DDoS
mitigation
ACL filtering is included on every plan, up to your port's full capacity. Clean-pipe scrubbing with Arbor and NexusGuard scales past 6 Tbit/s and 1 billion packets per second.
- Unmetered auto-mitigation, 24/7
- Unlimited clean return, up to your port
- Flowspec, Peakflow and clean-pipe scrubbing

Peakflow during a real mixed attack. About 1.6 Tbit/s in, a few hundred Mbit/s of clean traffic out.
5+ Tbit/s
Scrubbing capacity
1+ Bpps
Packet capacity
88+ / week
Attacks mitigated
<15 sec
Time to mitigate
Protection stack
Four layers, one path
ACL at the port. Flowspec and blackhole on the backbone. Peakflow and clean-pipe Arbor / NexusGuard for the rest.
1
ACL filtering
Included on every plan, up to your port's full capacity.
2
BGP Flowspec
RFC 8955 on every core and edge router. Line-rate volumetric filtering.
3
Arbor Peakflow TPS
Stateful DPI and TCP. 1.6 Tbps per centre, seven centres. Clean return on every Cisco and Ciena border.
4
Clean-pipe scrubbing
Arbor and NexusGuard. Past 6 Tbit/s and 1 billion packets per second.
Clean pipe
Divert, scrub, return
When a host is under attack, all traffic for that host goes to the nearest scrubber. Malicious packets drop. Genuine traffic comes back. That covers volumetric floods and most application attacks, against 99.6 Tbit/s of backbone capacity.
1
Divert
Traffic for the host goes to the nearest scrubber.
2
Scrub
Malicious packets drop. Genuine traffic stays.
3
Return
Clean traffic comes back, up to your port size.

Unlimited clean traffic
Genuine traffic comes back with no hidden cap, up to your port size.
Unmetered auto-mitigation
Automatic mitigation 24/7. No counting of minutes or days.
Unlimited prefixes
No limit on prefixes or subnets. IPv4 and IPv6.
Self-managed profiles
You set thresholds, network objects and profiles. Smart detection included.

See it in action
A real flood, dropped before origin
Live Peakflow. Mixed inbound around 1.5 to 1.6 Tbps, egress still in the hundreds of Mbps. Detection runs on NetHarrier.
Confirmed events are fingerprinted and matched to pcaps, then Flowspec, Peakflow or Arbor / NexusGuard. Same path as a DNS amplification flood at 1 Tbit/s and 600 million packets per second.
Collect
sFlow from routers and switches, SNMP for interface counters. Volume from SNMP, mix from the samples.
Enrich
Each flow gets interface, prefix, ASN, country and routing context while it is still moving.
Detect
One-second windows in memory against a learned baseline. Confirmed events are fingerprinted and matched to pcaps. Low sample counts show a range, never a fake zero.
Respond
Flowspec, RTBH or Peakflow after prefix checks and never-mitigate lists. Arbor and NexusGuard take over when the flood still needs stateful DPI.
Normal
Threshold-based. Samples at minute granularity.
Rapid
Same thresholds, second-level sampling. Faster trigger on short bursts.
Smart
Machine learning on historical netflow. Learns season, time of day and natural growth. No static threshold to babysit.
Coverage
Attack types we mitigate
Not exhaustive. Volumetric, protocol and application vectors are in scope.
Volumetric
- UDP flood and UDP fragmentation
- DNS amplification and DNS flood
- NTP amplification and NTP flood
- SSDP amplification
- Memcached
- Fraggle, Smurf, non-spoofed UDP
Protocol
- SYN, SYN-ACK, ACK / ACK-PUSH, RST/FIN
- TCP null, TCP connection flood, fragmented ACK
- Fake session, LAND, TOS flood, IP NULL
- ICMP flood, ICMP fragmentation, ping flood
- Source half-open and idle connections
Application
- HTTP flood and HTTP slow
- SSL/TLS malformed, renegotiation, per-source session
- SIP malformed, spoofing, REGISTER and INVITE floods
Packet path
Malicious drops. Clean continues.
Flowspec and Peakflow TPS on the path. Flood traffic is discarded. Legitimate packets reach your prefix.
Trivox Firewall · packet filter
Flowspec + Peakflow TPSInternet
Mixed traffic
Your prefix
Clean traffic
BGP controls
Blackhole and Flowspec
Complimentary with IP transit. Use them on their own or in front of Peakflow.
Traffic deprioritisation
Automated passive watchguard. Malicious traffic gets the lowest priority and is first discarded if a link congests.
Blackhole community
Discard traffic to a prefix, IPv4 and IPv6, down to a /32 or /128. Dropped at backbone ingress.
Extended UDP blackhole
Drop all UDP, or only known amplifiers and fragmented UDP. Everything else still passes.
Customer Flowspec
You announce the filters. Dry-run first, then a TTL. They apply on routers, so there is no scrubber bottleneck.
Operations
24/7 NOC
The stack runs on its own. Alerts go out when a mitigation starts. The Trivox NOC is reachable around the clock for special rules and low-volume patterns.
- noc@trivox.sh
- Special rules and low-volume pattern detection
- Monthly service report
Live traffic
Utilization, type and source. Switch bps and pps. Month, week, day or hour.
Event replay
Replay a mitigation. Size, duration, origin and traffic mix. Ingress vs egress.
Search and sort
Find events by multiple fields. Breakdown of the most common traffic types.