Site icon vXtream

DDoS Mitigation

Enterprise DDoS Attack Protection.

Keep your business online when attacks hit.

0
+
DDoS Attacks recorded per day worldwide
$
0
Can buy a Week long DDoS Attack on the Dark Web
0
%
Of Downtime Incidents are attributed to DDoS Attacks
0
Tbps
Largest Recorded DDoS Attack - October 2024
0
Minutes
Average DDoS Attack Duration

vXtream DDoS Mitigation

DDoS protection is built into the vXtream network, helping keep your online services available when malicious traffic attempts to overwhelm them. All Elastic Compute customers receive standard DDoS protection as part of their service.

For organisations requiring additional protection, our managed enterprise-level DDoS Mitigation service provides enhanced protection with pricing based on the volume of clean-return traffic.

Standard DDoS Protection

Protection built into the network.
Our network is protected against DDoS attacks, with standard DDoS protection included for all Elastic Compute customers. Enterprise-level DDoS Mitigation is also available for customers requiring additional protection.

On-Demand DDoS Mitigation

Activate enhanced protection when you need it.
Traffic can be re-routed and scrubbed when an attack is detected, with proactive or automated mitigation controls and around-the-clock support from global Security Operations Centres.

Always-On Enterprise DDoS Mitigation

Continuous protection. No waiting.
Traffic is continuously monitored and malicious traffic identified and mitigated before it reaches your network, helping keep critical services available around the clock.

What is a DDoS Attack?

A Distributed Denial of Service (DDoS) attack attempts to make a website, application or online service unavailable by overwhelming it with malicious traffic from multiple sources.

DDoS attacks can target any organisation with an online presence, disrupting critical services, affecting customers and damaging business operations. The challenge is identifying and filtering malicious traffic quickly enough to keep legitimate users connected.

When staying online matters.

Your website and online services are critical to your business. A successful DDoS attack can overwhelm your infrastructure with malicious traffic, disrupting services, affecting customers and quickly turning availability into a business-critical issue.

DDoS attacks are becoming larger, more frequent and more sophisticated, but the objective remains the same: keep legitimate users from accessing your services. Effective mitigation means detecting the attack quickly, filtering malicious traffic and keeping your business online.

Types of Attacks

DDoS attacks come in different forms, but they all have the same objective: overwhelm a network, system or application and prevent legitimate users from accessing a service.

Attack Class: Four common categories of attacks

TCP Connection Attacks - Exhausting connections

Attempt to consume the available connections on firewalls, load balancers and application servers, potentially preventing legitimate traffic from getting through.

Fragmentation Attacks - Overloading packet processing

Flood systems with fragmented TCP or UDP packets, consuming resources as they attempt to reassemble the traffic and degrading performance.

Application Attacks - Targeting specific services

Target a particular application or service rather than simply overwhelming the network. These attacks can be effective with relatively small amounts of traffic, making them harder to detect.

Volumetric Attacks - Consuming bandwidth

Flood the target network or service with enormous volumes of traffic, creating congestion and preventing legitimate users from accessing the service.

Amplification attacks – some DDoS attacks use legitimate network services to multiply the volume of traffic directed at a target

DNS Reflection - Amplifying traffic through DNS

Attackers send requests to DNS servers using a spoofed source address, causing much larger responses to be directed towards the victim

 

Chargen Reflection - Exploiting legacy services

The outdated Chargen protocol can generate streams of response traffic and has historically been abused to amplify DDoS attacks.

 

 

vXtream Enterprise DDoS Mitigation Key Features

Protect Any Connection

Carrier-agnostic protection can re-route and scrub traffic from vXtream or third-party connections, supporting IPv4 and IPv6 with IP VPN Direct and GRE clean-traffic return options.

85+ Tbps of Protection Capacity

With 15 global scrubbing centres and more than 85 Tbps of FlowSpec-based defence capacity, vXtream can absorb and filter even large-scale DDoS attacks.

 

 

24/7 Monitoring & Support

We monitor your edge devices for early detection and notification of attacks, backed by 24/7 support and eight global Security Operations Centres across Europe, North America, Latin America and Asia-Pacific.

Mitigation in Up to 10 Minutes

Up to 10-minute time-to-mitigate SLAs for most attacks once traffic reaches our scrubbing infrastructure.

Rapid Threat Defence

Automatic detection and response helps identify and block DDoS bot traffic at the network level, with countermeasures updated every 15 minutes by Black Lotus Labs

 

Global Scrubbing Network

Traffic is routed to the closest available scrubbing centre, with access to hundreds of partner internet and IP VPN points of presence worldwide.

Ready to strengthen your DDoS protection?
Exit mobile version