Skip to content
Cyber Security

DDoS Protection & Mitigation

Always-on and on-demand DDoS mitigation with 5 Tbps+ scrubbing capacity, BGP diversion or DNS-based protection, layer 3 to layer 7 coverage and a contractual time-to-mitigate under 60 seconds.

DDoS Protection & Mitigation - Dollu
  • 5 Tbps+

    Global scrubbing capacity

  • < 60 s

    Time-to-mitigate SLA

  • L3–L7

    Attack coverage

Overview

What is DDoS Protection & Mitigation?

Dollu DDoS Protection & Mitigation absorbs volumetric, protocol and application-layer attacks before they reach your network, your applications or your voice and messaging infrastructure. Scrubbing centres at our London, Frankfurt, Amsterdam, Ashburn, Mumbai and Singapore PoPs - backed by partner capacity in further regions - provide more than 5 Tbps of aggregate mitigation, and because they sit on the Dollu backbone, clean traffic is returned to Dollu connectivity customers over the same private paths they already use. Attacks are stopped upstream, not at your firewall.

Two delivery models cover every kind of asset. Network protection uses BGP: in always-on mode your prefixes are announced through Dollu scrubbing permanently and every packet is inspected; in on-demand mode traffic flows normally and is diverted to scrubbing within seconds of detection, with clean traffic returned over GRE tunnels, a private cross-connect or directly onto your Dollu circuit. Web and API protection uses DNS: you point records at Dollu anycast proxies, which terminate TLS, absorb floods, apply web application firewall rules and forward legitimate requests to your origin.

Detection combines flow telemetry from the Dollu core, inline packet analysis at the scrubbing edge and application-layer behavioural baselines. Mitigation is automatic and layered: upstream ACLs and flowspec drop the obvious, stateful scrubbing handles SYN, UDP, DNS and NTP amplification, and application-layer engines separate real users from HTTP floods, slow-loris, API abuse and bot traffic. For carrier and voice customers we add SIP-aware profiles that recognise INVITE and REGISTER floods and protect SBCs and softswitches without dropping legitimate call setup.

Every event is documented. The portal shows attacks in real time - vectors, peak bits and packets per second, sources, mitigation actions and residual traffic - and generates a post-attack report suitable for management, insurers and regulators. Contractual time-to-mitigate is under 60 seconds for always-on and under five minutes for on-demand diversion, and our 24×7 security operations team is on the phone with you throughout a sustained attack.

Why Dollu

Why choose Dollu for ddos protection.

The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.

  • Mitigation measured in seconds

    Always-on customers are protected continuously; on-demand customers see diversion and cleaning begin within seconds of detection, with a contractual time-to-mitigate rather than a best effort.

  • Capacity to absorb terabit attacks

    5 Tbps+ of distributed scrubbing means multi-hundred-gigabit floods are absorbed without saturating your circuits or ours, and without collateral blocking of clean traffic.

  • Built for carriers and voice

    Profiles tuned for SIP signalling, RTP media, SMPP and carrier interconnects, so an attack on your SBC or SMS gateway is stopped without dropping legitimate calls or messages.

  • Visibility during and after the event

    Real-time dashboards, alerts and detailed post-attack reports show what happened, what was blocked and what got through, for engineering, management and compliance.

  • Same provider as your circuits

    For Dollu DIA, MPLS and cloud customers, mitigation is upstream on the same backbone with clean return already in place - no tunnels to build, no third-party escalation.

Capabilities

Capabilities in detail.

Everything included with DDoS Protection & Mitigation - the platform features, options and controls you get from day one.

  1. 01

    Always-on network protection

    Your prefixes are announced via Dollu scrubbing at all times; every packet passes inline inspection with no diversion delay. Recommended for voice cores, payment systems and public-facing carrier infrastructure.

  2. 02

    On-demand BGP diversion

    Traffic flows normally until flow-based detection triggers diversion of the affected /24 or larger prefix; clean traffic returns via GRE, private cross-connect or directly onto your Dollu circuit. Customer-triggered diversion is also available.

  3. 03

    DNS-based web and API protection

    Anycast reverse proxies terminate TLS, absorb HTTP floods, enforce rate limits and WAF rules, challenge suspicious clients and forward clean requests to your origin, whose IP stays hidden.

  4. 04

    Multi-layer mitigation engine

    Flowspec and upstream ACLs, SYN and UDP flood defence, reflection and amplification filtering for DNS, NTP, SSDP, CLDAP and memcached, fragment handling, and application-layer behavioural analysis.

  5. 05

    SIP, RTP and SMPP profiles

    Signalling-aware inspection that distinguishes INVITE, REGISTER and OPTIONS floods from legitimate call setup, rate-limits per source, protects RTP port ranges and preserves carrier interconnect traffic.

  6. 06

    Automatic and manual controls

    Detection thresholds and mitigation templates per prefix or application, one-click diversion from the portal, emergency hotline to the security operations centre and change control on protection policies.

  7. 07

    Reporting and forensics

    Live attack view with vectors, pps/bps, geographic and ASN sources; post-attack PDF and JSON reports; sampled packet captures on request; monthly summary reports.

  8. 08

    Integration with Dollu security services

    Events feed Dollu MDR and SOC for correlation, and protection policies coordinate with Dollu managed firewall and SASE so mitigation and access controls act as one system.

How it works

How it works.

From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.

  1. Step 01

    Onboard

    We register your prefixes or domains, verify ownership, agree detection thresholds and mitigation templates, and configure GRE tunnels, cross-connects or origin settings.

  2. Step 02

    Baseline

    Flow telemetry and application traffic are profiled for two to four weeks to establish normal patterns per prefix, protocol and application, reducing false positives.

  3. Step 03

    Test

    A controlled diversion and clean-return test confirms routing, tunnel MTU and application behaviour under mitigation. Runbooks and escalation contacts are finalised.

  4. Step 04

    Protect

    Always-on customers are inline immediately; on-demand customers are monitored continuously with automatic or one-click diversion. Reports and alerts flow to your team and, optionally, your SIEM.

Use cases

Who uses this and why.

Typical deployments across carriers, enterprises, platforms and contact centres.

  • Carriers and voice providers

    Protect SBCs, softswitches, SMS gateways and interconnect edges from signalling floods and volumetric attacks that would otherwise take down call and message delivery.

  • Banks and payment platforms

    Always-on protection for internet banking, UPI and payment gateway endpoints where a minute of unavailability has regulatory and reputational consequences.

  • Gaming and streaming

    Absorb attacks aimed at game servers, matchmaking and streaming origins that peak during events, with low-latency clean return so players are not affected.

  • E-commerce and SaaS

    DNS-based protection with WAF and bot management for storefronts and APIs, keeping origins hidden and available through sales peaks and extortion campaigns.

  • Enterprises and public sector

    Protect DIA and MPLS internet breakouts, VPN concentrators and public services with upstream mitigation on the same Dollu backbone that carries the traffic.

Specifications

Technical & commercial specifications.

Key parameters at a glance. Ask us for the full service description and SLA document.

Scrubbing capacity5 Tbps+ aggregate; six Dollu PoPs plus partner centres
DeliveryAlways-on BGP, on-demand BGP diversion, DNS anycast proxy
Clean returnGRE, private cross-connect, direct on Dollu DIA/MPLS
CoverageL3/L4 volumetric and protocol; L7 HTTP/S, DNS, SIP, SMPP
Time-to-mitigate< 60 s always-on; < 5 min on-demand diversion (SLA)
Minimum prefix/24 IPv4, /48 IPv6 for BGP; any hostname for DNS proxy
WAFOWASP rules, custom rules, rate limiting, bot challenge
ReportingReal-time portal, post-attack reports, SIEM/syslog export
PricingFlat monthly per prefix or domain; no per-attack or overage charges
Support24×7 security operations; P1 response ≤ 15 min; hotline during attacks
Pricing model

How Security is priced.

Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.

We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.

Monthly recurring · per site, user or endpoint
  • DDoS and managed firewall per protected site or circuit
  • SASE and zero trust per user
  • MDR per endpoint or by log volume
  • Assessments and penetration tests as fixed-scope projects
  • 12–36 month terms on managed services
Billing
Monthly recurring in advance; projects invoiced on milestones
Commitment
12–36 months for managed services; none for assessments
Talk to salesActual rates within one business day.
FAQ

DDoS Protection - your questions answered.

The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.

Still have a question?

Ask our solutions team

Always-on suits assets where seconds of degradation matter - voice cores, payment systems, carrier interconnects - and adds a small, constant latency. On-demand suits general internet presence where a few minutes of detection and diversion is acceptable and adds no latency day to day. Many customers use always-on for critical prefixes and on-demand for the rest.

Let’s talk

Get protected before the next attack.

Send us your prefixes or domains for a proposal within one business day; if you are under attack now, call the 24×7 NOC or email [email protected] and an engineer will begin emergency onboarding immediately.

Abstract globe with connected network lines