Almost every company operating its own network, like hosting providers, datacenters, or government agencies, faces DDoS attacks. Our DNA comes from hosting providers and we had the same challenges as you. That's why we built our own DDoS Protection solution called PYRUS to filter DDoS attacks effectively and efficiently without using simple DDoS mitigations like BGP Flowspec. Instead, we use a combination of pattern filters, application-layer filtering and AI/ML algorithms to detect and block threats directly in our scrubbing center. This allows you to offload all your DDoS attacks to our scrubbing center and to focus on your core business.
We receive attack traffic directly from our Tier 1 upstreams, Internet Exchanges and PNIs. Before the traffic reaches our Edge Routers, it is first routed through our in-line PYRUS DDoS Protection appliances. This enables us to track connections and separate malicious traffic from legitimate traffic and to filter traffic in real-time. You can use application filters to allow traffic for the specific application and discard all other traffic. Also, our AI/ML-based detection will analyze the traffic in real-time and generate dynamic filters based on the traffic.
Instead of using simple BGP FlowSpec rules which could also affect services and using country blocking, we rely on connection tracking for TCP as well as for UDP, traffic behaviour analysis, and attack patterns.
In combination with our Cloud Firewall, you can also block, rate limit or allow traffic based on Source IP, Source ASN, Source Country, Source Port, Destination IP, Destination Port, Protocol and more. This enables you to have more control over your traffic and to block more specific attacks.
After the traffic has been analyzed and filtered, it is routed through our Edge Routers to your network.
Our PYRUS DDoS Protection is designed and built to be as flexible as possible, as not every network is the same and not every company has the same needs. That's why we offer a flexible solution with a lot of options to configure the DDoS Protection to your needs.
We track connections for TCP as well as for UDP, traffic behaviour analysis and attack patterns.
The traffic is analyzed and filtered in real-time in our scrubbing center without any delay.
See what happened with graphs, top source IPs, source ASNs, source countries, IP samples and more.
You can use application filters to allow traffic for the specific application and to discard all other traffic.
Our AI/ML-based detection will analyze the traffic in real-time and generate dynamic filters based on the current attack traffic.
We protect you against TCP, UDP, ICMP, GRE and application attacks for IPv4 and IPv6.
PYRUS DDoS Protection filters layer 3 and layer 4 attacks for IPv4 and IPv6. But it also can do deep packet inspection to track application connections and to build fingerprints. Encrypted payloads like HTTPS are not covered by our DDoS Protection.
We protect you against TCP, UDP, ICMP, GRE and application attacks for IPv4 and IPv6.
We are planning to provide a Web Application Firewall in the future to also cover HTTPS attacks.
We have a range of filters for specific applications already implemented and ready to use in our PYRUS DDoS Protection. These filters track connections from real users, to allow their traffic and to discard all other traffic. The filters need to be set by the customer. We do not use any predefined port ranges to give you the maximum flexibility.
Currently, we are able to handle attacks up to 600 Gbps / 860 Mpps. This is a theoretical maximum and will grow with our customer amount and needs. Larger attacks will be automatically blackholed to keep our, your and other customers' networks stable and to prevent network overload.
Our basic IP Transit plan includes volumetric DDoS Protection up to 100 Gbps and 140 Mpps.
Our premium IP Transit plan includes volumetric DDoS Protection up to 600 Gbps and 860 Mpps.
At Tievolu, DDoS Protection is not an extra billed feature, it is included in every IP Transit plan. You can choose between the basic and the premium plan, depending on your needs.
Essential connectivity with volume-based DDoS Protection
Starting at 1G commitment (€0.09/Mbit)
Essential connectivity with volume-based DDoS Protection
Starting at 10G commitment (€0.075/Mbit)
Complete protection with Cloud Firewall and advanced DDoS Protection
Starting at 1G commitment (€0.25/Mbit)
Complete protection with Cloud Firewall and advanced DDoS Protection
Starting at 10G commitment (€0.16/Mbit)
The basic and the premium plan are the same in terms of features, but there are some differences in the capacity, functionality, and price.
| Feature | Basic | Premium |
|---|---|---|
| IP Transit Connectivity | ||
| Port Options (10G - 100G) | ||
| Free TievoluIX Access | ||
| BGP Routing Support | ||
| 24/7 Emergency Support | ||
| Dedicated Account Manager | ||
| Volume DDoS Protection | Up to 100G | Up to 600G (continuous scaling) |
| Cloud Firewall | ||
| Advanced DDoS Settings | ||
| Application-Layer Filtering | ||
| Real-time Attack Analytics | ||
| Custom Mitigation Rules | ||
| Priority Support | ||
| Free DDoS Consulting Service for the first 3 months |
The first actions take place immediately in real-time. Further and more granular actions are placed within the first 10 seconds.
Our network SLA guarantees that 99.9% of the time, our backbone is up and running.
Our emergency team can be called 7 days a week, 24 hours a day to help you with any issues you may have.
Our Cloud Firewall works seamlessly together with our PYRUS DDoS Protection system, giving you a complete, layered defense against all types of network attacks.
All functions in our dashboard can also be controlled via our API. This allows you to automate your DDoS Protection and to integrate it with your other systems.
We provide a wide range of application filters. Non-existing filters can be requested and added without any additional costs.
Our mitigation solutions seamlessly scale to handle attacks from a few Gbps up to several 100 Gbps without service degradation. You can also request a custom capacity for your needs.
Gain detailed insight into attacks and traffic patterns via an interactive analytics dashboard. See what happened with graphs, top source IPs, source ASNs, source countries, IP samples and more.
Tailor rules and policies to fit the unique requirements of your applications or network segments. You can also create custom mitigation rules to fit your needs.
Integrate DDoS Protection with your existing cloud, on-prem, or hybrid infrastructure easily and efficiently. You can also use our API to integrate it with your other systems.
Benefit from our different DDoS Protection solutions to implement our DDoS Protection into your network.
Our flagship product, our PYRUS DDoS Protection, is a state-of-the-art solution that combines pattern filters, application-layer filtering, and advanced AI/ML algorithms to detect and block threats directly in our scrubbing center. This allows you to offload all your DDoS attacks to our scrubbing center and to focus on your core business. This service is available without any additional costs for all our IP Transit customers.
We also offer a on-premise PYRUS DDoS Protection solution. This allows you to install a managed PYRUS DDoS Protection sensor and appliances in your infrastructure. We will do the installation and management and setup the protection for your needs. This is perfect for large networks they already have a huge bandwidth and want to filter all their traffic in their own infrastructure.
Our Hybrid DDoS Protection solution combines the benefits of our Cloud DDoS Protection and our On-premise DDoS Protection. This allows you to filter your traffic in your own infrastructure and to offload larger attacks to our scrubbing center. This if you want to filter some attacks on your end and just want to offload high volume attacks to our scrubbing center.
Contact our expert Collin Schneeweiß today to protect your network from DDoS attacks and get your personal offer.
Contact us LinkedIn