DDoS protection for your servers and websites
A distributed denial-of-service (DDoS) attack tries to take a service offline by flooding it with traffic from many machines. Several HyperDC product lines list DDoS protection in their plans. Here is what that means and how to prepare your own service.
Three kinds of DDoS attack
The categories used by the US Cybersecurity and Infrastructure Security Agency (CISA). Real attacks often mix them.
Volumetric
Floods the target with more traffic than its connection can carry, so legitimate requests cannot get through.
Protocol
Abuses network protocols, as in a SYN flood, to exhaust the connection tables of servers and firewalls.
Application layer
Sends requests that look legitimate, such as an HTTP flood, until the application runs out of capacity.
Product lines with DDoS-protected plans
-
America Dedicated Server Hosting
With Dedicated Server Hosting, you have exclusive access to a physical server, providing high performance and customization options.
Starting from $90.00/mês -
Germany Dedicated Server Hosting
With Dedicated Server Hosting, you have exclusive access to a physical server, providing high performance and customization options.
Starting from $150.00/mês -
Turkey Dedicated Server Hosting
With Dedicated Server Hosting, you have exclusive access to a physical server, providing high performance and customization options.
Starting from $135.00/mês -
WordPress Web Hosting
Our WordPress Web Hosting is optimized for WordPress-based websites, ensuring fast and secure operation. Benefit from automatic updates, backups, and specialized WordPress support.
Starting from $2.39/mês -
Internet Radio Hosting
If you're an internet radio station, our Internet Radio Hosting is designed to offer high bandwidth and audio quality, allowing for smooth live broadcasts and podcast sharing.
Starting from $1.58/mês
How network DDoS mitigation works
The general approach described by CISA and the UK NCSC. Each plan’s protection is described in its plan details.
-
Monitor
Traffic is compared with its normal baseline, so unusual floods stand out quickly.
-
Detect
Attack traffic is identified by its volume, protocol and source patterns.
-
Filter
Malicious traffic is filtered upstream while legitimate traffic still reaches the service.
-
Protect the network
An attack larger than the filtering capacity can be null-routed to keep the rest of the network online.
What you can do before an attack
Keep software updated
Patch the operating system, web server and applications so attacks cannot exploit known weaknesses.
Cache and filter web traffic
Caching, rate limiting and a web application firewall absorb application-layer floods.
Hide your origin
Behind a proxy or CDN, keep the server’s real IP address out of public DNS records and email headers.
Have a response plan
Know who to contact, which logs to keep and how you will tell your customers.
Keep backups
Attacks are sometimes used as a distraction; current backups let you recover from anything else.
Contact us early
Open a ticket with the affected IPs, times and logs as soon as you notice a problem.
Open a ticketServices with DDoS protection
Frequently asked questions
What is a DDoS attack?
A distributed denial-of-service attack sends so much traffic, or so many requests, from many machines at once that a server, website or network can no longer answer legitimate users. Attackers often combine several types of attack.
Which HyperDC services include DDoS protection?
Every plan of our Turkey dedicated servers, WordPress hosting and Internet radio hosting lists DDoS protection among its features, as do most of our dedicated servers in the United States and some in Germany. Co-location lists DDoS mitigation as an add-on. Check the plan card of the service you choose: it shows exactly what is included.
Does network DDoS protection stop every attack?
Network protection is built for floods at the network and transport layers. Attacks on the application itself, such as floods of HTTP requests that look legitimate, also need caching, rate limiting and a web application firewall in front of the site.
What should I do if I think my service is under attack?
Open a support ticket right away with the affected IP addresses and services, the time the problem started and any logs you have. Keep a record of what you see; it helps to tell an attack from a configuration problem or a legitimate traffic peak.
Why is my server’s real IP address important?
If you use a CDN or a proxy in front of your website, attackers who learn the server’s real address can bypass it. Point every public DNS record through the proxy, avoid sending mail from the same IP and allow web traffic only from the proxy.
What is null routing?
When an attack is larger than a network can filter, operators can drop all traffic to the targeted IP address for a while. This takes that address offline but protects every other service on the network.
Questions before you order?
Send us a message and our team will help you choose the right service.