. Choose L3/L4 network scrubbing, SCDN web protection or a combined design, with SNS-IX engineers and 24/7 monitoring.

01 · Available Protection Layers
L3—L7
02 · Monitoring
24/7
03 · Connection Models
BGP / DNS
01HOW THE SERVICE WORKS

Protection at every public layer

Network scrubbing reduces malicious traffic before clean packets reach your infrastructure. Web protection inspects HTTP requests and applies WAF, flood and bot policies. The selected design keeps these layers aligned with your services and routes.

Service illustration: redundant network security appliances in separate rack bays.
Service illustration
security
01

Network DDoS protection

Mitigate UDP floods, amplification, protocol attacks and channel saturation at L3/L4.

language
02

WAF & API protection

SCDN can combine WAF request inspection, L7 flood controls and bot management for websites and APIs.

route
03

Clean traffic delivery

Use BGP traffic diversion for networks or a reverse proxy for selected websites and APIs.

Protection architecture

Match protection to the threat

An attack on network bandwidth needs a different response from an attack on a login endpoint. SNS-IX selects protection for the asset that must stay available: an IP network, a TCP/UDP service, a website or an API.

L3 / L4

Network Anti-DDoS

For operators, enterprise networks, servers and services that need protection at the IP and transport layers.

  • Volumetric and protocol attack filtering before clean traffic reaches your network.
  • BGP routing for protected prefixes, with an explicitly designed clean-traffic return path.
  • TCP/UDP protection works beyond websites; it does not replace HTTP request inspection by a WAF.
Network onboarding
SCDN / WAF

Website & API protection

For web services: requests pass through protected edge nodes that combine content delivery with traffic inspection.

  • The WAF inspects requests for SQL injection, XSS, exploit attempts and malicious scans.
  • HTTP flood and bot controls use rate limits, access rules and client verification.
  • Domain onboarding through DNS, with TLS and origin access rules configured together.
Explore SCDN

How network protection handles traffic

  1. 01

    Route to protection

    Agreed IP prefixes are routed to the scrubbing network through BGP.

  2. 02

    L3/L4 filtering

    Attack traffic is separated from legitimate packets under the selected policies.

  3. 03

    Return to your network

    Clean traffic returns over the agreed tunnel or direct connection.

Possible designs include GRE/IPIP, IX access or a physical connection. Availability, routing and MTU are validated for your site.

In detail

What we establish before activation

Protection must withstand an attack while keeping legitimate traffic flowing. Onboarding starts with a service baseline and route validation.

Assets & protocols

We identify prefixes, domains, ports and protocols. A UDP game server, a website and a payment API need controls tailored to their traffic.

Baseline & thresholds

We account for normal demand, seasonal peaks and critical actions. Web protection can apply different rules to login, search, checkout and API endpoints.

Routing & activation

We agree an always-on or on-demand mode where supported by the selected design. Announcements, return routing, service availability and restoration are checked together.

Visibility & operations

We agree alert events, NOC contacts, escalation and reporting. Operational tuning uses security events and feedback about legitimate traffic.

02USE CASES

Protect what cannot go offline

A practical fit for public services with direct availability and revenue impact.

01 router

Telecom

Backbones, BGP sessions and subscriber services.

02 account_balance

Banks & fintech

Payment gateways, online banking and APIs.

03 web

Digital platforms

E-commerce, media, SaaS and customer portals.

04 sports_esports

Gaming

Latency-sensitive game servers and launches.

Service illustration: a network security gateway with managed optical interfaces. Service illustration
03Distributed Scrubbing

Attack traffic stops here

Traffic is monitored against an agreed baseline. When detection and diversion conditions are met, malicious packets or requests are filtered while clean traffic is forwarded to your infrastructure. Capacity, thresholds, activation targets and the handling of legitimate traffic are confirmed for the selected topology.

24/7
Monitoring
Tested
Failover & Response
Integration Flow
01

Assess

Services, prefixes, traffic profile and critical user journeys.

02

Connect

BGP diversion or reverse proxy with agreed origin controls.

03

Validate

Thresholds, health checks, failover and escalation contacts.

04

Operate

Continuous monitoring, tuning and incident reporting.

04Seamless Onboarding

From assessment to protected traffic

SNS-IX engineers select the protection topology, define traffic baselines and validate failover before production activation.

verified Powered by 24/7 NOC Support
Common Questions

FAQ

How do Anti-DDoS, WAF and SCDN differ?

add
Network Anti-DDoS filters volumetric and protocol attacks at L3/L4. A WAF inspects application HTTP requests, such as SQL injection or XSS attempts. SCDN combines web protection, L7 DDoS controls, bot management and content delivery. An IP network and its public application may need both protection paths.

Which attacks does network protection address?

add
It addresses volumetric and protocol attacks, including UDP floods, amplification and traffic that exhausts bandwidth or network resources. TCP/UDP profiles, protected ports and capacity are defined during design. Malicious web-request content is handled by a WAF and is not automatically inspected by BGP scrubbing.

Can I protect a website without my own ASN or BGP?

add
Yes. A website or HTTP/HTTPS API can use DNS-based SCDN onboarding. Certificates, the origin and protection policies are configured and validated first; then the domain CNAME is updated or NS delegated, depending on the design. Network BGP protection requires prefix announcement authorization and routing validation; it is a separate integration model.

How is an entire IP network connected?

add
Engineers agree the protected prefixes and clean-traffic delivery method. The platform supports GRE/IPIP, IX or physical connection designs, subject to site-specific availability. Prefix authorization, BGP announcements, return routes, MTU and service reachability are validated before activation.

Does SCDN protect game servers and other UDP services?

add
The SCDN web path primarily serves HTTP/HTTPS websites, account portals and APIs. UDP game traffic or other network protocols need suitable L3/L4 protection. A project may use different designs for its game server, authentication endpoints and website; include all protocols in the request.

Is protection always on or activated during an attack?

add
This depends on the selected design. In an always-on mode, traffic already passes through protection; an available on-demand mode requires detection and route switching. Thresholds, activation, switching targets and restoration of normal routing are agreed and tested before launch.

What happens to legitimate users during an attack?

add
Filtering aims to pass legitimate traffic while restricting attacks. A normal traffic baseline is established in advance, and policies are tuned using observed events. Impact cannot be ruled out for every attack: the outcome depends on provisioned capacity, routing and application behavior.

How can WAF false positives be reduced?

add
Web rules can first be checked in observation mode, recording matches without blocking. Login, payment, uploads, webhooks and APIs are tested, exceptions refined and required actions enabled. Exceptions should be narrowly scoped to a rule or workflow instead of disabling protection for the entire application.

Should APIs and mobile applications use CAPTCHA?

add
Browser challenges are unsuitable for most machine clients. APIs, payment callbacks and mobile applications need rate limits, access conditions and exceptions that account for authentication. These flows are tested separately so a programmatic client is not required to complete a CAPTCHA.

Is hiding an origin IP behind SCDN sufficient?

add
Changing DNS alone does not close direct access to the old IP. Where supported, origin access is restricted to protection-platform addresses and TLS and additional request validation are configured. Management connections and backup paths must also be considered; a publicly reachable bypass address can leave a route around web protection.

How will protection affect latency?

add
Network scrubbing can change the route, while web caching can reduce trips to a distant origin. There is no universal latency promise. A pilot compares response times and errors from target networks and checks dynamic operations and switching behavior.

What information is available during an incident?

add
Network protection provides traffic status and filtering events. SCDN provides web security events and request and bot analytics within the selected modules. Alert channels, log access, retention, report format and escalation contacts are agreed during onboarding.

What capacity, SLA and traffic limits apply?

add
Parameters apply to a specific deployment and are defined in the proposal and contract. Protected assets, legitimate traffic, mitigation capacity, operating mode, support response and handling beyond agreed limits must be specified. The technology platform’s global capacity is not a per-customer capacity guarantee.

What should I provide for assessment and onboarding?

add
Provide domains or prefixes, an ASN if available, protocols, ports, sites and normal and peak traffic. Past attacks, existing protection and critical workflows are also useful. Assessment is followed by agreement on the protection design, validation, switching window and operational support.
Service illustration: a network security gateway with managed optical interfaces. Service illustration
Plan the next step

Prepare before the next flood

Tell us which network, website or API must stay available. We will recommend a practical protection topology and activation plan.