DDoS Mitigation

Full-stack DDoS defense, engineered without compromise

Heuristic filtering in the hardware datapath at every Wirescope PoP, from volumetric floods to application-layer attacks. No diversion, no nullroutes, no attack-size cap. Read about how we designed Wirescope for DDoS.

$0Cost of any attack, any size
Always-onNo traffic diversion delay
L3–L7One stack, every layer
24/7Engineer-staffed NOC

Predictable Under Attack

Unmetered by design

DDoS protection is always-on and unmetered. Attack traffic is filtered inline at the edge, is excluded from billing, and never counts toward your commit, so the size of the attack does not change your bill. There is no fallback mode you have to trigger.

Inline at the PoP
Attacks are dropped where they enter our network, never backhauled to a distant scrubbing center and tromboned back.
Stateless by design
Filtering works without return-traffic visibility, so asymmetric routing and partial announcements are fine.
No nullroutes
We filter the attack and keep you announced. Your prefixes never leave the routing table to save someone else's network.
Transit on the same path
Mitigation is part of your connectivity, not an overlay on someone else's. One hop, one SLA, one bill.

How It Works

Five stages, one pass

Every packet crosses the full pipeline before it reaches you. Malicious traffic is dropped at the earliest stage that can identify it; clean traffic never leaves the forwarding path.

01

Ingress & classification

Traffic for your prefixes lands at a Wirescope PoP and is classified on arrival using flow telemetry, protocol fingerprinting, and behavioral signatures.

Every packet inspected, no sampling

02

Volumetric scrubbing

Amplification floods (NTP, DNS, CLDAP, Memcached, SSDP, CHARGEN) are dropped at the PoP where they enter, before they touch the delivery path.

Dropped at the ingress PoP

03

Protocol-level filtering

TCP state tracking, SYN cookie validation, and anomaly detection neutralize SYN, ACK, and RST floods and malformed packet storms.

Drop-or-pass at wire speed, per packet

04

Application-layer analysis

Deep packet inspection identifies HTTP floods, slowloris, DNS query floods, and encrypted vectors, separating real traffic surges from coordinated attacks.

Anomaly scoring tuned to your traffic profile

05

Clean traffic delivery

Clean traffic is forwarded by your preferred method, with full visibility into what was filtered, why, and how much.

Same path and speed as before the attack

Architecture

Two tiers of defense, built for the worst case

In-house scrubbing handles the overwhelming majority of attacks with the full depth of our filtering stack. The rare flood that exceeds local capacity gets cut down further upstream, long before it converges on our edge.

Tier 1 · In-house, at every PoP

Purpose-built ASICs in the forwarding path

Filtering runs on our own hardware, in the same datapath that delivers your traffic. Packets are classified and scored as they cross the chip: nothing is copied into memory, queued for a verdict, or replayed in software. Behaviour during an attack is the behaviour you measured before it.

  • No queueing: packets are scored in flight, inspection adds no dwell time
  • No emulation: the filtering logic is the datapath itself
  • No fallback mode: there is no slow path to drop into under load

Tier 2 · Upstream, when it counts

FlowSpec escalation into partner networks

At extreme scale, shared infrastructure congests before any single edge does. So we propagate our own FlowSpec rules upstream into the transit networks that feed our PoPs, shrinking the flood to what in-house scrubbing absorbs completely.

ZayoGTTRETN

Heuristics

Tuned to the traffic you actually run

Static rules catch known attacks. The heuristic engine handles the rest: it scores traffic against behavioral signatures, protocol anomalies, and the profile of your service, so a flood that has never been named still gets dropped.

Behavioral fingerprinting
Flows are fingerprinted on packet timing, TTL distribution, window sizes, and payload entropy, separating real users from botnet nodes even as attackers rotate IPs.
Profile-aware thresholds
Sensitivity is set per prefix, protocol, and flow from your service profile, so expected spikes are provisioned for, not flagged.
Event-driven rules
When an attack is confirmed, scoped rules deploy to every PoP at once, and upstream via FlowSpec when the flood warrants it.
Protocol anomaly scoring
Every packet gets a composite anomaly score from header compliance, behavioral deviation, and statistical outliers, then passes, drops, or gets challenged.

Protocol-aware defense

Dedicated validation logic per workload instead of generic packet rules. Don't see your protocol? We can build custom filtering for it, or you can write your own rules in BPF syntax.

Web & API

HTTP/S
  • HTTP/2 rapid reset defense
  • Slowloris & slow-read detection
  • API rate limiting per endpoint

DNS

DNS
  • Query flood filtering
  • NXDOMAIN attack detection
  • Amplification reflection defense

Game servers

UDP/TCP
  • Per-player session tracking
  • Game protocol validation
  • Player-count-aware scaling

Custom protocols

ANY
  • BPF-syntax custom rules
  • Payload pattern matching
  • Zero-downtime rule deployment

Attack coverage

The full mitigation stack ships with every deployment. No tiers, no add-ons.

L3Network layer
UDP FloodDNS AmplificationNTP AmplificationMemcached ReflectionSSDP AmplificationCLDAP ReflectionCHARGEN FloodGRE FloodIP FragmentationCarpet Bombing
L4Transport layer
SYN FloodACK FloodRST FloodFIN FloodTCP State Exhaustion
L7Application layer
HTTP FloodHTTPS FloodSlowlorisSlow ReadDNS Query FloodTLS ExhaustionWebSocket AbuseAPI Abuse

Integration

Connect your way

Choose the onboarding method that fits your infrastructure. All methods deliver the same full mitigation stack with identical SLAs.

Inline transit

Included with transit

Mitigation built into your IP transit port. One path, one contract, nothing to divert.

  • Included with every transit commit
  • Same port, same path, no overlay
  • Full BGP table on the same session
  • Single or redundant ports

Tunnel

Fastest setup

The fastest way to get protected, and the easiest to change later.

  • GRE / IPsec / IPIP / QUIC
  • Emergency onboarding in hours
  • Switch delivery method anytime
  • Multi-tunnel load balancing

Cross-connect / fibre

Lowest latency

Physical interconnect at any of our PoPs. Lowest latency, highest throughput.

  • 10GE / 25GE / 100GE ports at every PoP
  • 400GE in Ashburn (Equinix DC2)
  • Campus cross-connects where the fabric reaches
  • Single or redundant ports

On-premise appliance

On-premise

Our hardware inside your network, running the same engine as our PoPs.

  • Deployed at your network edge
  • Same filtering engine as our PoPs
  • Local inspection: data never leaves your network
  • Managed and updated remotely by Wirescope NOC

Every mitigation control (rules, thresholds, prefixes, alerting) is yours to tune in real time, from the panel or programmatically. No tiers, no paywalled knobs.

SLA

Backed by real commitments

Uptime, time-to-mitigate, false-positive and response commitments are contractual and backed by service credits. Formal figures are published at launch and included in every contract.

Network uptime
Measured per calendar month across all PoPs
Time to mitigate
Covers volumetric and application-layer attacks alike
False positive rate
With managed filters tuned to your traffic profile
Clean traffic delivery
Legitimate traffic keeps flowing during active mitigation
BGP convergence
Full route propagation across the network
NOC response
24/7 response to customer-initiated escalations

Under attack right now?

Our NOC team is available 24/7 for emergency DDoS mitigation. GRE tunnel onboarding in hours, not days.

Ready to stop DDoS attacks?

Tell us about your network and your threat model, and we will have you protected in days, not weeks.