DDoS Protection & Mitigation
Terabit-era defence, engineered by people who ran the pipes.
DDoS defence is a routing and capacity problem before it is a security product — which is why it belongs to engineers who have operated BGP at carrier scale. We are Radware-trained and have defended operator infrastructure where the attack traffic and the revenue traffic share the same interfaces. We design layered mitigation: upstream and exchange-level filtering, BGP-signalled diversion into scrubbing (on-premises or cloud), and application-layer defence for the services that volumetric filters cannot see. Carpet-bombing across whole prefixes, IoT-botnet floods, and DNS amplification each get their own playbook, because they fail differently.
- Attack-surface and dependency mapping: which prefixes, services, and upstreams actually carry the business
- Volumetric mitigation architecture — RTBH, Flowspec, and BGP diversion into scrubbing centres
- On-premises vs cloud scrubbing trade-offs engineered on latency, cost, and sovereignty — not vendor slides
- Application-layer (L7) defence: HTTP floods, Slowloris-class attacks, API abuse, and bot management
- Anycast and DNS resilience so the control plane survives what the data plane is absorbing
- Upstream and IXP coordination — mitigation clauses and traffic engineering negotiated in carrier language
- Detection tuned for carpet-bombing across /24s and /16s, not just per-destination thresholds
- Attack post-mortems with packet-level forensics and a hardening list that gets executed
Attacks become an operational event with a procedure — not an outage with a press statement.