The simplest solution is to order anti-DDoS protection from your Internet connection provider. If your provider doesn’t provide such a service, consider changing it to one that uses a professional, carrier-class anti-DDoS system.
Advantages of protection provided directly by the carrier:
- The operator cares as much as you for the system to work correctly and effectively, because he does not want volumetric attacks to unnecessarily burden his network – you simply play to one goal
- Virtually no delays in the delivery of cleaning traffic, because all activities take place within a single network
- Easy management of services in a single panel: preview of saturation of the link, reports from DDoS attacks, possibility of changing the protection plan
- Convenient billing for services on a single invoice.
The anti-DDoS protection system consists of two mechanisms. The first one monitors and regularly samples the your incoming traffic, checking its quality in the carriers’s backbone network – even before it reaches your link. If an anomaly is detected, a second mechanism comes into action. The traffic is redirected to the so-called scrubbing center located on the operator’s servers, where the suspicious part of the traffic is filtered out. The rest, i.e. the legitimate traffic, is sent to the receiver. In situations of extremely heavy attacks, scrubbing may prove inefficient and it is necessary to “cut out” all incoming traffic (it’s called blackholing) until the attack is over. This is an extreme action because it involves the loss of normal, and therefore desirable IP traffic.
This is the general principle of operation, but as with everything: the system is uneven when it comes to efficiency. So what features ensure high effectiveness? Here are the main ones:
- Instant detection of anomalies/attacks and short time from detection to activation of defense procedure (attack mitigation)
- Automatic response (exclusion of unreliable human factor)
- In-depth, self-learning traffic monitoring algorithms based on a global, rich and continuously updated signature database
- Frequent sampling of traffic to look for deviations from the norm
Among Polish providers of B2B Internet access for example Atman offers such a solution. One of the Atman Anti-DDoS system’s unique features is the additionally extended period of sending traffic through the scrubbing center – up to 15 minutes after the observed end of the attack.
In Atman’s experience and analysis, pulsed attacks are quite common, i.e., a few minutes or so after the attack ends, another wave arrives, followed by another wave. If scrubbing is turned off immediately after an attack expires, its new wave must be detected again, and the entire process have to be repeated – like it’s a completely new attack. Extended active protection after an attack in many cases therefore saves the time required to restart it, allowing the Atman client to operate without undue disruption. An additional advantage of Atman Anti-DDoS is the ability to precisely set scrubbing at the level of a single service instead of the entire IP address.
Your Internet providers’s anti-DDoS protection has virtually no weaknesses: it’s permanent, automatic, adjustable (protection plans), and has no side effects in terms of latency or traffic transfer (and thus data transfer) to an external entity. You don’t have to maintain any additional devices or change anything in your network configuration. In addition, the costs are known and therefore easy to budget for because you pay a fixed subscription unaffected by the number, size or duration of attacks.