DDoS protection for your servers and websites
A distributed denial-of-service (DDoS) attack tries to take a service offline by flooding it with traffic from many machines. Several HyperDC product lines list DDoS protection in their plans. Here is what that means and how to prepare your own service.
Three kinds of DDoS attack
The categories used by the US Cybersecurity and Infrastructure Security Agency (CISA). Real attacks often mix them.
Volumetric
Floods the target with more traffic than its connection can carry, so legitimate requests cannot get through.
Protocol
Abuses network protocols, as in a SYN flood, to exhaust the connection tables of servers and firewalls.
Application layer
Sends requests that look legitimate, such as an HTTP flood, until the application runs out of capacity.
Product lines with DDoS-protected plans
-
America Dedicated Server Hosting
With Dedicated Server Hosting, you have exclusive access to a physical server, providing high performance and customization options.
Starting from $100.00/mnd -
Germany Dedicated Server Hosting
With Dedicated Server Hosting, you have exclusive access to a physical server, providing high performance and customization options.
Starting from $150.00/mnd -
Turkey Dedicated Server Hosting
With Dedicated Server Hosting, you have exclusive access to a physical server, providing high performance and customization options.
Starting from $150.00/mnd -
WordPress Web Hosting
Our WordPress Web Hosting is optimized for WordPress-based websites, ensuring fast and secure operation. Benefit from automatic updates, backups, and specialized WordPress support.
Starting from $3.00/mnd -
Internet Radio Hosting
If you're an internet radio station, our Internet Radio Hosting is designed to offer high bandwidth and audio quality, allowing for smooth live broadcasts and podcast sharing.
Starting from $2.00/mnd
How filtering keeps a server reachable
A flood does not have to break into a server to take it offline. It is enough to fill the network link or the connection tables in front of it. DDoS protection filters traffic on its way to the server: it recognises flood traffic by its volume, protocol and source patterns, drops it and passes legitimate traffic on.
Network filtering is built for floods at the network and transport layers. Floods of requests that look like normal visits to a website also need caching, rate limiting and a web application firewall on the site itself. Each plan lists in its details whether DDoS protection is included.
- Flood traffic is filtered before it reaches the server
- Legitimate traffic is passed on
- Website floods also need caching and rate limits
How network DDoS mitigation works
The general approach described by CISA and the UK NCSC. Each plan’s protection is described in its plan details.
-
Monitor
Traffic is compared with its normal baseline, so unusual floods stand out quickly.
-
Detect
Attack traffic is identified by its volume, protocol and source patterns.
-
Filter
Malicious traffic is filtered upstream while legitimate traffic still reaches the service.
-
Protect the network
An attack larger than the filtering capacity can be null-routed to keep the rest of the network online.
What you can do before an attack
Know your normal traffic
Note typical traffic levels and busy hours, so an attack stands out and you can describe it quickly.
Keep software updated
Patch the operating system, web server and applications so attacks cannot exploit known weaknesses.
Expose only what you use
Close the ports you do not need and limit admin access to known addresses.
Cache and filter web traffic
Caching, rate limiting and a web application firewall absorb application-layer floods.
Hide your origin
Behind a proxy or CDN, keep the server’s real IP address out of public DNS records and email headers.
Have a response plan
Know who to contact, which logs to keep and how you will tell your customers.
Keep backups
Attacks are sometimes used as a distraction; current backups let you recover from anything else.
Contact us early
Open a ticket with the affected IPs, times and logs as soon as you notice a problem.
Open a ticketServices with DDoS protection
Frequently asked questions
What is a DDoS attack?
A distributed denial-of-service attack sends so much traffic, or so many requests, from many machines at once that a server, website or network can no longer answer legitimate users. Attackers often combine several types of attack.
Which HyperDC services include DDoS protection?
Every plan of our Turkey dedicated servers, WordPress hosting and Internet radio hosting lists DDoS protection among its features, as do most of our dedicated servers in the United States and some in Germany. Co-location lists DDoS mitigation as an add-on. Check the plan card of the service you choose: it shows exactly what is included.
Does network DDoS protection stop every attack?
Network protection is built for floods at the network and transport layers. Attacks on the application itself, such as floods of HTTP requests that look legitimate, also need caching, rate limiting and a web application firewall in front of the site.
What should I do if I think my service is under attack?
Open a support ticket right away with the affected IP addresses and services, the time the problem started and any logs you have. Keep a record of what you see; it helps to tell an attack from a configuration problem or a legitimate traffic peak.
Why is my server’s real IP address important?
If you use a CDN or a proxy in front of your website, attackers who learn the server’s real address can bypass it. Point every public DNS record through the proxy, avoid sending mail from the same IP and allow web traffic only from the proxy.
What is null routing?
When an attack is larger than a network can filter, operators can drop all traffic to the targeted IP address for a while. This takes that address offline but protects every other service on the network.
How can I tell an attack from a busy day?
Both slow a service down, but they look different in your logs and graphs. A traffic peak after a campaign or a mention brings real visitors who browse several pages and place orders. An attack often shows a sudden jump in one kind of traffic, such as a single protocol, port or URL, from unusual sources, without a matching rise in orders or sign-ups. Knowing your normal traffic makes the difference easier to see, and the details help our team when you open a ticket.
Does DDoS protection replace a firewall and other security measures?
No. DDoS protection deals with floods that try to make a service unreachable. It does not patch software, stop password guessing or remove malware. Keep the operating system and applications updated, open only the ports you use, protect logins with strong passwords or SSH keys and keep current backups. For websites, caching, rate limiting and a web application firewall add protection against floods at the application layer.
Questions before you order?
Send us a message and our team will help you choose the right service.