DDoS Protection
A Distributed Denial of Service (DDoS) attack leverages multiple compromised systems to target a single or multiple servers, overwhelming them with traffic to exhaust bandwidth or system resources, ultimately rendering services unavailable.
Attack Methods
DDoS attacks aim to disrupt services by saturating network or server capacity. Common methods include:
- Network Overload: Flooding the network with traffic to degrade or block normal communication.
- Server Exhaustion: Submitting excessive requests to overwhelm server resources.
- Targeted Blocking: Preventing specific users or systems from accessing a service.
- Service Isolation: Disrupting communication between the target service and its users or systems.
Attack Symptoms
DDoS attacks generally manifest in two major forms:
- Volume-Based Attacks (Traffic Flooding): Consume network bandwidth using forged or meaningless packets, preventing legitimate traffic from reaching the server.
- Resource Exhaustion Attacks: Overwhelm server memory, CPU, or connection capacity, causing performance degradation or system crashes.
Typical signs include:
- Numerous half-open TCP connections on the host.
- Massive volumes of illegitimate packets with spoofed IP addresses.
- Congested network links due to irrelevant or malformed traffic.
- Exploitation of protocol/service flaws to send rapid, repetitive requests.
- In severe cases, complete system failure or service crash.
DDoS Protection by Security CDN
1. Core Capabilities
- Real-Time Traffic Analysis: Continuously monitor incoming traffic to detect abnormal connection rates, malformed packets, and attack signatures.
- Automated Defense: Instantly trigger countermeasures based on predefined thresholds, without requiring manual intervention.
2. Supported DDoS Attack Types
Supports but is not limited to protection against the following types of DDoS attacks
| Attack Type | Description |
|---|---|
| UDP Flood | Exhausts bandwidth with high-volume UDP packets. |
| SYN Flood | Exploits TCP handshake to consume server connection resources. |
| ACK/FIN Flood | Sends large volumes of ACK or FIN packets to drain resources. |
| HTTP Flood | Mimics legitimate HTTP requests to exhaust web server capacity. |
| DNS Query Flood | Overwhelms DNS servers with massive query requests. |
3. Protection Tiers
| Plan Type | Service Description |
|---|---|
| Basic | Provides fundamental protection. When attack traffic exceeds the local mitigation threshold, service disruption may occur. |
| Pro / Business / Enterprise | Delivers dedicated and robust DDoS protection for your services, ensuring robust protection for critical business operations. |
Note: While our defense system is highly resilient, no DDoS protection solution can guarantee absolute prevention under all circumstances.
Need help? Contact our support team at support@edgenext.com.
Back to documentation home