DDoS Protection Solutions
Two-layer scrubbing architecture plus intelligent global routing. From onboarding to clean origin return, attacks are washed away mid-path.
The core challenge: attacks arrive in layers
Modern DDoS campaigns are never a single technique. A typical attack combines three layers at once:
- Volumetric floods — UDP floods and NTP/DNS reflection amplification generating hundreds of Gbps to Tbps, aimed at saturating your uplink.
- Protocol attacks — SYN and ACK floods exhausting the connection tables of servers and firewalls. Tens of Gbps is often enough to render equipment unresponsive.
- Application-layer attacks — CC attacks, HTTP floods, and malicious crawlers disguised as normal users. Traffic may be only a few Mbps, yet it can break your business logic.
These three categories require fundamentally different detection and mitigation. This is precisely why single-layer protection inevitably fails: it can only be effective at one layer, and attacks from the others slip through the gaps.
The two-layer scrubbing architecture
AwayDDoS uses a two-layer cleaning architecture that routes each type of attack to the stage best suited to handle it:
Layer 1 · Near-source scrubbing
Global edge nodes sit at major internet exchange hubs. When an attack begins, traffic is diverted and diluted at the point nearest the attack source — attack traffic never competes with the path between you and your legitimate users, and volumetric peaks are flattened within seconds.
Layer 2 · Deep cleaning
Partially diluted traffic then enters scrubbing centers for protocol consistency validation, session behavior analysis, and traffic baseline modeling. This layer catches attacks that "look normal": spoofed-source protocol packets, browser-mimicking CC requests, and low-and-slow crawlers.
Clean traffic returns home
Only traffic that passes both layers returns to your origin over the intelligent shortest path. Your origin only ever sees real users — no additional hardware, and no awareness that an attack occurred.
Defense matrix: eight attack vectors
These are the primary attack types we handle in production, with the corresponding defenses:
| Attack vector | Layer | Typical scale | Defense |
|---|---|---|---|
| UDP flood | L3/L4 | 100 Gbps – 1 Tbps | Near-source dilution + protocol validation |
| DNS / NTP reflection | L3/L4 | 50x amplification possible | Reflector filtering + rate limiting |
| SYN flood | L4 | Tens of Gbps | SYN cookies + connection table protection |
| ACK / RST flood | L4 | Tens of Gbps | State inspection + malformed packet drop |
| CC attack | L7 | May be only a few Mbps | Behavior analysis + bot challenges |
| HTTP flood | L7 | Thousands of QPS | Rate baselines + precise throttling |
| Malicious crawlers | L7 | Low and slow | Fingerprinting + reputation feeds |
| Spoofed game-protocol packets | L4/L7 | Highly variable | Protocol consistency + session tracking |
Three deployment models compared
Different business shapes suit different onboarding methods. Here is the full comparison:
| Dimension | DNS steering | GRE / BGP tunnel | Protected hosting |
|---|---|---|---|
| Onboarding | Update DNS records | Establish tunnel; no architecture change | Deploy directly in our facility |
| Time to effect | Minutes | Hours (configuration required) | Immediate on provisioning |
| Scope | Single domain / site | Entire subnet / IP range | One or a group of servers |
| Ops overhead | Very low | Medium (network config skills) | Zero |
| Best for | Websites, APIs, login services | Own racks, hybrid cloud, IDC | Small teams without dedicated ops |
| Origin hidden | Yes | Yes | Inherent |
| Recommendation | ★★★★★ | ★★★★ | ★★★★ |
DNS steering: fastest to deploy
Point your domain's DNS at protection nodes and traffic is automatically scrubbed before reaching your origin. The advantages are minutes-level effectiveness, zero ops overhead, and no architectural changes — the default choice for most websites and API services. Note that on first onboarding you must properly hide your origin IP, otherwise attackers can still bypass protection and hit the origin directly.
GRE / BGP tunnel: protect an entire subnet
Using GRE tunnels or BGP announcements, your IP range is steered into our scrubbing centers. Ideal for teams that run their own racks and need to protect non-HTTP traffic (gaming, mail, custom protocols). Protection is not limited to ports 80/443 — it covers all traffic to the subnet.
Protected hosting: zero operations
Deploy your services directly in our protected facility. The origin is inherently hidden and no protection configuration is required. Ideal for small and mid-sized businesses without dedicated ops teams, or teams that prefer to fully outsource security responsibility.
Global scrubbing nodes and intelligent routing
Protection quality ultimately depends on node distribution and scheduling quality. AwayDDoS covers these major regions:
Our intelligent routing system continuously probes each node's latency, packet loss, and availability to an origin, dynamically selecting the optimal return path. When a link becomes congested or fails, traffic switches to a backup path within seconds — invisibly to users.
For cross-border businesses this step is critical: it determines whether protection introduces latency. Our routing target is straightforward — after enabling protection, latency for legitimate users should go down, not up.
During an attack, our experts are with you
Even the best equipment cannot fully replace human judgment. Attackers change tactics daily, and rules need real-time adjustment. AwayDDoS provides:
- 7×24 expert operations — attacks do not keep office hours, and neither does our response.
- Proactive intervention — we detect anomalies, notify you, and intervene without waiting for repeated tickets.
- Post-attack reports — traffic analysis and mitigation effectiveness, ready to share with management or customers.
- A dedicated technical contact — a consistent team that knows your traffic characteristics over time.
Fixed pricing. Never blackholed.
This is our most important commitment, and the most fundamental difference from many providers.
During an attack: no blackholing, no surge pricing.
Many providers null-route your IP once attack traffic exceeds your plan — the attacker succeeds and your business goes completely offline. That kind of "protection" effectively finishes the attacker's job for them. See What Is DDoS Blackholing?
AwayDDoS uses a fixed-fee model: no matter how large the attack, the cost does not change. This aligns our interests completely with your uptime — scrubbing the attack clean is our only optimal move.
Frequently asked questions
Do I need to change my architecture to onboard?
Usually not. The most common approach is a DNS change, effective in minutes. To protect an entire subnet, GRE / BGP tunnels are available.
Will you blackhole me if an attack exceeds my plan?
No. We commit to no blackholing and no surge pricing during an attack, with no hard cap on scrubbing capacity.
How is two-layer cleaning different from single-layer?
Single-layer cleaning fails against mixed attacks. Two layers split the work: near-source scrubbing dilutes the peak, then deep cleaning filters precisely — handling volumetric and application-layer attacks simultaneously.
Do CC attacks need the same defense as volumetric DDoS?
No. Volumetric attacks are handled by scrubbing and rate limiting. CC attacks hit business resources with tiny traffic volumes and require behavior analysis and bot challenges. See CC Attack vs DDoS.