DDoS Mitigation
Full-stack DDoS defense, engineered without compromise
Heuristic filtering in the hardware datapath at every Wirescope PoP, from volumetric floods to application-layer attacks. No diversion, no nullroutes, no attack-size cap. Read about how we designed Wirescope for DDoS.
Predictable Under Attack
Unmetered by design
DDoS protection is always-on and unmetered. Attack traffic is filtered inline at the edge, is excluded from billing, and never counts toward your commit, so the size of the attack does not change your bill. There is no fallback mode you have to trigger.
- Inline at the PoP
- Attacks are dropped where they enter our network, never backhauled to a distant scrubbing center and tromboned back.
- Stateless by design
- Filtering works without return-traffic visibility, so asymmetric routing and partial announcements are fine.
- No nullroutes
- We filter the attack and keep you announced. Your prefixes never leave the routing table to save someone else's network.
- Transit on the same path
- Mitigation is part of your connectivity, not an overlay on someone else's. One hop, one SLA, one bill.
How It Works
Five stages, one pass
Every packet crosses the full pipeline before it reaches you. Malicious traffic is dropped at the earliest stage that can identify it; clean traffic never leaves the forwarding path.
Ingress & classification
Traffic for your prefixes lands at a Wirescope PoP and is classified on arrival using flow telemetry, protocol fingerprinting, and behavioral signatures.
Every packet inspected, no sampling
Volumetric scrubbing
Amplification floods (NTP, DNS, CLDAP, Memcached, SSDP, CHARGEN) are dropped at the PoP where they enter, before they touch the delivery path.
Dropped at the ingress PoP
Protocol-level filtering
TCP state tracking, SYN cookie validation, and anomaly detection neutralize SYN, ACK, and RST floods and malformed packet storms.
Drop-or-pass at wire speed, per packet
Application-layer analysis
Deep packet inspection identifies HTTP floods, slowloris, DNS query floods, and encrypted vectors, separating real traffic surges from coordinated attacks.
Anomaly scoring tuned to your traffic profile
Clean traffic delivery
Clean traffic is forwarded by your preferred method, with full visibility into what was filtered, why, and how much.
Same path and speed as before the attack
Architecture
Two tiers of defense, built for the worst case
In-house scrubbing handles the overwhelming majority of attacks with the full depth of our filtering stack. The rare flood that exceeds local capacity gets cut down further upstream, long before it converges on our edge.
Tier 1 · In-house, at every PoP
Purpose-built ASICs in the forwarding path
Filtering runs on our own hardware, in the same datapath that delivers your traffic. Packets are classified and scored as they cross the chip: nothing is copied into memory, queued for a verdict, or replayed in software. Behaviour during an attack is the behaviour you measured before it.
- No queueing: packets are scored in flight, inspection adds no dwell time
- No emulation: the filtering logic is the datapath itself
- No fallback mode: there is no slow path to drop into under load
Tier 2 · Upstream, when it counts
FlowSpec escalation into partner networks
At extreme scale, shared infrastructure congests before any single edge does. So we propagate our own FlowSpec rules upstream into the transit networks that feed our PoPs, shrinking the flood to what in-house scrubbing absorbs completely.
Heuristics
Tuned to the traffic you actually run
Static rules catch known attacks. The heuristic engine handles the rest: it scores traffic against behavioral signatures, protocol anomalies, and the profile of your service, so a flood that has never been named still gets dropped.
- Behavioral fingerprinting
- Flows are fingerprinted on packet timing, TTL distribution, window sizes, and payload entropy, separating real users from botnet nodes even as attackers rotate IPs.
- Profile-aware thresholds
- Sensitivity is set per prefix, protocol, and flow from your service profile, so expected spikes are provisioned for, not flagged.
- Event-driven rules
- When an attack is confirmed, scoped rules deploy to every PoP at once, and upstream via FlowSpec when the flood warrants it.
- Protocol anomaly scoring
- Every packet gets a composite anomaly score from header compliance, behavioral deviation, and statistical outliers, then passes, drops, or gets challenged.
Protocol-aware defense
Dedicated validation logic per workload instead of generic packet rules. Don't see your protocol? We can build custom filtering for it, or you can write your own rules in BPF syntax.
Web & API
HTTP/S- HTTP/2 rapid reset defense
- Slowloris & slow-read detection
- API rate limiting per endpoint
DNS
DNS- Query flood filtering
- NXDOMAIN attack detection
- Amplification reflection defense
Game servers
UDP/TCP- Per-player session tracking
- Game protocol validation
- Player-count-aware scaling
Custom protocols
ANY- BPF-syntax custom rules
- Payload pattern matching
- Zero-downtime rule deployment
Attack coverage
The full mitigation stack ships with every deployment. No tiers, no add-ons.
Integration
Connect your way
Choose the onboarding method that fits your infrastructure. All methods deliver the same full mitigation stack with identical SLAs.
Inline transit
Included with transitMitigation built into your IP transit port. One path, one contract, nothing to divert.
- Included with every transit commit
- Same port, same path, no overlay
- Full BGP table on the same session
- Single or redundant ports
Tunnel
Fastest setupThe fastest way to get protected, and the easiest to change later.
- GRE / IPsec / IPIP / QUIC
- Emergency onboarding in hours
- Switch delivery method anytime
- Multi-tunnel load balancing
Cross-connect / fibre
Lowest latencyPhysical interconnect at any of our PoPs. Lowest latency, highest throughput.
- 10GE / 25GE / 100GE ports at every PoP
- 400GE in Ashburn (Equinix DC2)
- Campus cross-connects where the fabric reaches
- Single or redundant ports
On-premise appliance
On-premiseOur hardware inside your network, running the same engine as our PoPs.
- Deployed at your network edge
- Same filtering engine as our PoPs
- Local inspection: data never leaves your network
- Managed and updated remotely by Wirescope NOC
Every mitigation control (rules, thresholds, prefixes, alerting) is yours to tune in real time, from the panel or programmatically. No tiers, no paywalled knobs.
SLA
Backed by real commitments
Uptime, time-to-mitigate, false-positive and response commitments are contractual and backed by service credits. Formal figures are published at launch and included in every contract.
- Network uptime
- Measured per calendar month across all PoPs
- Time to mitigate
- Covers volumetric and application-layer attacks alike
- False positive rate
- With managed filters tuned to your traffic profile
- Clean traffic delivery
- Legitimate traffic keeps flowing during active mitigation
- BGP convergence
- Full route propagation across the network
- NOC response
- 24/7 response to customer-initiated escalations
Under attack right now?
Our NOC team is available 24/7 for emergency DDoS mitigation. GRE tunnel onboarding in hours, not days.
FAQ
Common questions
Ready to stop DDoS attacks?
Tell us about your network and your threat model, and we will have you protected in days, not weeks.