Inside DDoS Protection: What Actually Happens When Your Server Is Attacked
-
Tuesday, 14th July, 2026
-
10:00am
Every NetVO plan ships with enterprise DDoS protection — but what does that actually mean? Here's a plain-language tour of how attacks work and how our mitigation keeps your services online.
The three families of DDoS attacks
- Volumetric (the flood): UDP amplification, DNS/NTP reflection — hundreds of Gbps aimed at saturating your uplink. The most common type by far.
- Protocol attacks: SYN floods, fragmented packet games — exhausting connection tables on servers and firewalls rather than raw bandwidth.
- Application-layer (L7): HTTP floods that look like real users hammering expensive endpoints (search pages, login forms).
What our protection does automatically
- Always-on detection samples traffic to every IP, building a baseline of what “normal” looks like for your service;
- When an anomaly is detected, traffic is redirected through scrubbing infrastructure within seconds — filters drop attack packets (spoofed sources, reflection signatures, malformed protocol floods);
- Clean traffic continues to your server — legitimate users typically notice nothing;
- When the attack subsides, routing returns to normal. No action needed from you, no extra charge, no traffic bill surprise.
What you should still do at the host level
Network mitigation handles the flood; application hygiene handles the rest:
# Rate-limit expensive endpoints (nginx example)
limit_req_zone $binary_remote_addr zone=login:10m rate=5r/m;
location /wp-login.php { limit_req zone=login burst=3; }
- Cache aggressively (LiteSpeed/Redis/CDN) so L7 floods hit cheap cached responses;
- Keep your origin IP private when using a CDN — attackers can't flood what they can't find;
- Monitor: a sudden connection spike in
ss -s is your early warning.
Under attack right now?
Mitigation engages automatically — but if you're seeing degraded performance during an attack, open a ticket flagged urgent with your service IP and timestamps. Our network engineers can apply tighter, service-specific filtering profiles 24/7.
DDoS protection is included with every product we sell — shared hosting, cloud and bare metal alike. It's not an upsell; it's table stakes for serious infrastructure.