All systems operational 12 elite locations · Europe & Asia Pay with crypto · 0 KYC
Home / Glossary / What is DDoS protection?
Glossary · DDoS

What is DDoS protection?

VPSbit DDoS still: traffic lines through a filter into a clean rack

How volumetric, protocol and application-layer attacks are filtered at the edge — and what a free tier of DDoS protection honestly covers.

Short answer

DDoS protection is the set of network and edge systems that absorb or filter distributed denial-of-service attacks before they reach your server: scrubbing volumetric floods, defeating protocol state exhaustion and rate-limiting application abuse. On this catalog, Layer 3/4 filtering is included with every plan at every location; what it cannot do is substitute for a tuned application or an honest conversation about Layer 7 ceilings.

What DDoS protection means

A distributed denial-of-service attack is volume aimed at a finite resource: your server's bandwidth, its connection table or its application's capacity. Protection is the machinery that absorbs or discards that volume upstream, so the attack exhausts someone else's scrubbing capacity instead of your machine's. The economics are unflattering: attack capacity is rented by the hour, a booter subscription costs less than a pizza, and the defence has to be standing before the first packet arrives, because mitigation deployed mid-attack is mitigation that arrives late.

The practical question for a VPS buyer is never “does the host have DDoS protection” — every serious host answers yes. The questions that separate products are: which layers are covered, at what ceiling, whether filtering is always-on or bolted on after an incident, and what the host does when an attack arrives that its edge cannot hold — pass it through, or null-route your IP and call it handled.

VPS from $4.80* — Core on the annual term (list $6/mo), one invoice for 12 months, no auto-charges. Dedicated with IPMI from $39.20/mo. Crypto invoice, no KYC.

Launch now

The three layers of attack

Attacks sort into three families by what they exhaust, and each family is measured in its own unit:

LayerExhaustsMeasured inTypical shapes
Volumetric (L3/L4)Bandwidth and packets per secondGbps, MppsUDP floods, DNS/NTP/memcached amplification, ICMP floods
Protocol (L3/L4)Connection state on firewalls and stacksPackets/s, connections/sSYN floods, ACK floods, fragmented-packet abuse
Application (L7)Application work per requestRequests/sHTTP GET/POST floods, slowloris, API hammering, login brute force

The families differ in cost asymmetry. Volumetric attacks are cheap to launch and cheapest to filter, because amplification traffic looks like noise once you know its signature — reflection sources produce requests with telltale payloads. Application attacks invert the maths: each request is small, well-formed and expensive for your backend to answer, which is why a 20 Gbps flood can be shrugged off at the edge while 5,000 requests per second against an unindexed database endpoint takes the site down.

How mitigation actually works

Edge filtering is the first line: stateless access lists drop the signatures that should never reach you — spoofed sources, known amplification vectors, garbage protocols — before packets consume meaningful capacity. Protocol defence comes next: SYN cookies let a stack complete handshakes without storing half-open state, and per-source rate limits stop one address from opening thousands of connections. Upstream, providers announce more specific routes to pull attack traffic into scrubbing centres, or push filters toward the attacker with BGP flowspec; when a pipe is truly saturated, remotely triggered blackholing of the specific destination is the honest last resort, and a good host tells you when it fires.

Tuning is the part brochures skip. The same edge that waves through legitimate traffic must be taught what your normal looks like: which ports are real, which geographies are plausible, what a genuine UDP flow to your game server resembles. That is why filtering included with the plan at L3/L4 — as on every tier of this catalog — is a meaningful baseline, and why application-layer incidents end up being solved with your own web server config, caching and rate limits just as often as with the host's tools. The DDoS-protected VPS guide walks that division of labour with real numbers.

Detection closes the loop. Most attacks announce themselves in graphs you already have: pps or bandwidth suddenly flat-topped, RTT to the box climbing while CPU sits idle, SYN backlog filling. Knowing which attack family you are seeing changes the ticket you file — “volumetric UDP, mostly DNS reflection, started 14:20 UTC” gets a useful answer in minutes, while “site is slow” gets questions. A host that gives you flow-level visibility, or at least answers tickets with what its edge saw, is doing the second half of a service the first half often takes for granted.

What “free DDoS protection” covers — and what it cannot

Included filtering, done honestly, means always-on Layer 3/4 scrubbing at the network edge: volumetric and protocol families handled inside the host's capacity, with no per-attack invoice and no upsell after your first incident. That is the baseline on every VPS plan here, and the L3/L7 scrubber on the Monolith dedicated tier extends the same idea to application-layer floods on metal. What any free tier cannot promise is infinite ceiling: every edge has a capacity, a genuine multi-terabit attack embarrasses everyone, and a host that pretends otherwise is writing marketing fiction.

The second thing included filtering cannot fix is the host's own incentives. Some providers handle overflow by null-routing the attacked IP on first complaint from anyone — which turns a piece of email into an outage, and makes “protection” a service you must beg to keep. This catalog's answer is contractual rather than rhetorical: the 99.95% monthly SLA with bill credits prices downtime, so an overeager null-route costs the host money and is treated accordingly. Check what your current host does under pressure before you need to know.

Why attack-prone projects go offshore for it

Three structural reasons keep recurring. First, jurisdictions: a project that expects takedown-by-attack campaigns wants its infrastructure with a host that does not fold on the first foreign letter, which is the same jurisdiction logic the rest of this glossary describes. Second, incentives: hosts whose filtering is included rather than metered have no reason to let an attack through in order to sell you the cure, and crypto-only billing removes the payment-rail leverage a conventional processor offers whoever complains. Third, posture: an invoice settled in nineteen coins from an email-or-token account means an attacker cannot easily convert a legal complaint into your deplatforming, so the DDoS becomes what it actually is — a network event, handled at the edge.

None of that makes a server unattackable; the honest claim is smaller and more useful. Offshore placement plus included L3/L4 filtering plus an SLA that credits downtime changes who gets to decide when your service is available: not the attacker with a booter budget, and not a random complainant with a mail template — only your own architecture, within the edge's documented capacity.

Is DDoS protection really included with every VPS plan?

On this catalog, yes: Layer 3/4 filtering runs at the edge of every location on every plan, with no per-attack invoice. The Monolith dedicated tier adds an L3/L7 scrubber for application-layer floods on metal.

What size attack can a VPS actually absorb?

Volumetric and protocol attacks are absorbed at the network edge inside the host's capacity, so your plan's port speed matters less than the edge does. Every edge has a ceiling, and a host that publishes its real filtering posture is more trustworthy than one quoting hero numbers.

Does DDoS filtering slow my server down?

Always-on Layer 3/4 filtering adds negligible latency because it discards junk before it reaches you; legitimate packets traverse the same path as they would anyway. Application-layer defences can add processing on requests, which is why they belong tuned to your actual traffic.

Can included protection stop a Layer 7 attack?

Partly: the edge drops malformed and floods-level HTTP, but well-formed requests against an expensive endpoint need your own defences — caching, rate limits, authentication. The DDoS guide on this site shows the split between edge filtering and application tuning.

Why do some hosts null-route attacked servers?

Because it is cheaper than absorbing the attack: blackholing your IP protects their other customers and ends the incident at the cost of your uptime. An SLA that credits downtime makes that trade expensive for the host, which is exactly the point of one.

Ready to launch?

Build the box — VPS or bare metal — create the password, pay the invoice that follows.