Skip to content

SecurityDDoS protection

DDoS protection basics: recognise, mitigate, report

What DDoS attacks are, how to tell one from a traffic peak, which HyperDC plans include protection, how to limit floods with nginx and what to report.

  • Intermediate
  • 15 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. The three kinds of attack
  3. Step 1: Is it an attack or a busy day?
  4. Step 2: Protect the application
  5. Step 3: Report it
  6. Null routing
  7. DDoS protection is not a firewall
  8. Troubleshooting
  9. Next steps

A distributed denial-of-service (DDoS) attack sends so much traffic, or so many requests, from many machines at once that a server or network can no longer answer real users. This guide explains the types, how to recognise an attack, what protects you and what to do while it happens.

Before you start

  • Check whether your plan includes DDoS protection: the plan card on our website and the DDoS protection page show it.
  • Know your normal traffic. Without a baseline, an attack and a successful campaign look alike.

The three kinds of attack

TypeWhat it doesWhat helps
VolumetricFills the network link with traffic (UDP floods, amplification)Network-level filtering upstream
ProtocolExhausts connection tables (SYN floods)Network filtering, kernel SYN cookies
Application layerSends many legitimate-looking requests (HTTP floods)Caching, rate limits, a CDN or web application firewall

Network protection deals with the first two. Application-layer floods also need measures on your side.

Step 1: Is it an attack or a busy day?

A traffic peak after a campaign brings real visitors who browse several pages and place orders. An attack often shows a sudden jump in one kind of traffic, from unusual sources, to a single URL or port, without more orders or sign-ups. Look at the server:

Bash
ss -s
sudo awk '{print $1}' /var/log/nginx/access.log | sort | uniq -c | sort -rn | head -n 20
sudo awk '{print $7}' /var/log/nginx/access.log | sort | uniq -c | sort -rn | head -n 20

ss -s summarises connections; thousands of connections in SYN-RECV or TIME-WAIT suggest a flood. The two awk lines show the client addresses and the URLs with the most requests in the access log.

Step 2: Protect the application

If the attack targets your website, limit how fast a single address may make requests. In nginx, define zones in the http block:

Nginx
limit_req_zone $binary_remote_addr zone=perip:10m rate=10r/s;
limit_conn_zone $binary_remote_addr zone=peraddr:10m;

and apply them in the server or location block:

Nginx
limit_req zone=perip burst=20 nodelay;
limit_conn peraddr 20;

Test and reload with sudo nginx -t and sudo systemctl reload nginx. Requests over the limit get status 503 by default. Also:

  • Cache pages that do not change per user, so floods hit the cache instead of PHP and the database.
  • Put a CDN or proxy in front of the site, such as Cloudflare, which absorbs and filters HTTP floods at its edge; see Cloudflare in front of your site.
  • Hide the origin. Attackers who know your server's real IP address can bypass the proxy. Point every public record through the proxy, do not send mail from the same IP and allow web traffic only from the proxy's addresses.

Step 3: Report it

Open a ticket right away with:

  • the affected IP addresses and services,
  • the time the problem started, with time zone,
  • what you observe: graphs, ss -s output, log excerpts, the URLs attacked.

Keep a record of what you see; it helps to tell an attack from a configuration problem or a real traffic peak.

Null routing

When an attack is larger than a network can filter, operators can null-route the targeted IP address for a while: all traffic to it is dropped to protect every other service on the network. The address is offline during that time. DDoS protection exists to filter attack traffic before it comes to that, which is why it matters for services that are likely targets, such as game servers and busy shops.

DDoS protection is not a firewall

DDoS protection deals with floods that try to make a service unreachable. It does not patch software, stop password guessing or remove malware. Keep the system updated, open only the ports you use, protect logins with keys and keep backups current.

Troubleshooting

Legitimate users get 503 after enabling rate limits. The limit is too low, or many users share one address (offices, mobile networks). Raise rate and burst, and exclude assets such as images from the limited location.

The site is slow but traffic looks normal. It may not be an attack. See high CPU or memory usage and website 502, 503 and 504 errors.

The server is completely unreachable. See server unreachable and check Support › Network Status.

Next steps

Frequently asked questions

Which HyperDC services include DDoS protection?

The plan card of each service shows it. Examples are our Turkey dedicated servers, WordPress hosting and Internet radio hosting, most US dedicated servers and some in Germany. Co-location lists DDoS mitigation as an add-on.

Does network DDoS protection stop every attack?

It is built for floods at the network and transport layers. Attacks on the application, such as floods of HTTP requests that look legitimate, also need caching, rate limiting and a web application firewall in front of the site.

What is null routing?

When an attack is larger than a network can filter, operators can drop all traffic to the targeted IP address for a while. This takes that address offline but protects every other service on the network.

Should I reboot the server during an attack?

Usually not: the traffic keeps coming after the reboot. Collect information, apply rate limits if the attack targets your application, and open a ticket.

Can Fail2ban stop a DDoS attack?

No. It reacts to individual addresses in logs, which suits password guessing, not floods from thousands of sources. Use network protection and edge services for floods.

Sources

Створити пароль

Please confirm