Customer Story

A new game "swarmed at launch"
how two-layer cleaning absorbed an 8.6 Tbps botnet

A highly anticipated new game was hit by a hired botnet with sustained UDP / TCP floods on its very first day live — multiple attack waves, servers repeatedly on the brink. Here is how it used AwayDDoS to hold the line at an 8.6 Tbps peak with players noticing nothing (client name withheld, figures illustrative).

Customer Background

The client is a globally launched multiplayer game. Launch day is a dual peak of traffic and revenue: huge numbers of players flood in to download, log in, match and battle. Games are extremely sensitive to connection stability and low latency — any lag or login failure turns directly into churn and bad reviews. The launch hype also makes it a prime target for competitors and malicious traffic.

Its network follows a typical game-publishing shape: global players reach login and battle servers via DNS resolution, backed by cloud hosts + load balancing. With no professional high-defense deployed before launch, its security was near zero — exactly why it got "precisely swarmed" on day one.

①① 8.6 Tbps smoothly scrubbedA peak 8.6 Tbps botnet attack was absorbed by two-layer cleaning; the origin stayed online.
②② Zero origin reworkOnboarded purely via DNS protection — not a line of game backend code changed; zero-risk launch.
③③ Real-time expert tuning7×24 expert standby dynamically tuned policy during the attack, holding every wave.

Swarmed at launch: the botnet "opening-day snipe"

① Multiple UDP / TCP floods, origin on the brink

On launch day the attacker mobilized a massive botnet to hammer login and battle servers with UDP / TCP floods. These attacks are high-volume and widely distributed, instantly filling the origin's bandwidth and connection table — causing login timeouts, match failures and battle disconnects, a near-disaster launch experience.

② Competitor-driven "timed" attacks

Worse, the attacks were timed: the attacker struck precisely at launch, version updates and limited-time events — aiming to cause incidents when the new game was most fragile and most reputation-dependent. One failed launch means churn and reputation loss far larger than the attack's cost, trapping the business in a passive "crash if hit, lose if not."

The risk of a new-game launch is not "will it be attacked," but "can the business survive when attacked." One failed launch can zero out all the pre-launch marketing and pre-registrations overnight.

AwayDDoS Solution

Before launch we onboarded it to AwayDDoS Smart DNS protection: the game domain was switched to the AwayDDoS scrubbing center, volumetric traffic was diluted at the network edge, and deep application-layer attacks were precisely identified and blocked at the center, with clean traffic re-injected to the origin. The whole process needed zero origin rework — not a line of game backend code changed.

The key was real-time expert policy tuning: during the attack, expert engineers stood by 7×24, dynamically adjusting cleaning policies and rate limits by attack signature, keeping legitimate player traffic on the optimal path. Every wave on launch day was absorbed at the edge; the origin stayed stable throughout.

  1. Pre-launch onboarding — before launch, the game domain was onboarded to the AwayDDoS scrubbing center via DNS protection, with policy templates pre-set so the game went live already protected.
  2. Edge dilution + center precision — massive UDP / TCP floods were diluted 90% at edge nodes; remaining app-layer attacks were precisely blocked at the center via signature and behavioral analysis.
  3. Real-time expert tuning — security experts monitored the attack 7×24, dynamically adjusting policy so every wave was smoothly absorbed, players unaware.

How it works: a millisecond protection loop

Built on real-time Smart DNS probing and globally distributed scrubbing nodes, the system completes anomaly detection, traffic switching and clean re-injection in milliseconds, forming an automated protection loop that keeps the business interruption-free.

1. Smart detection & DNS switch

Continuously probes origin health; on anomaly it seamlessly switches the domain from the primary CNAME to the AwayDDoS backup node, blocking attacks from reaching the origin — no manual intervention.

2. Global node scrubbing

Traffic is pulled into distributed scrubbing clusters; using signature detection and behavioral analysis, it precisely filters DDoS, CC and other attacks while preserving legitimate requests and avoiding harm to real users.

3. Safe re-injection

Cleaned traffic is re-injected to the origin (WAF / SLB) via cloud interconnect or public IP; users notice nothing and business processing is unaffected.

Core advantages

Proactive defense, smart switching

Smart DNS health probing delivers second-level fault sensing and automatic traffic shifting, keeping access interruption-free and coping with node failures and traffic spikes without manual switchovers.

Controllable cost, elastic defense

No more "billing by peak." A fixed protection package allows a certain number of overage events, with advance confirmation before any extra — drastically lowering total TCO.

Seamless integration, no rework

Fully compatible with the existing cloud stack — no change to deployment logic. Onboard with a simple CNAME configuration; non-intrusive, zero impact on live business.

Global coverage, local scrubbing

Globally distributed high-defense nodes scrub attack traffic at the network edge, avoiding backhaul congestion; local scrubbing sharply reduces re-injection latency.

Technical specs & scenarios

Traffic diversion

MethodDescriptionBest for
DNS CNAME diversionSmoothly steer traffic to the scrubbing center by changing DNS records; simple, non-intrusive, fast to switch and roll back.Websites, video, API services
BGP route diversionFor bare-IP services, dynamically announce target IP blocks via BGP for transparent牵引 (pull), supporting very large bandwidth in real time.Hosting providers, financial trading
Anycast IP diversionGlobal anycast IP; user traffic auto-connects to the nearest scrubbing node by topology, millisecond-level pull and scrub.Global acceleration, cross-border SaaS

Traffic re-injection

MethodDescriptionBest for
Static IP fixed re-injectionFixed-IP re-injection for legacy systems, returning cleaned traffic via a preset static public IP.Fixed-IP origins, closed networks
Cloud interconnect / VPN tunnelA dedicated channel returns compliant cleaned traffic to the origin — secure, stable, low-latency.Private cloud, cross-region networks

Comparison: AwayDDoS vs native cloud high-defense

DimensionAwayDDoSNative cloud high-defense (client's prior setup)
ScrubbingTwo-layer, >99.9%: Layer 1 dilutes 90% volumetric at the edge; Layer 2 precisely scrubs CC / app-layer attacks.Single layer, ~90%; limited app-layer scrubbing, users still feel pressure.
BlackholeNever blackholes, no matter the attack size; origin stays online; regional isolation keeps the business interruption-free.Protects only within quota; over the quota it blackholes the IP, taking the whole network down until you pay to lift it.
Expert serviceSecurity experts deliver personalized analysis and dynamically tune policies.Standardized self-service; rarely deep per-customer analysis.
Cost modelFixed package with included overage; advance confirmation before any extra — never a surprise attack surcharge.Billed by attack peak and duration; attacks trigger demands to pay for upgrades, or you get blackholed.
Global networkIntegrates Tier-1 carriers (CTG, CMI, NTT) for strong volumetric scrubbing.Mostly in-house clusters; prone to rate-limiting under multi-point global attacks.

Protection Results

After onboarding AwayDDoS, every wave on launch day was defused; the business shifted from "constantly crashing" to "stable throughout." Key metrics (illustrative):

8.6 Tbpspeak attack scrubbed
0origin downtime
Seamlessplayer experience
7×24expert watch
  • Peak 8.6 Tbps attack smoothly scrubbed — massive UDP / TCP floods diluted at the edge, app-layer attacks precisely blocked at the center, origin 0 downtime.
  • Players noticed nothing — logins, matching and battles proceeded normally during the attack, preserving launch reputation and pre-registration conversion.
  • Zero-rework launch — onboarded via DNS protection only; the game backend architecture was untouched, launch rhythm unaffected.

Return on Investment (ROI)

For game publishing, the value of security is not "how many G you blocked," but defending launch reputation and first-wave revenue. Illustrative estimate:

ItemBeforeAfter (AwayDDoS)
Launch availabilityNo high-defense; crashes when attacked, launch failsTwo-layer cleaning holds; launch stable throughout
Origin rework costRetrofitting high-defense needs big re-architectingDNS onboarding, zero rework, live same day
Reputation & retentionLaunch incident causes massive churn & bad reviewsUnaware protection preserves pre-regs & first-wave revenue
Expert inputNo watch; firefighting only after incidents7×24 expert real-time tuning, attacks neutralized on the spot

Conservatively: a single launch incident's player churn and bad reviews far exceed a full year of high-defense spend; AwayDDoS's DNS zero-rework onboarding + 7×24 expert watch holds exactly the "cannot-fail" launch moments steady. Just "avoiding one failed launch" already yields an excellent return.

The real payoff: operations can finally tell the boss, "On launch day, even under a swarm, players felt nothing."