Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. Understanding DDoS protection: what it actually does

Understanding DDoS protection: what it actually does

Applies to Dedicated Servers, Flexible VPSAudience Technical evaluator, existing customerLast reviewed September 2026

Quick answer

DDoS protection defends against attacks that try to overwhelm a server or network with traffic rather than exploiting a software flaw. Always-on mitigation analyses traffic continuously and scrubs out attack traffic in real time, rather than waiting for an attack to be detected before switching on. DDoS protection is included by default on Worldstream servers and can be scaled to a higher mitigation capacity as an add-on.

On this page
  • What a DDoS attack actually is
  • Always-on mitigation vs. on-demand mitigation
  • Why detection speed and false positives both matter
  • What Worldstream's DDoS protection actually covers

What a DDoS attack actually is

A distributed denial-of-service (DDoS) attack tries to make a service unavailable by overwhelming it, usually with traffic sent from many sources at once rather than one. That's the "distributed" part: the traffic doesn't come from a single machine you could simply block, it comes from large numbers of hosts, often part of a botnet, all directed at the same target. Attacks generally fall into three broad categories, and a real attack often combines more than one:

  • Volumetric floods. The simplest kind conceptually: sheer volume of traffic aimed at a target's network link, trying to consume all the available bandwidth so legitimate traffic can't get through. UDP floods and amplification attacks (where a small request tricks a third-party server into sending a much larger response to the victim) are common examples.
  • Protocol attacks. These target weaknesses in how network protocols handle connections rather than raw bandwidth. A SYN flood, for example, opens huge numbers of TCP connections and never completes them, exhausting the connection-tracking resources of a firewall or server rather than its bandwidth.
  • Application-layer attacks. The most targeted kind: traffic that looks like normal, valid requests (HTTP requests to a website, for example) but is sent at a volume or pattern designed to exhaust the application itself, its database, or its backend, rather than the network underneath it. Because the traffic looks legitimate at the network level, this category is generally the hardest to distinguish from real users.

Always-on mitigation vs. on-demand mitigation

The distinction that matters most in practice is when mitigation actually engages:

  • Always-on mitigation means traffic is continuously analysed as it arrives, attack traffic is scrubbed out, and clean traffic is passed through, all the time, whether or not an attack is currently happening. There's no window where an attack is running unmitigated while a system decides whether to react.
  • On-demand mitigation only activates once an attack is detected and traffic is rerouted to scrubbing infrastructure. That detection-and-rerouting step takes time, and during it the target is exposed to at least some of the attack.

Always-on protection removes that detection gap by design, which is why it's the standard approach for anything that can't tolerate downtime at the start of an attack.

Why detection speed and false positives both matter

A mitigation system is judged on two things, not one. Detection speed is the obvious one: the faster attack traffic is identified and scrubbed, the shorter the window of impact. But the false-positive rate matters just as much, and it's easy to overlook. A system that's too aggressive will start blocking or throttling legitimate traffic that merely looks unusual, real users and real requests getting caught in the same net as the attack. Blocking legitimate traffic is also a failure mode, not a safe default, since the practical effect for anyone affected looks the same as the outage the protection was meant to prevent. Well-tuned mitigation has to hold both goals at once: react fast, and avoid mistaking real traffic for an attack.

What Worldstream's DDoS protection actually covers

All Worldstream servers come standard with 20 Gbit/s of anti-DDoS protection, scalable up to 1 Tbit/s+ mitigation capacity. Mitigation is powered by Nokia Deepfield Defender, integrated directly with the network equipment, so suspicious traffic is analysed and filtered at the network level before it reaches your server, not after. That's always-on protection in the sense described above: it's standing by continuously, not switched on only once an attack is already under way. Filtering is tuned to your own risk profile and traffic pattern rather than a single one-size-fits-all threshold, and you can request a mitigation report with the details of a specific attack after it happens.

Related articles

  • Firewall basics in Portal
  • Continuous Security Validation
  • Configuring a dedicated server when you order it
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure