network background popup

Data Center Defender (DCD)

Cloud based DDoS protection for network infrastructure


Concerned that your network infrastructure could be a target of malicious traffic?

This is one of the worst scenarios to be in, depending on what type of business you have, a hacker can flood your network with 100’s of Gb/sec of traffic targeting any IPs that are part of your network infrastructure.

Without adequate and tested protection in place your whole data center, websites, applications or corporate network access will cease to function, and you will be at the mercy of your network provider to solve the problem.

We all know how quick network providers are to snap into action and solve problems in a timely fashion!

The misconception

Network engineers employed by corporations or hosting operations are under the impression that their ISP or upstream provider will take care of a large network flood of nuisance traffic that’s overwhelming their link to the Internet.

Without a prearranged agreement in place with your network provider you may be out of luck. Then there are the network providers who claim to be able to handle a DDoS flood of traffic but have little or no experience handling such large volumes of traffic in a timely fashion, especially when the target is rotating on different IPs inside your network.

Reality check

ISP's, hosting providers and network providers will not allow an attack on your network to negatively impact other customers. The immediate solution for them is to null-route or black-hole your IP space, you lose but your provider saves their other customers.

Not sure if your network can handle a DDoS attack on your infrastructure ?

Then you should test it……… Try our DDoS attack platform. Learn more here.

DDoS protection for Network infrastructure

DOSarrest’s Data Center Defender DCD

DOSarrest developed the Datacenter Defender (DCD), specifically to protect network infrastructure, the DCD platform leverages the mitigation engines of DOSarrest’s global network, scrubbing DDoS traffic (volumetric and advanced) and then routing valid traffic on an established clean path back to the customer's Datacenter or network, all within a few seconds.

How it works

Step 1

There are a number of connectivity options, the easiest and fastest setup is to first setup 2 GRE tunnels to 2 different cities within the DOSarrest cloud. Only one is required for operation at any one time and one is for auto failover should there be an issue on a particular tunnel.

Step 2

This service has a number of configuration options as well, the most popular mode is that the customer feeds DOSarrest their Netflow,Sflow or Jflow network data. The customer then defines thresholds on their whole netblock and/or as granular as a single IP address. Once a threshold has been triggered, DOSarrest will advertise the specific class C on the customers behalf that is being attacked, this causes all traffic for that specific Class C to ingress to all of DOSarrest’s scrubbing centers, where it is cleaned and then tunneled back to the customer’s network. The return traffic is routed directly to the Internet visitor from the customers network (Asymmetric routing) This minimizes latency and provides the ultimate performance when under attack. Once the attack has stopped the system will withdraw the customers’ class C advertisement from Dosarrest’s network and the traffic will ingress and egress from the Customer’s network as it normally does.
This is all done automatically!

Your network infrastructure is completely protected 24/7 and monitored by our 24/7/365 SOC and you can also login and see the attack and mitigation in near real-time.

Why Use DOSarrest’s Data Center Defender Platform ?

  • Protect any amount of IP space in any global location
  • Volumetric traffic anomalies are continuously monitored every few seconds
  • AI generated rulesets- analyzes traffic, packet by packet for sophisticated anomalies in near real-time (10Sec) and blocks the malicious traffic
  • Immediate intelligent mitigation, no traffic learning period required
  • Asymmetric routing for ultimate performance
  • Define thresholds on a single IP address or as large as a /16 network
  • Traffic analysis – See what’s passing through any interface inside your network real-time using our customer portal
  • Reporting - Interactive graphical displays for historical and real-time stats with “one click” filters
  • Multiple configuration options, Always-on, on-demand and auto fail-back
  • Multiple connectivity options, GRE tunnels, exchange points or direct connect
  • Stateless operation allows for asynchronous traffic analysis and mitigation
  • Employs 3rd party reputation-based databases to block known malicious IPs & domains
  • Supports permanent blacklists and/or whitelists
  • All traffic types are analyzed including MPLs traffic, great for NSP’s

Click Here To View Pricing

There are 3 options available to configure the DCD platform:

BGP Based Trigger

In this type of configuration, customers configure a BGP session with DOSarrest, over which they can announce their netblocks anytime. This will cause all visitors to that netblock to come into the DOSarrest network, where the attack traffic will be scrubbed, and clean traffic tunneled/routed back to the customer network.

Control method: Customer controlled

Modes of Operation: “Always on” or “hotstandby”

Connectivity Options: GRE, IPsec, direct connect, MPLS/VPLS, Equinix Cloud Exchange, Cloud WAN.

Flow Based Trigger

For customers who do not have BGP capabilities and/or would like to have automated mitigation in place and are able to export Network Flows (Netflow/Jflow/Sflow) to the DCD platform. The DCD platform will analyze incoming flows, and automatically modify routing for effected netblocks and immediately mitigate the attack once it starts to come into the DOSarrest network. Once the attack is over, routing is restored back to normal.

Control method: Automatic

Modes of Operation: “Always on” or “hotstandby”

Connectivity Options: GRE, IPsec, direct connect, MPLS/VPLS, Equinix Cloud Exchange, Cloud WAN.

Secure Stack

For customers who are not able to do option 1 or 2, and have a server or stack that needs DDoS protection. Typical customers of this service are organizations who are co-locating their servers, or using a public cloud (eg. AWS or Rackspace).

Users of this service are allocated a Secured DOSarrest IP/IP’s, which they configure on their servers. A tunnel is created from the DOSarrest network to the server(s), over which the Secured IP(s) is routed.

Control method: Customer controlled

Modes of Operation: “Always on” or “hotstandby”

Connectivity Options: GRE or IPsec.

The DCD platform is supported 24/7/365 by our SOC and can be a fully managed service.