Protection Architecture

DDoS Protection Solutions

Two-layer scrubbing architecture plus intelligent global routing. From onboarding to clean origin return, attacks are washed away mid-path.

The core challenge: attacks arrive in layers

Modern DDoS campaigns are never a single technique. A typical attack combines three layers at once:

  • Volumetric floods — UDP floods and NTP/DNS reflection amplification generating hundreds of Gbps to Tbps, aimed at saturating your uplink.
  • Protocol attacks — SYN and ACK floods exhausting the connection tables of servers and firewalls. Tens of Gbps is often enough to render equipment unresponsive.
  • Application-layer attacks — CC attacks, HTTP floods, and malicious crawlers disguised as normal users. Traffic may be only a few Mbps, yet it can break your business logic.

These three categories require fundamentally different detection and mitigation. This is precisely why single-layer protection inevitably fails: it can only be effective at one layer, and attacks from the others slip through the gaps.

The two-layer scrubbing architecture

AwayDDoS uses a two-layer cleaning architecture that routes each type of attack to the stage best suited to handle it:

Layer 1 · Near-source scrubbing

Global edge nodes sit at major internet exchange hubs. When an attack begins, traffic is diverted and diluted at the point nearest the attack source — attack traffic never competes with the path between you and your legitimate users, and volumetric peaks are flattened within seconds.

Layer 2 · Deep cleaning

Partially diluted traffic then enters scrubbing centers for protocol consistency validation, session behavior analysis, and traffic baseline modeling. This layer catches attacks that "look normal": spoofed-source protocol packets, browser-mimicking CC requests, and low-and-slow crawlers.

Clean traffic returns home

Only traffic that passes both layers returns to your origin over the intelligent shortest path. Your origin only ever sees real users — no additional hardware, and no awareness that an attack occurred.

Defense matrix: eight attack vectors

These are the primary attack types we handle in production, with the corresponding defenses:

Attack vectorLayerTypical scaleDefense
UDP floodL3/L4100 Gbps – 1 TbpsNear-source dilution + protocol validation
DNS / NTP reflectionL3/L450x amplification possibleReflector filtering + rate limiting
SYN floodL4Tens of GbpsSYN cookies + connection table protection
ACK / RST floodL4Tens of GbpsState inspection + malformed packet drop
CC attackL7May be only a few MbpsBehavior analysis + bot challenges
HTTP floodL7Thousands of QPSRate baselines + precise throttling
Malicious crawlersL7Low and slowFingerprinting + reputation feeds
Spoofed game-protocol packetsL4/L7Highly variableProtocol consistency + session tracking

Three deployment models compared

Different business shapes suit different onboarding methods. Here is the full comparison:

DimensionDNS steeringGRE / BGP tunnelProtected hosting
OnboardingUpdate DNS recordsEstablish tunnel; no architecture changeDeploy directly in our facility
Time to effectMinutesHours (configuration required)Immediate on provisioning
ScopeSingle domain / siteEntire subnet / IP rangeOne or a group of servers
Ops overheadVery lowMedium (network config skills)Zero
Best forWebsites, APIs, login servicesOwn racks, hybrid cloud, IDCSmall teams without dedicated ops
Origin hiddenYesYesInherent
Recommendation★★★★★★★★★★★★★

DNS steering: fastest to deploy

Point your domain's DNS at protection nodes and traffic is automatically scrubbed before reaching your origin. The advantages are minutes-level effectiveness, zero ops overhead, and no architectural changes — the default choice for most websites and API services. Note that on first onboarding you must properly hide your origin IP, otherwise attackers can still bypass protection and hit the origin directly.

GRE / BGP tunnel: protect an entire subnet

Using GRE tunnels or BGP announcements, your IP range is steered into our scrubbing centers. Ideal for teams that run their own racks and need to protect non-HTTP traffic (gaming, mail, custom protocols). Protection is not limited to ports 80/443 — it covers all traffic to the subnet.

Protected hosting: zero operations

Deploy your services directly in our protected facility. The origin is inherently hidden and no protection configuration is required. Ideal for small and mid-sized businesses without dedicated ops teams, or teams that prefer to fully outsource security responsibility.

Global scrubbing nodes and intelligent routing

Protection quality ultimately depends on node distribution and scheduling quality. AwayDDoS covers these major regions:

Hong Kong, ChinaSingaporeTokyo SeoulLos AngelesSan Jose FrankfurtLondonDubai Sydney

Our intelligent routing system continuously probes each node's latency, packet loss, and availability to an origin, dynamically selecting the optimal return path. When a link becomes congested or fails, traffic switches to a backup path within seconds — invisibly to users.

For cross-border businesses this step is critical: it determines whether protection introduces latency. Our routing target is straightforward — after enabling protection, latency for legitimate users should go down, not up.

During an attack, our experts are with you

Even the best equipment cannot fully replace human judgment. Attackers change tactics daily, and rules need real-time adjustment. AwayDDoS provides:

  • 7×24 expert operations — attacks do not keep office hours, and neither does our response.
  • Proactive intervention — we detect anomalies, notify you, and intervene without waiting for repeated tickets.
  • Post-attack reports — traffic analysis and mitigation effectiveness, ready to share with management or customers.
  • A dedicated technical contact — a consistent team that knows your traffic characteristics over time.

Fixed pricing. Never blackholed.

This is our most important commitment, and the most fundamental difference from many providers.

During an attack: no blackholing, no surge pricing.

Many providers null-route your IP once attack traffic exceeds your plan — the attacker succeeds and your business goes completely offline. That kind of "protection" effectively finishes the attacker's job for them. See What Is DDoS Blackholing?

AwayDDoS uses a fixed-fee model: no matter how large the attack, the cost does not change. This aligns our interests completely with your uptime — scrubbing the attack clean is our only optimal move.

Frequently asked questions

Do I need to change my architecture to onboard?

Usually not. The most common approach is a DNS change, effective in minutes. To protect an entire subnet, GRE / BGP tunnels are available.

Will you blackhole me if an attack exceeds my plan?

No. We commit to no blackholing and no surge pricing during an attack, with no hard cap on scrubbing capacity.

How is two-layer cleaning different from single-layer?

Single-layer cleaning fails against mixed attacks. Two layers split the work: near-source scrubbing dilutes the peak, then deep cleaning filters precisely — handling volumetric and application-layer attacks simultaneously.

Do CC attacks need the same defense as volumetric DDoS?

No. Volumetric attacks are handled by scrubbing and rate limiting. CC attacks hit business resources with tiny traffic volumes and require behavior analysis and bot challenges. See CC Attack vs DDoS.