DDoS protection is a service that spots attack traffic aimed at your IP addresses and filters it out upstream, in the carrier's network or a scrubbing centre, before it reaches your circuit. Your own firewall cannot do this for a large attack, because by the time the flood arrives at your building the circuit is already full. The buying decisions are where the filtering happens, how quickly it starts, and what it costs when it does.
Most businesses never think about DDoS until the morning the internet goes solid and the carrier tells them the circuit is "up." It is up. It is carrying nothing but garbage. This guide explains what is happening in that moment, where protection can sit, and how to read the offers you will be given.
What a DDoS attack is
A distributed denial-of-service attack sends a target more traffic, or more requests, than it can handle, from many sources at once. The word "distributed" is why it is hard to block. The traffic comes from thousands of hijacked devices, rented servers and misconfigured systems all over the internet, so there is no single address you can shut off.
Launching one is cheap, which is why size is not much protection. A business can be hit because of a public dispute, an unhappy former user, a competitor, a random scan that found an open service, or simply because it shares an address range with someone else who was the real target.
The three broad types
| Type | How it works | What it exhausts | Where it has to be stopped |
|---|---|---|---|
| Volumetric | Raw volume, often using "amplification": attackers send small requests to open DNS, NTP or similar servers, which reply to you with far larger answers | Your circuit's bandwidth | Upstream, before traffic reaches your circuit |
| Protocol | Abuses how connections are set up, for example SYN floods that leave thousands of half-open connections | Firewall and server connection tables | Upstream, or at an edge device built to absorb it |
| Application layer | Requests that look normal, such as repeated logins or searches, at a rate the application cannot serve | The web server or application | A web application firewall, CDN or the application itself |
Real attacks often combine them. For an office on a dedicated circuit, the volumetric kind is the one that takes everybody offline at once, including the phones.
Why your firewall cannot save you
Picture a 1 Gbps circuit and an attack of several gigabits per second aimed at one of your addresses. The carrier's router at the far end of your circuit can only hand you 1 Gbps. Everything above that is dropped at the carrier's edge, and the router does not know which packets are the attack and which are your customer's email or your staff's Teams call. Legitimate traffic loses in the scramble.
Your firewall sits on the far side of that bottleneck. It can inspect and drop whatever it receives, but it only receives what fits down the pipe, and the pipe is already full of junk. A firewall that tries to track every bogus connection can also run out of memory and fall over on its own. That is why the cybersecurity answer to volumetric attacks is always upstream scrubbing, with the firewall handling what remains.
Where protection can sit
Carrier-based mitigation
Many carriers sell DDoS protection as an add-on to a dedicated internet circuit. The carrier watches traffic flow data for your addresses. When it sees an attack, it diverts traffic headed for you through scrubbing equipment in its network, drops the attack traffic, and delivers what is left down your normal circuit. There is little to configure on your side, which is its main appeal.
The limitation is that it protects only that carrier's circuit. If you run a second circuit from another carrier, that circuit and its addresses need their own protection.
Cloud scrubbing services
Independent providers run large scrubbing networks that work across carriers. During an attack, traffic for your addresses is redirected to them, usually by announcing your address block over BGP, then clean traffic is returned to you through a tunnel or a direct connection. This needs address space you control, and on the public internet an IPv4 announcement generally has to be at least a /24 (256 addresses) to be accepted. Our guide to static IPs and BGP explains what that involves.
Remotely triggered black hole
The blunt option. The carrier simply drops all traffic to the attacked address, so the rest of your circuit recovers. The attacked address, and whatever runs on it, stays offline until the attack stops. It is often free and it is a useful last resort, but notice that it finishes the attacker's job for them. When a carrier says a circuit "includes DDoS protection," ask whether this is what they mean.
CDN and web application firewall
If your public presence is a website hosted somewhere else, its protection belongs with that host or a content delivery network in front of it. Buying scrubbing for your office circuit does nothing for a site that does not live there.
Always-on or on-demand
| Always-on | On-demand (detect and divert) | |
|---|---|---|
| Normal traffic path | Always passes through scrubbing | Direct; diverted only when an attack is detected |
| Time to start mitigating | Immediate | Minutes, depending on detection and whether diversion is automatic or needs a call |
| Effect on latency | Possible small addition | None until diverted |
| Relative cost | Generally higher | Generally lower |
| Good fit | Services that cannot tolerate even a few minutes of disruption | Most offices |
For most businesses, on-demand with automatic diversion is the sensible middle. The few minutes between detection and mitigation are the price of not paying for always-on.
The terms that decide what you are buying
- Which addresses are covered. Every IP on the circuit, or a named list.
- Mitigation capacity. Is there a cap on attack size, and what happens above it?
- Detection. Is it based on thresholds you agree, on a learned baseline, or on you calling in?
- Time to mitigate. Is a target written into the contract, and does it carry credits like the rest of your SLA?
- Activation. Automatic, or does someone have to approve the diversion at 2am?
- Pricing model. Flat monthly, per incident, or a monthly fee with a limit on the number of attacks.
- Reporting. Will you get a record of each attack, its size and what was dropped?
- Tuning. How are false positives handled, so a legitimate traffic spike is not scrubbed away?
Who needs it, and who probably does not
Consider protection seriously if any of these are true:
- Staff reach the office through a VPN on your circuit, so an attack on that address stops remote work.
- You host anything customers or partners reach directly: a portal, a server, a phone system.
- Your own clients hold you to uptime commitments.
- You have been attacked before, or someone has an obvious motive.
An office whose only exposure is outbound browsing and cloud apps, with its website hosted elsewhere, has less to lose. It can still be hit, but the damage is usually an interrupted afternoon, and a backup circuit on a different carrier, with different addresses, often does more for it than scrubbing would.
A worked example
Every figure here is a hypothetical illustration, not a quote, a real client or a measured attack.
Suppose a 40-person firm runs a 1 Gbps DIA circuit. Staff working from home connect through a VPN on one of its static addresses, and the office desk phones run over the same circuit to a hosted phone platform. At 10am a 15 Gbps amplification attack hits the VPN address. That is fifteen times the circuit's capacity.
Without protection: the circuit saturates, so the VPN, the desk phones and every cloud app stop working together. After some time the carrier black-holes the VPN address, the office recovers, and remote staff stay cut off until the attack ends. If it runs for three hours and the firm values staff time at $3,000 an hour, that is about $9,000 of lost work, before any missed calls.
With on-demand carrier protection: detection and automatic diversion take, say, ten minutes. After that, traffic for all the firm's addresses passes through scrubbing and clean traffic comes down the circuit. The firm loses ten degraded minutes instead of three hours.
Whether that is worth buying depends on the monthly price you are quoted and how likely an attack is. Put the quoted fee next to your own version of the $9,000 figure, and the decision usually makes itself one way or the other.
Questions to ask your carrier
- Is your DDoS protection scrubbing, or black-holing? If both, when do you use each?
- Is diversion automatic, and what is the committed time to mitigate?
- Is there a maximum attack size, and what happens beyond it?
- Does it cover every address on my circuit, including IPv6?
- Is it priced flat, per attack, or with a cap on incidents?
- Will I receive a report after each attack?
- If I add a second circuit from another carrier, how would you protect both?
Getting it priced properly
DDoS protection is quoted very differently from carrier to carrier, and the cheapest line on a quote is sometimes just a black hole with a nicer name. When several carriers bid on your circuit, we put their protection terms side by side with the price, and we will tell you plainly if your exposure does not justify it. If you want the firewall side handled too, see managed network. The quote is free with no obligation and you usually hear back the same day: send us your address, call 478-758-8091 or text (347) 870-0965.