Network DDoS protection
Mitigate UDP floods, amplification, protocol attacks and channel saturation at L3/L4.
Protection for IP networks, websites and APIs. Choose L3/L4 network scrubbing, SCDN web protection or a combined design, with SNS-IX engineers and 24/7 monitoring.
Network scrubbing reduces malicious traffic before clean packets reach your infrastructure. Web protection inspects HTTP requests and applies WAF, flood and bot policies. The selected design keeps these layers aligned with your services and routes.
Mitigate UDP floods, amplification, protocol attacks and channel saturation at L3/L4.
SCDN can combine WAF request inspection, L7 flood controls and bot management for websites and APIs.
Use BGP traffic diversion for networks or a reverse proxy for selected websites and APIs.
An attack on network bandwidth needs a different response from an attack on a login endpoint. SNS-IX selects protection for the asset that must stay available: an IP network, a TCP/UDP service, a website or an API.
For operators, enterprise networks, servers and services that need protection at the IP and transport layers.
For web services: requests pass through protected edge nodes that combine content delivery with traffic inspection.
Agreed IP prefixes are routed to the scrubbing network through BGP.
Attack traffic is separated from legitimate packets under the selected policies.
Clean traffic returns over the agreed tunnel or direct connection.
Possible designs include GRE/IPIP, IX access or a physical connection. Availability, routing and MTU are validated for your site.
Protection must withstand an attack while keeping legitimate traffic flowing. Onboarding starts with a service baseline and route validation.
We identify prefixes, domains, ports and protocols. A UDP game server, a website and a payment API need controls tailored to their traffic.
We account for normal demand, seasonal peaks and critical actions. Web protection can apply different rules to login, search, checkout and API endpoints.
We agree an always-on or on-demand mode where supported by the selected design. Announcements, return routing, service availability and restoration are checked together.
We agree alert events, NOC contacts, escalation and reporting. Operational tuning uses security events and feedback about legitimate traffic.
A practical fit for public services with direct availability and revenue impact.
Backbones, BGP sessions and subscriber services.
Payment gateways, online banking and APIs.
E-commerce, media, SaaS and customer portals.
Latency-sensitive game servers and launches.
Service illustration DDOS / SNS-IX Traffic is monitored against an agreed baseline. When detection and diversion conditions are met, malicious packets or requests are filtered while clean traffic is forwarded to your infrastructure. Capacity, thresholds, activation targets and the handling of legitimate traffic are confirmed for the selected topology.
Services, prefixes, traffic profile and critical user journeys.
BGP diversion or reverse proxy with agreed origin controls.
Thresholds, health checks, failover and escalation contacts.
Continuous monitoring, tuning and incident reporting.
SNS-IX engineers select the protection topology, define traffic baselines and validate failover before production activation.
Service illustration Tell us which network, website or API must stay available. We will recommend a practical protection topology and activation plan.