DDoS
mitigation

ACL filtering is included on every plan, up to your port's full capacity. Clean-pipe scrubbing with Arbor and NexusGuard scales past 6 Tbit/s and 1 billion packets per second.

  • Unmetered auto-mitigation, 24/7
  • Unlimited clean return, up to your port
  • Flowspec, Peakflow and clean-pipe scrubbing
Peakflow during a mixed volumetric attack around 1.6 Tbps. Ingress about 1.6 Tbit/s, egress in the hundreds of Mbps.

Peakflow during a real mixed attack. About 1.6 Tbit/s in, a few hundred Mbit/s of clean traffic out.

5+ Tbit/s

Scrubbing capacity

1+ Bpps

Packet capacity

88+ / week

Attacks mitigated

<15 sec

Time to mitigate

AMD Logo
Intel Logo
RIPE NCC Logo
Bytenode Logo
Backbone Logo
BakkerIT Logo
Protection stack

Four layers, one path

ACL at the port. Flowspec and blackhole on the backbone. Peakflow and clean-pipe Arbor / NexusGuard for the rest.

1

ACL filtering

Included on every plan, up to your port's full capacity.

2

BGP Flowspec

RFC 8955 on every core and edge router. Line-rate volumetric filtering.

3

Arbor Peakflow TPS

Stateful DPI and TCP. 1.6 Tbps per centre, seven centres. Clean return on every Cisco and Ciena border.

4

Clean-pipe scrubbing

Arbor and NexusGuard. Past 6 Tbit/s and 1 billion packets per second.

Clean pipe

Divert, scrub, return

When a host is under attack, all traffic for that host goes to the nearest scrubber. Malicious packets drop. Genuine traffic comes back. That covers volumetric floods and most application attacks, against 99.6 Tbit/s of backbone capacity.

1

Divert

Traffic for the host goes to the nearest scrubber.

2

Scrub

Malicious packets drop. Genuine traffic stays.

3

Return

Clean traffic comes back, up to your port size.

DDoS mitigation on the Trivox network

Unlimited clean traffic

Genuine traffic comes back with no hidden cap, up to your port size.

Unmetered auto-mitigation

Automatic mitigation 24/7. No counting of minutes or days.

Unlimited prefixes

No limit on prefixes or subnets. IPv4 and IPv6.

Self-managed profiles

You set thresholds, network objects and profiles. Smart detection included.

Live DDoS events under mitigation on Peakflow
See it in action

A real flood, dropped before origin

Live Peakflow. Mixed inbound around 1.5 to 1.6 Tbps, egress still in the hundreds of Mbps. Detection runs on NetHarrier.

Confirmed events are fingerprinted and matched to pcaps, then Flowspec, Peakflow or Arbor / NexusGuard. Same path as a DNS amplification flood at 1 Tbit/s and 600 million packets per second.

Collect

sFlow from routers and switches, SNMP for interface counters. Volume from SNMP, mix from the samples.

Enrich

Each flow gets interface, prefix, ASN, country and routing context while it is still moving.

Detect

One-second windows in memory against a learned baseline. Confirmed events are fingerprinted and matched to pcaps. Low sample counts show a range, never a fake zero.

Respond

Flowspec, RTBH or Peakflow after prefix checks and never-mitigate lists. Arbor and NexusGuard take over when the flood still needs stateful DPI.

Normal

Threshold-based. Samples at minute granularity.

Rapid

Same thresholds, second-level sampling. Faster trigger on short bursts.

Smart

Machine learning on historical netflow. Learns season, time of day and natural growth. No static threshold to babysit.

Coverage

Attack types we mitigate

Not exhaustive. Volumetric, protocol and application vectors are in scope.

Volumetric

  • UDP flood and UDP fragmentation
  • DNS amplification and DNS flood
  • NTP amplification and NTP flood
  • SSDP amplification
  • Memcached
  • Fraggle, Smurf, non-spoofed UDP

Protocol

  • SYN, SYN-ACK, ACK / ACK-PUSH, RST/FIN
  • TCP null, TCP connection flood, fragmented ACK
  • Fake session, LAND, TOS flood, IP NULL
  • ICMP flood, ICMP fragmentation, ping flood
  • Source half-open and idle connections

Application

  • HTTP flood and HTTP slow
  • SSL/TLS malformed, renegotiation, per-source session
  • SIP malformed, spoofing, REGISTER and INVITE floods
Packet path

Malicious drops. Clean continues.

Flowspec and Peakflow TPS on the path. Flood traffic is discarded. Legitimate packets reach your prefix.

Trivox Firewall · packet filter

Flowspec + Peakflow TPS

Internet

Mixed traffic

Trivox firewall

Your prefix

Clean traffic

Forwarded
Dropped
BGP controls

Blackhole and Flowspec

Complimentary with IP transit. Use them on their own or in front of Peakflow.

Traffic deprioritisation

Automated passive watchguard. Malicious traffic gets the lowest priority and is first discarded if a link congests.

Blackhole community

Discard traffic to a prefix, IPv4 and IPv6, down to a /32 or /128. Dropped at backbone ingress.

Extended UDP blackhole

Drop all UDP, or only known amplifiers and fragmented UDP. Everything else still passes.

Customer Flowspec

You announce the filters. Dry-run first, then a TTL. They apply on routers, so there is no scrubber bottleneck.

Operations

24/7 NOC

The stack runs on its own. Alerts go out when a mitigation starts. The Trivox NOC is reachable around the clock for special rules and low-volume patterns.

  • noc@trivox.sh
  • Special rules and low-volume pattern detection
  • Monthly service report

Live traffic

Utilization, type and source. Switch bps and pps. Month, week, day or hour.

Event replay

Replay a mitigation. Size, duration, origin and traffic mix. Ingress vs egress.

Search and sort

Find events by multiple fields. Breakdown of the most common traffic types.