Customized DDoS attack mitigation with programmable flow protection

Last update: April 7th 2026
  • DDoS attacks have gone from hundreds of Gbps to hyper-attacks of several Tbps, supported by IoT botnets and UDP amplification techniques.
  • Professional mitigation combines scrubbing centers, Anycast CDNs, firewalls, WAFs, and good hardening and early monitoring practices.
  • Cloudflare's Programmable Flow Protection allows packet logic in C/eBPF to filter specific UDP traffic at the application level.
  • An effective strategy requires defense in depth, automation, contingency plans, and collaboration with ISPs and cloud providers.

Customized DDoS attack mitigation with programmable flow protection

We live in an era where the network is the connective tissue of almost everything we do. When a company loses service due to a denial-of-service attack, it's not just a website that goes down: sales, internal processes, customer service, and, in the most serious cases, essential services are paralyzed. That's why customized DDoS mitigation with programmable flow protection has become a strategic component of any modern architecture.

The emergence of technologies like Cloudflare's Programmable Flow Protection for Magic Transit , the use of custom C logic deployed as eBPF, integration with clouds like AWS and Azure, and support from specialized defense services have radically changed the landscape. It's now possible to model what constitutes "good" or "malicious" traffic at the packet level, tailor mitigation to very specific UDP protocols (such as those used in online gaming or VoIP), and combine this with business intelligence and AI solutions that learn from each attack.

What is a DDoS attack and why has it become such a serious problem?

A distributed denial-of-service (DDoS) attack aims to overwhelm a system's resources (servers, links, applications, or intermediate infrastructure) by launching a flood of traffic from multiple simultaneous sources. Unlike a classic DoS attack, where a single source triggers the attack, a DDoS attack involves thousands or even millions of compromised devices, organized into a botnet.

The motivations behind DDoS attacks are varied: economic blackmail, sabotage among competitors, activism, reprisals against journalists or media outlets, or simply tests of strength by new botnets in "capabilities demonstration" mode. The result, however, is always the same: service unavailability , severe performance degradation, and economic and reputational damage.

In recent years, there has been a steady increase in the frequency and intensity of these attacks. Reports from major security vendors indicate a sustained growth in hyper-volumetric attacks (above 1 Tbps or one billion packets per second), often targeting critical infrastructure such as financial services, utilities, and telecommunications.

Types of DDoS attacks: from the network to the application

To understand how custom DDoS mitigation works, it's helpful to review the main categories of attacks. Generally speaking, we can group them into four main families, linked to different layers of the OSI model and different resources they aim to deplete.

Network layer (L3/L4) attacks focus on exploiting network and transport protocols (IP, TCP, UDP, ICMP) to drain limited resources from the server or intermediate infrastructure: CPU, memory, firewall tables, pending connections, or network buffers. Classic examples include SYN floods (flooding the server with TCP connection requests that never complete the handshake), UDP floods to random ports, and ICMP attacks.

Application layer (L7) attacks target less bandwidth than the resources of the web application or API itself. They generate a huge volume of HTTP requests (GET/POST), complex queries to internal search engines, calls to heavy APIs, or interactions that, while seemingly legitimate, force the backend, database, or content generation systems to work at their limits.

Volumetric attacks: Here, the goal is to flood the link until it becomes unusable. Massive amounts of traffic are sent, often exploiting amplification and reflection techniques on misconfigured UDP services, such as public DNS servers (DNS, NTP, Memcached, CLDAP, SNMP, SSDP, Chargen, SLP, etc.), so that a small request packet generates a much larger response directed at the impersonated victim.

Multi-vector attacks are currently the most complex. They combine several methods (volumetric, protocol, and application) and change strategy in real time as they detect that a defense is succeeding. A single attack can start as a UDP flood, then transition to a SYN flood, and subsequently pivot to a Layer 7 HTTP attack, forcing the victim to deploy comprehensive and coordinated defenses.

Real evolution of DDoS attacks: from Mirai to Tbps hyper-attacks

The theory is fine, but the true magnitude of the problem becomes apparent in real-world cases. In the last decade, we've gone from attacks of hundreds of Gbps to events easily exceeding several terabits per second (Tbps) , with packet rates reaching billions per second.

In 2016, an attack against Dyn—a major DNS provider—reached approximately 1,2 Tbps and temporarily took down sites like Twitter, GitHub, PayPal, and Netflix. The Mirai botnet, which recruited over 600.000 IoT devices (routers, cameras, and DVRs with default credentials), was used to generate massive traffic to Dyn's DNS servers, likely using a combination of UDP flooding and amplification techniques.

That same year, the security blog KrebsOnSecurity suffered an attack of approximately 623 Gbps , also powered by Mirai. For nearly four days, large UDP packets were primarily launched to random ports, saturating the links and forcing the rerouting of traffic to specialized mitigation services such as Akamai Prolexic, which applied signature and behavioral filtering.

In 2018, GitHub was the target of a 1,35 Tbps attack based on Memcached amplification. The attackers sent small UDP requests to Memcached servers exposed on port 11211, using a spoofed GitHub IP address. Each tiny request triggered responses 50-100 times larger directed to GitHub's systems, which were forced to redirect traffic to cleanup centers where the Memcached responses were filtered for their specific patterns.

  How to unlock the BIOS password on your laptop

In 2020, Amazon reported that AWS Shield had mitigated a 2,3 Tbps attack relying on CLDAP reflection (UDP 389). The attack vector involved bombarding stateless LDAP servers with queries that generated high-volume responses to the victim. AWS distributed the traffic across its global network and applied filtering rules for that specific CLDAP pattern.

More recently, botnets like Mēris have emerged , exploiting vulnerabilities in MikroTik routers. In 2021, peaks of 21,8 million requests per second (RPS) were recorded, and in 2022, these reached 46 million RPS against Google infrastructure, with approximate volumes of 1,3 Tbps. Mitigation efforts involved patching devices en masse, closing ports such as 5678 , and applying specific filtering rules for the Mēris signature on networks like Cloudflare and Akamai.

In April 2025, Cloudflare reported a hyper-attack of approximately 6,5 Tbps and several billion packets per second. According to their analysis, it was an unattributed botnet with characteristics similar to Mēris and Aisuru, which primarily used direct UDP floods from IoT devices and misconfigured servers, without requiring traditional amplification. Defenses relied on Cloudflare's global Anycast network, XDP/eBPF mitigation at the edge, dynamic scrubbing, and rate limiting per IP and per region.

And in May 2025, KrebsOnSecurity made headlines again by withstanding an attack of approximately 6,3 Tbps launched by the Aisuru botnet. In this instance, some 585 million UDP packets were generated per second for about 40-45 seconds. Google Project Shield, which was protecting the site, immediately activated aggressive filtering policies for unsolicited UDP and diverted traffic to cleanup centers distributed across its global network, so the impact on service was virtually imperceptible.

Attackers' resources and techniques: botnets, amplification, and evasion

To achieve these staggering figures, attackers employ a variety of resources, combining them according to their objective. Massive botnets are the foundation: networks of compromised devices worldwide, recruited by exploiting known vulnerabilities, default passwords, or exposed administrative services. Mirai, Mēris, and Aisuru are family names, but countless variations exist, targeting different manufacturers or services.

The second major vulnerability is misconfigured servers acting as reflectors. Any unauthenticated UDP service that responds with more data than it receives is a candidate: DNS (port 53), NTP (123), Memcached (11211), CLDAP (389), SNMP (161), SSDP, Chargen, SLP, TFTP, Portmap, P2P services, or even video game protocols. The attacker sends small requests spoofing the victim's IP address, and the servers amplify and return the response to the actual target.

In DNS, for example, an ANY query to an open resolver can multiply the request size by about 28 times. In NTP, the old MONLIST command reached amplification ratios of 50-500x. Memcached is an extreme case: a tiny request can return hundreds of kilobytes, reaching amplification ratios of tens of thousands. CLDAP operates at factors of 56-70x, while SLP has been used with values ​​exceeding 2000x.

Furthermore, attackers are refining their evasion techniques. IP spoofing remains a classic method for concealing the true origin and exploiting reflection. Other methods include constantly rotating attack vectors, mixing encrypted traffic to force higher processing loads on the defender, using "low and slow" techniques (gradual consumption of resources without obvious spikes), or bringing traffic closer to the application layer, where it much more closely resembles legitimate traffic.

In the pre-attack phase, mass scanning tools like masscan or zmap are used to locate vulnerable services, along with exploit kits specifically designed for IoT or servers. During the attack, traffic generators such as hping3, LOIC/HOIC, or optimized C/Python scripts are employed, while for post-attack analysis, the attackers themselves may use Wireshark, tcpdump, and monitoring platforms.

Phases of a DDoS attack and the need for adaptive defense

Although often perceived as chaotic bursts of traffic, sophisticated DDoS attacks go through several distinct phases . First, the reconnaissance stage, in which the attacker studies the exposed surface, identifies domains, IP addresses, open services, CDNs or mitigation providers present, and looks for vulnerabilities.

Next comes device compromise, which involves infecting the computers that will feed the botnet. This can mean exploiting vulnerabilities in routers, cameras, remote management systems, or servers, often by taking advantage of outdated software or default credentials. Once recruited, they connect to the C2 infrastructure, which centralizes commands and updates.

The execution phase of the attack is usually timed to coincide with critical moments for the victim: marketing campaigns, product launches, weekends with fewer staff on duty, or politically or media-sensitive dates. The goal is to maximize impact and pressure . In next-generation attacks, there is also a dynamic adaptation component: the botnet monitors the victim's response and changes its attack vector if it detects effective mitigation.

On the defense side, this necessitates the design of equally adaptive strategies. A static firewall or bandwidth threshold is no longer sufficient: systems capable of detecting traffic anomalies in real time , correlating events, deploying new rules on the fly, and scaling resources (computing, storage, and network capacity) on demand are required.

  Is a VPN worth paying for? A complete and honest guide

A recent study showed that DDoS attacks against critical infrastructure have grown by more than 50% in four years, and that they are often used as a smokescreen for other intrusions, such as the deployment of ransomware while the security team is focused on "putting out the fire" of the denial of service.

Traditional mitigation: scrubbing centers, CDNs, firewalls and WAFs

Professional DDoS defenses rely on a combination of technologies and providers. The most characteristic component is traffic scrubbing centers , large distributed infrastructures that can absorb tens of Tbps and filter malicious traffic before returning only valid connections to the client.

Companies like Netscout/Arbor, Akamai/Prolexic, Cloudflare, Radware, Imperva, and AWS Shield manage global networks with multiple points of presence. When an attack is detected, traffic destined for the victim organization is redirected (via BGP changes or DNS updates) to these centers, where filters are applied based on signatures, behavior, blacklists, statistical analysis, and custom rules.

In parallel, many organizations are deploying on-premises anti-DDoS appliances in their own data centers or those of their ISPs. Devices such as Arbor TMS, Radware DefensePro, FortiDDoS, or certain F5 solutions are responsible for detecting and mitigating attacks up to a specific capacity limit. It is common practice to combine these local appliances with a cloud-based scrubbing solution for attacks that exceed their capacity.

CDNs and Anycast architectures —such as those from Cloudflare, Akamai, Fastly, or Google Cloud CDN—add another layer of defense by geographically dispersing the load. By publishing a service behind a CDN, traffic is distributed across multiple nodes, and volumetric attacks are diluted by not concentrating them in a single point. Furthermore, they typically integrate Web Application Firewalls (WAFs) and HTTP-level rate-limiting policies.

Finally, network firewalls (Cisco, Palo Alto, iptables on Linux, etc.) and specialized WAFs (ModSecurity, Cloudflare WAF, AWS WAF) allow you to filter traffic by IP address, port, flags, and application patterns . While they alone won't stop a Tbps attack at the backbone level, they are essential for blocking known attack vectors, limiting suspicious connections, and protecting layers 6 and 7 of the stack.

Programmable Flow Protection and customized mitigation with Magic Transit

In this context of increasingly complex attacks and increasingly specific protocols, solutions such as Cloudflare's Programmable Flow Protection for Magic Transit emerge , marking a qualitative leap: they allow companies to write their own mitigation logic and deploy it directly on a global provider's network.

The idea is simple yet powerful: Magic Transit customers can load stateful packet processing programs written in C. Cloudflare validates, compiles, and transforms these programs into eBPF, running them in user space within its global infrastructure. This allows them to inspect application UDP traffic in a protocol-aware manner: understanding headers specific to an online game, a high-frequency trading system, VoIP services, or streaming platforms, and deciding, packet by packet, what to allow and what to block.

This custom logic integrates with Flowtrackd, Cloudflare's stateful mitigation platform. The feature supports both symmetric and asymmetric topologies, although in this closed beta phase, it focuses on analyzing incoming traffic. All management is handled through the Cloudflare API, with endpoints for uploading programs, creating associated rules, listing configurations, or deleting them as needs change.

The key takeaway here is that we no longer rely solely on generic vendor signatures and heuristics. A video game company, for example, can clearly define the legitimate flow of its proprietary UDP protocol (handshake, position messages, keep-alives, etc.) and which patterns are characteristic of an attack. This logic is compiled and deployed across all Cloudflare points of presence, bringing the decision closer to the network edge.

For environments with custom protocols or applications with very high latency demands, this DDoS attack mitigation with programmable flow protection is a game-changer: it adds a layer of business-specific intelligence on top of standard defenses. And when combined with cloud services like AWS or Azure, and with custom software solutions (such as those developed by companies specializing in AI and analytics, like Q2BSTUDIO), it allows for even greater automation of rule detection and updates based on emerging threats.

Why ISPs and organizations need advanced DDoS mitigation

Internet service providers (ISPs) and large organizations are on the front lines. A sufficiently large attack can overwhelm not just a single customer, but an entire section of an operator's network, causing cascading outages that affect thousands of users. Therefore, DDoS mitigation has become an essential requirement, not an optional extra.

From a business perspective, the consequences of failing to defend oneself are clear: service interruption, breach of service level agreements (SLAs), contractual penalties, direct loss of revenue, and customer attrition to competitors perceived as more reliable. If a critical application is unavailable when the user needs it, they will naturally seek alternatives.

In sectors such as banking, insurance, utilities, and healthcare, the impact can extend beyond the economic: disruptions to physical processes , operational risks, and disruption to essential services. Furthermore, there is a reputational cost that is difficult to recover when a brand is associated with a "system down" for hours on social media and in the press.

  A complete guide to safely buying a refurbished PC

To make matters worse, DDoS attacks are frequently used as cover for more damaging attacks. While the security team is focused on managing the surge of traffic, attackers can attempt to move laterally within the network, deploy ransomware, or exfiltrate data. In other words, DDoS attacks act as decoys and distractions in multi-stage attacks.

Modern mitigation solutions, both on-premises and in the cloud, significantly reduce downtime, maintain business continuity, and protect both local assets and public cloud resources. The key is their ability to automatically scale to handle massive traffic spikes and offer clear guarantees of capacity and response time.

Specific mitigation techniques: from rate limiting to blackholing

Beyond the major technological blocks, there are a number of specific techniques applied daily to combat various types of attacks. One of the most basic is perimeter filtering using firewalls and access control lists (ACLs) on routers and switches, blocking packets based on source IP address, destination IP address, ports, TCP flags, or size.

Another classic component is rate limiting , both at layers 3/4 and in HTTP. On Linux systems, iptables offers modules like hashlimit or SYNPROXY to control how many connections or packets per second are accepted from a single IP address. At the application level, proxies like Nginx or HAProxy can set limits on requests per client or per route.

For Layer 7 attacks, implementing challenges or additional authentication is very useful . CAPTCHAs, JavaScript challenges, and similar mechanisms allow for better discrimination between real browsers and automated bots, reducing the load on the actual application. In TCP, techniques like SYN cookies help the server avoid having to store state for each connection attempt until the handshake is complete.

When the volume of an attack is unmanageable even for the mitigation infrastructure, BGP blackholing can be used : the ISP advertises the route to the attacked network as a "black hole," discarding all traffic destined for that prefix before it enters the backbone. It is a last resort, because it makes the service unavailable, but it prevents the attack from affecting other parts of the network.

Cloud scrubbing services—such as those offered by Cloudflare, Akamai, AWS Shield, Google Project Shield, Radware, and others—allow you to route all traffic to their data centers and clean it there, applying specific rules for vectors like Memcached amplification, CLDAP, DNS, NTP, unamplified UDP floods, and so on. Each blocked attack feeds machine learning models and signature databases that are used in future mitigation efforts.

Good practices and lessons learned in the face of current DDoS attacks

Several clear lessons can be learned from the major incidents of recent years. The first is that securing IoT devices is crucial: much of the power of botnets like Mirai, Mēris, or Aisuru comes from home routers, cameras, and other devices with outdated firmware and factory default passwords.

The second is that we must eliminate amplification vectors within our own networks: disable unnecessary UDP services, filter NTP, DNS, or Memcached outbound traffic, apply firewall rules that only allow queries from authorized ranges, and periodically review exposed ports. Any misconfigured server can become an amplifier for an attacker.

Early detection of anomalies is also essential . Tools such as NetFlow, sFlow, IDS/IPS (Snort, Suricata), log analysis platforms, or SIEMs should be configured to alert as soon as unusual traffic spikes, sudden changes in connection patterns, or known attack signatures appear. The sooner the response is activated, the less time there is for the attack to escalate.

In web environments, it's almost mandatory to use updated WAFs, CAPTCHAs when they fit the user experience, and caches or CDNs to absorb some of the load. At the system level, enabling SYN cookies, adjusting simultaneous connection thresholds, and closing any non-essential services reduces the attack surface.

Finally, every organization should have a documented DDoS contingency plan : a runbook with clear steps, designated responsible parties, technical contacts at mitigation providers and ISPs, and predefined criteria on when to activate scrubbing, when to request blackholing, or when to degrade non-essential functions to protect the core business.

The trend points to increasingly faster, more intense, and adaptive attacks, but also to smarter and more customizable defenses. Leveraging the capabilities of solutions like Programmable Flow Protection, combined with constant traffic monitoring, best configuration practices, and redundant cloud architectures, allows companies to continue operating normally even in the midst of a packet storm, protecting not only their data but also their reputation and customer trust.

What is bandwidth and how to measure it
Related articles:
What is bandwidth and how to measure it on your connection