Understanding DDoS protection: what it actually does
Quick answer
DDoS protection defends against attacks that try to overwhelm a server or network with traffic rather than exploiting a software flaw. Always-on mitigation analyses traffic continuously and scrubs out attack traffic in real time, rather than waiting for an attack to be detected before switching on. DDoS protection is included by default on Worldstream servers and can be scaled to a higher mitigation capacity as an add-on.
What a DDoS attack actually is
A distributed denial-of-service (DDoS) attack tries to make a service unavailable by overwhelming it, usually with traffic sent from many sources at once rather than one. That's the "distributed" part: the traffic doesn't come from a single machine you could simply block, it comes from large numbers of hosts, often part of a botnet, all directed at the same target. Attacks generally fall into three broad categories, and a real attack often combines more than one:
- Volumetric floods. The simplest kind conceptually: sheer volume of traffic aimed at a target's network link, trying to consume all the available bandwidth so legitimate traffic can't get through. UDP floods and amplification attacks (where a small request tricks a third-party server into sending a much larger response to the victim) are common examples.
- Protocol attacks. These target weaknesses in how network protocols handle connections rather than raw bandwidth. A SYN flood, for example, opens huge numbers of TCP connections and never completes them, exhausting the connection-tracking resources of a firewall or server rather than its bandwidth.
- Application-layer attacks. The most targeted kind: traffic that looks like normal, valid requests (HTTP requests to a website, for example) but is sent at a volume or pattern designed to exhaust the application itself, its database, or its backend, rather than the network underneath it. Because the traffic looks legitimate at the network level, this category is generally the hardest to distinguish from real users.
Always-on mitigation vs. on-demand mitigation
The distinction that matters most in practice is when mitigation actually engages:
- Always-on mitigation means traffic is continuously analysed as it arrives, attack traffic is scrubbed out, and clean traffic is passed through, all the time, whether or not an attack is currently happening. There's no window where an attack is running unmitigated while a system decides whether to react.
- On-demand mitigation only activates once an attack is detected and traffic is rerouted to scrubbing infrastructure. That detection-and-rerouting step takes time, and during it the target is exposed to at least some of the attack.
Always-on protection removes that detection gap by design, which is why it's the standard approach for anything that can't tolerate downtime at the start of an attack.
Why detection speed and false positives both matter
A mitigation system is judged on two things, not one. Detection speed is the obvious one: the faster attack traffic is identified and scrubbed, the shorter the window of impact. But the false-positive rate matters just as much, and it's easy to overlook. A system that's too aggressive will start blocking or throttling legitimate traffic that merely looks unusual, real users and real requests getting caught in the same net as the attack. Blocking legitimate traffic is also a failure mode, not a safe default, since the practical effect for anyone affected looks the same as the outage the protection was meant to prevent. Well-tuned mitigation has to hold both goals at once: react fast, and avoid mistaking real traffic for an attack.
What Worldstream's DDoS protection actually covers
All Worldstream servers come standard with 20 Gbit/s of anti-DDoS protection, scalable up to 1 Tbit/s+ mitigation capacity. Mitigation is powered by Nokia Deepfield Defender, integrated directly with the network equipment, so suspicious traffic is analysed and filtered at the network level before it reaches your server, not after. That's always-on protection in the sense described above: it's standing by continuously, not switched on only once an attack is already under way. Filtering is tuned to your own risk profile and traffic pattern rather than a single one-size-fits-all threshold, and you can request a mitigation report with the details of a specific attack after it happens.