DDoS Protection

  • protection against denial of service attacks
  • own DDoS protection solution
  • fast scalable DDoS protection

DDoS Protection Details

Free Inquiry Contact form
Bronze DDoS Protection €0.00 per month
Silver DDoS Protection €5.00 per month
Gold DDoS Protection €100.00 per month
Platinum DDoS Protection €500.00 per month
Protected Servers
1
Support
business hours
business hours
business hours
24/7/365
Support Outside Business Hours
€95.20 / h
Mitigation template
standard template
service specific
custom
custom
Individual IP Whitelist/Blacklist
Individual GeoIP Blacklist
Permanent Mitigation
optional
optional
optional
IPv4 Protection
IPv6 Protection
Cleantraffic Included

IP-Projects DDoS-Protection

Internet services are increasingly becoming victims of so-called DDoS (Distributed Denial of Service) attacks. In a DDoS attack, an attempt is made to overload the available bandwidth of a server or to specifically impair the service being operated by making a large number of requests. This results in long loading times or even complete inaccessibility of the service being operated. This type of attack now affects both private individuals and companies, with potential financial damage being the main concern.

IP-Projects' add-on DDoS Protection allows you to distinguish between attack traffic and legitimate traffic routed to your server. We know that DDoS protection is always an individual issue - that's why we support you with different offers, ranging from a basic protection to an individual offer and support.

In-house filtering infrastructure - AS48314

In-house filtering infrastructure - AS48314

IP-Projects has been investing extensively since 2021 in expanding its own external connectivity and building its own filtering solution for DDoS attacks. In addition to using specialized filtering hardware from reputable vendors in the industry, we also rely on in-house developments to accommodate specific customer needs.

IP-Projects DDoS protection is done completely in-house within our self-operated network (AS48314). Because we manage our entire network with several POPs ourselves, the traffic to your server does not take an additional route via external filter providers or their network structures. Higher packet transit times (pings) or data protection concerns are therefore excluded.

Active improvement of DDoS mitigation

Active improvement of DDoS mitigation

When DDoS attacks are received, our NOC (Network Operations Center) is automatically notified to create additional filtering rules and evaluate attacks as needed.

The automatically created samples during a DDoS attack allow us to perform an analysis of the attack patterns even after the attack has ended. Our DDoS experts then review the attacks received in detail through traffic snippets and can continuously improve our protection solution. We are thus able to add new attack patterns to our DDoS mitigation almost daily.

By analyzing the traffic, we can develop individual filters for new applications and games within a short period of time to provide application-level protection as well.

Customized solutions

Customized solutions

In active contact with our customers there is a continuous exchange on the subject of DDoS protection. This enables us to implement new functions as well as customer requests and to take them into account during the implementation in our customer area.

Due to the received customer feedback we constantly extend the provided mitigation templates, which can be selected in the customer area.

If the desired application is not yet included or you would like an individual offer, please feel free to contact us at any time.

Frequently asked questions

all
What is DDoS protection or DDoS protection?
employee photo

DDoS Protection protects your servers, websites or services from so-called distributed denial-of-service attacks. These attacks aim to overload your systems or services with mass requests and make them unavailable. Our protection solution detects and blocks such attacks in real time - automatically and without manual intervention.

Why is DDoS protection important?
employee photo

DDoS protection increases the availability, security and therefore the reputation of your IT infrastructure - especially for publicly accessible services such as websites, stores, game servers, APIs or email systems. As attacks are often automated and carried out by large botnets, countermeasures are becoming increasingly important.

Protection against outages

A DDoS attack (Distributed Denial of Service) aims to flood a server with masses of requests until it becomes unreachable. Without protection, the affected service becomes inaccessible to real users and can often only be restored with the help of the provider.

Avoiding loss of revenue

Particularly in the case of online stores or SaaS services, any outage can cause direct financial damage through lost sales, lost leads or loss of image.

How does DDoS protection work?
employee photo

Our solution constantly analyzes incoming traffic for anomalies (sensoring). As soon as an attack is detected, the malicious traffic is redirected via our Scrubbing Center, normalized and only legitimate traffic is allowed through to the target system. This happens within seconds without affecting your services. In some cases, it may be necessary to route the traffic permanently via our Scrubbing Center - this is known as permanent mitigation.

What types of attacks are detected and defended against?
employee photo

Our DDoS Protection protects against, among other things:

  • Volume-based attacks (UDP floods, amplification)
  • TCP attacks (SYN flood, RST flood)
  • DNS or NTP attacks
  • Mixed vector attacks (complex mixed attacks)
  • Targeted attacks on individual services (mitigation templates)
What is a mitigation template?
employee photo

A mitigation template specifies the rules within the DDoS scrubbing center according to which the traffic is filtered in the event of an attack. In order to enable the most effective filtering of attack traffic, it is advisable to only operate services of the same type per IP. For example, if you host several game servers of different games on one server, you should group them by IP. With our cheapest tariff (Bronze DDoS Protection), you do not have the option of selecting the mitigation template. Here, only a generally valid DDoS protection template is active, which filters for common standard DDoS attacks. If you opt for our Silver DDoS Protection, you can choose from our predefined filter templates for each server IP. These were created in advance by our DDoS specialists. It is not possible to customize these filter templates. If suitable filter templates are missing for your service, our support team can create a customized filter template for a fee. The Gold and Platinum DDoS Protection tariffs include an individual filter template tailored to your needs. Our DDoS specialists create a new filter template to optimally protect your services against manipulation from the Internet.

How do I choose the right DDoS protection offer?
employee photo

If you only rarely expect an attack and your services are not business-critical, our Bronze or Silver DDoS Protection is absolutely sufficient in most cases. If you operate critical services that require an individual filter option, our Gold and Platinum tariffs would be the right choice. Our DDoS specialists will be happy to advise you!

Is IP blacklisting or whitelisting possible?
employee photo

The whitelisting and blacklisting of IP addresses always requires an individual mitigation template. This function is therefore only available with our Gold or Platinum DDoS Protection packages.

Is GeoIP blacklisting possible?
employee photo

Geo-IP (short for geolocation via IP address) refers to the technology used to determine the geographical location of a user based on their IP address. This works by comparing the IP with large databases that assign countries, cities or providers to IP blocks. An individual mitigation template is required to exclude certain countries for your service. We will be happy to work this out for you with our Gold and Silver DDoS Protection tariffs.

What is permanent mitigation?
employee photo

With permanent mitigation, traffic is always routed via our scrubbing center (not just in the event of an attack). This procedure may be necessary in the event of frequent, recurring attacks. It can also be used for testing purposes, for example to optimize filter templates or to check whether the DDoS protection solution is filtering too much traffic or whether the filters need to be adjusted.

Is the protection included with all products?
employee photo

Basic protection is included free of charge with many of our vServer and dedicated products. For particularly sensitive applications, we offer extended protection packages with more capacity, longer mitigation or individual filter templates.

Are Layer 7 DDoS attacks also filtered?
employee photo

No - We do not currently offer granular filtering on layer 7 (e.g. HTTP traffic) with our DDoS protection solution. However, we do provide HTTP flood defense and HTTP connection defense, which offers a kind of basic protection for websites. We also check the data traffic for botnet traffic via an IP reputation database. A web application firewall with SSL offloading is required for complete HTTP protection. This can be booked as part of our firewall tariffs. The WAF also provides basic protection against SQL injections and cross-site scripting attacks.

Do frequent attacks incur additional costs, e.g. for traffic?
employee photo

No, our DDoS protection solution is not billed according to traffic volume or mitigation time. There are no additional hidden costs. However, frequent, highly targeted attacks may require an individual filter template and therefore a tariff upgrade.

Can I be notified about DDoS attacks?
employee photo

Yes - it is possible to use webhooks to receive an automatic notification from our sensors about ongoing DDoS attacks. The following notification methods are currently supported:

  • Email notification
  • Individual webhook
  • Discord webhook
  • Mattermost webhook
  • Slack webhook
  • Telegram bot The messages can be customized using predefined variables. We also offer real-time information about ongoing attacks in our server management.
Show more
Show less

How DDoS Protection Works

1. normal state

By default, when we have provisioned your server, traffic comes directly from our routers to your server. At this point, there is no incoming attack on your server and the services you are running are available without any restrictions. If needed, DDoS protection is available and will join between the router and the server.

2nd detection of an incoming attack

Based on the bandwidth, packet volume and targeted patterns, we are able to automatically detect an attack and activate protection for the attacked IP address.

To do this, we constantly analyze your server's incoming traffic with samples we receive from our routers.

3rd attack filtering

If we detect an incoming attack on your server, we dynamically route the traffic for your server through our multi-layer protection infrastructure. Our filters now discard the attack traffic. Legitimate traffic is forwarded to your server so that your server can continue to provide the services it offers.

To minimize the impact on you, filtering is limited to the attack type or protocols used.

4th end of attack

A DDoS attack becomes very costly for the attacker over time, so attacks are usually stopped if the desired effect does not occur (e.g. server no longer accessible).

As soon as we detect no more attack traffic, your server is automatically removed from the protection infrastructure again and the traffic is routed directly to your server.

Mitigation modes at a glance

By default, we provide our DDoS Mitigation in sensor mode. This is the most recommended mode for most customers. If the attacked server is frequently the target of a DDoS attack, permanent mitigation may also be recommended. Our team of experts will be happy to advise you on this.

Sensor-Mode

in sensor mode, your server is in the filtering infrastructure only in case of attack. In the event of an attack, the protection is switched on within a few seconds and the filtering of the attack begins.

  • Ideal for basic protection, or for sporadic attacks
  • No impact on traffic in normal operation

Permanent Mitigation

Permanent mitigation is recommended for servers that are frequently the victims of DDoS attacks. In this case, the traffic is permanently inspected and attack traffic is immediately discarded without delay.

  • Ideal for game & voice servers and critical applications
  • Need for high availability