Skip to main content

How Our DDoS Protection Works

Game servers are attacked more often than almost anything else on the internet, and "DDoS protected" means very different things from one host to the next. This page explains what we actually do, and where the limits are.

The short version​

  • Traffic to game servers on our protected network passes through our own filtering platform, built and run by us specifically for game traffic.
  • It is always on. There is nothing to enable, and no wait for an attack to be detected and rerouted before filtering starts.
  • It is game-aware. It is not a generic website firewall placed in front of a game server.
  • Protection is provided on a best-effort basis. It is not a guarantee. See Best effort, not a guarantee.

How it works​

Protection is layered, so no single system has to catch everything.

LayerWhat it does
Upstream networkOur network partners run their own mitigation, which can absorb or divert very large floods before they reach us.
Edge filterEvery packet is inspected at the edge of our network, before it reaches your server. Traffic that can never be legitimate, such as spoofed sources and reflection or amplification floods (the most common attack on game servers), is discarded here.
Game-aware checksFor many of the games we host, the filter understands the game's own network protocol, so it can tell real game traffic from a flood made to look like it.
Player recognitionPlayers who are already connected and playing are recognised as genuine, so the filter keeps passing their traffic while it drops the attack around them.

Built around your players​

A filter that blocks real players is as bad as the attack itself, so ours is designed to stay out of the way.

  • Stricter checks apply only while a server is under attack. A server that is not being attacked is not second-guessed.
  • Each server is handled on its own. An attack on someone else's server does not tighten the rules on yours.
  • Attack sources are blocked automatically, and the blocks expire on their own.
  • Attacks are logged and our team is alerted as they happen, so we can review what was sent and how it was handled.

What it does not cover​

  • Attacks larger than the network can carry. No provider has unlimited capacity, including us and our upstream partners.
  • Exploits, not floods. Vulnerable mods or plugins, leaked RCON or admin passwords, and game exploits are not DDoS attacks, and a network filter cannot stop them.
  • Services hosted elsewhere. Your website, Discord bot, voice server or home connection are outside our network.
  • New attack methods. Attackers change tactics constantly. We update the filter as new methods appear, but something new can get through before it is recognised.

Best effort, not a guarantee​

We would rather be straightforward than promise something no host can deliver. Our Terms of Service state:

DDoS protection is provided on a best-effort basis only, as set out under Denial of Service Attacks below, and is not a guaranteed component of this SLA. Downtime caused by attacks targeting other customers' services or the broader Hyper Layer network is covered.

In practice this means:

  • Downtime caused by an attack aimed at your own service is not covered by the SLA.
  • Downtime caused by an attack aimed at another customer or at our network is covered.
  • If a sustained attack on one service starts to affect other customers or the wider network, we may temporarily null-route or suspend that service until the attack subsides. We restore it as quickly as we reasonably can.

The full wording is under Denial of Service Attacks in the Terms of Service.

Why we do not publish the details​

We do not publish capacities, thresholds or the specifics of our checks. Doing so would tell an attacker exactly what to aim for.

If you think you are being attacked​

Open a support ticket with:

  • Your server's address and port.
  • The time it started, with your timezone.
  • What your players saw, for example timeouts, lag, or being unable to join.

We can then check the filter's records for that server and time, and tell you what was happening.