Stage 1 · EdgeVolumetric absorption500+ Tbpsupstream capacity
Volumetric
- TCP floodsSYN, ACK, RST, PSH and mixed-flag packets
- UDP floodsHigh-rate datagrams with random ports and payloads
- ICMP floodsEcho request floods and oversized pings
- Tunnel protocol floodsESP and GTP packet floods
- Botnet floodsMixed vectors sent from compromised hosts
Reflection & amplification
- TCP amplificationSpoofed SYNs reflected back as SYN-ACK floods
- Common UDP amplificationDNS · NTP · Memcached · SSDP / UPnP · LDAP · SNMP · Chargen · TFTP
- QUIC reflectionSpoofed Initial packets that trigger large handshake replies
Stage 2 · In-houseStateful validation13+ Tbpsacross 13+ PoPs
Exhaustion
- Malformed packetsTruncated headers and bad checksums
- Invalid TCP flagsImpossible or reserved flag combinations
- IP fragmentationTeardrop and overlapping fragments
- Bogon sourcesPackets from reserved and unroutable addresses
- Invalid portsPackets to port 0 and reserved ports
Game protocols
- Arma ReforgerRplNet handshake floods and malformed packets
- Squad and Source titlesA2S query floods: INFO, PLAYER, GETSUM
- RustConnection floods and game-state abuse
- MinecraftHandshake and bot-driven floods
- GTA V / FiveMConnection exhaustion and state attacks
- Your gameApp-specific floods against any other title
Not an exhaustive list. Traffic that doesn't match what your service expects is dropped whether or not it appears here.
We don't have to. Detection has to recognise an attack before it can stop it, so anything new gets through the first time. We check every packet against what your protocol and service expect, and drop anything that doesn't match, whether we've seen it before or not.