Tievolu Logo Tievolu

The Internet Carrier

DDoS Protection

What happens when your network is under attack and not reachable anymore? Tievolu protects your network from DDoS attacks and provides you the flexibility to adjust the filtering rules to your needs. With our advanced DDoS Protection, you can block specific application attacks or combine it with our application filters and AI and ML-based detection to block unknown attacks.

What is our answer to DDoS attacks?

Almost every company operating its own network, like hosting providers, datacenters, or government agencies, faces DDoS attacks. Our DNA comes from hosting providers and we had the same challenges as you. That's why we built our own DDoS Protection solution called PYRUS to filter DDoS attacks effectively and efficiently without using simple DDoS mitigations like BGP Flowspec. Instead, we use a combination of pattern filters, application-layer filtering and AI/ML algorithms to detect and block threats directly in our scrubbing center. This allows you to offload all your DDoS attacks to our scrubbing center and to focus on your core business.

How does it work?

We receive attack traffic directly from our Tier 1 upstreams, Internet Exchanges and PNIs. Before the traffic reaches our Edge Routers, it is first routed through our in-line PYRUS DDoS Protection appliances. This enables us to track connections and separate malicious traffic from legitimate traffic and to filter traffic in real-time. You can use application filters to allow traffic for the specific application and discard all other traffic. Also, our AI/ML-based detection will analyze the traffic in real-time and generate dynamic filters based on the traffic.

Instead of using simple BGP FlowSpec rules which could also affect services and using country blocking, we rely on connection tracking for TCP as well as for UDP, traffic behaviour analysis, and attack patterns.

In combination with our Cloud Firewall, you can also block, rate limit or allow traffic based on Source IP, Source ASN, Source Country, Source Port, Destination IP, Destination Port, Protocol and more. This enables you to have more control over your traffic and to block more specific attacks.

After the traffic has been analyzed and filtered, it is routed through our Edge Routers to your network.

Tievolu PYRUS DDoS Protection

Built to be as flexible as possible

Our PYRUS DDoS Protection is designed and built to be as flexible as possible, as not every network is the same and not every company has the same needs. That's why we offer a flexible solution with a lot of options to configure the DDoS Protection to your needs.

Connection Tracking

We track connections for TCP as well as for UDP, traffic behaviour analysis and attack patterns.

0ms Time To Mitigate

The traffic is analyzed and filtered in real-time in our scrubbing center without any delay.

Deep attack insight

See what happened with graphs, top source IPs, source ASNs, source countries, IP samples and more.

Application Filters

You can use application filters to allow traffic for the specific application and to discard all other traffic.

AI/ML-based detection

Our AI/ML-based detection will analyze the traffic in real-time and generate dynamic filters based on the current attack traffic.

Vectors we protect

We protect you against TCP, UDP, ICMP, GRE and application attacks for IPv4 and IPv6.

What is covered by our DDoS Protection?

PYRUS DDoS Protection filters layer 3 and layer 4 attacks for IPv4 and IPv6. But it also can do deep packet inspection to track application connections and to build fingerprints. Encrypted payloads like HTTPS are not covered by our DDoS Protection.

Covered attacks

We protect you against TCP, UDP, ICMP, GRE and application attacks for IPv4 and IPv6.

  • IP floods for IPv4 and IPv6
  • TCP SYN floods
  • TCP SYN ACK floods
  • TCP floods
  • UDP floods
  • ICMP floods
  • GRE floods
  • Amplification floods
  • Application attacks with existing filters
  • Zero-day attacks

Not or not fully covered

  • Encrypted payloads like HTTPS
  • Application bots where traffic looks like legitimate traffic (can be mitigated with Cloud Firewall)
  • Attacks of any type if source is whitelisted

We are planning to provide a Web Application Firewall in the future to also cover HTTPS attacks.

Support filters for specific applications

We have a range of filters for specific applications already implemented and ready to use in our PYRUS DDoS Protection. These filters track connections from real users, to allow their traffic and to discard all other traffic. The filters need to be set by the customer. We do not use any predefined port ranges to give you the maximum flexibility.

  • FiveM
  • TeamSpeak
  • CS:GO
  • CS2
  • Source Engine
  • Minecraft Java
  • SSH
  • HTTPS
  • HTTP
  • OpenVPN
  • WireGuard

What is the capacity of our DDoS Protection?

Currently, we are able to handle attacks up to 600 Gbps / 860 Mpps. This is a theoretical maximum and will grow with our customer amount and needs. Larger attacks will be automatically blackholed to keep our, your and other customers' networks stable and to prevent network overload.

Basic DDoS Protection

Our basic IP Transit plan includes volumetric DDoS Protection up to 100 Gbps and 140 Mpps.

Premium DDoS Protection

Our premium IP Transit plan includes volumetric DDoS Protection up to 600 Gbps and 860 Mpps.

DDoS Protection plans

At Tievolu, DDoS Protection is not an extra billed feature, it is included in every IP Transit plan. You can choose between the basic and the premium plan, depending on your needs.

Basic IP Transit 1G

Essential connectivity with volume-based DDoS Protection

90 /month

Starting at 1G commitment (€0.09/Mbit)

What's included:

  • High-performance IP Transit
  • Volume DDoS Protection up to 100G
  • Free TievoluIX access
  • BGP routing support
  • 24/7 Emergency support
  • 1G 95th percentile commitment
  • 10G ports
  • Connection via physical port or GRE tunnel
  • Multiple Tier1 upstreams
  • Dedicated account manager

Not included:

  • Cloud Firewall
  • Advanced DDoS settings
  • Application-layer filtering

Basic IP Transit 10G

Essential connectivity with volume-based DDoS Protection

750 /month

Starting at 10G commitment (€0.075/Mbit)

What's included:

  • High-performance IP Transit
  • Volume DDoS Protection up to 100G
  • Free TievoluIX access
  • BGP routing support
  • 24/7 Emergency support
  • 10G 95th percentile commitment
  • 10G, 25G, 40G or 100G ports
  • Connection via physical port or GRE tunnel
  • Multiple Tier1 upstreams
  • Dedicated account manager

Not included:

  • Cloud Firewall
  • Advanced DDoS settings
  • Application-layer filtering
Recommended

Premium IP Transit 1G

Complete protection with Cloud Firewall and advanced DDoS Protection

250 /month

Starting at 1G commitment (€0.25/Mbit)

What's included:

  • 1G 95th percentile commitment
  • 10G, 25G, 40G or 100G ports

Everything else in Basic, plus:

  • Full DDoS Protection
  • Cloud Firewall included
  • Advanced DDoS settings & customization
  • Free DDoS Consulting Service for the first 3 months
  • Application-layer filtering
  • Real-time attack analytics
  • Custom mitigation rules
  • Priority support
Recommended

Premium IP Transit 10G

Complete protection with Cloud Firewall and advanced DDoS Protection

1600 /month

Starting at 10G commitment (€0.16/Mbit)

What's included:

  • 10G 95th percentile commitment
  • 10G, 25G, 40G or 100G ports

Everything else in Basic, plus:

  • Full DDoS Protection
  • Cloud Firewall included
  • Advanced DDoS settings & customization
  • Free DDoS Consulting Service for the first 3 months
  • Application-layer filtering
  • Real-time attack analytics
  • Custom mitigation rules
  • Priority support

Differences between Basic and Premium

The basic and the premium plan are the same in terms of features, but there are some differences in the capacity, functionality, and price.

Feature Basic Premium
IP Transit Connectivity
Port Options (10G - 100G)
Free TievoluIX Access
BGP Routing Support
24/7 Emergency Support
Dedicated Account Manager
Volume DDoS Protection Up to 100G Up to 600G (continuous scaling)
Cloud Firewall
Advanced DDoS Settings
Application-Layer Filtering
Real-time Attack Analytics
Custom Mitigation Rules
Priority Support
Free DDoS Consulting Service for the first 3 months

Your benefits with Tievolu

0ms Time To Mitigate

The first actions take place immediately in real-time. Further and more granular actions are placed within the first 10 seconds.

99.9% Network SLA

Our network SLA guarantees that 99.9% of the time, our backbone is up and running.

24/7 Emergency Support

Our emergency team can be called 7 days a week, 24 hours a day to help you with any issues you may have.

Cloud Firewall

Our Cloud Firewall works seamlessly together with our PYRUS DDoS Protection system, giving you a complete, layered defense against all types of network attacks.

Fully API driven

All functions in our dashboard can also be controlled via our API. This allows you to automate your DDoS Protection and to integrate it with your other systems.

Application Filters

We provide a wide range of application filters. Non-existing filters can be requested and added without any additional costs.

Scalable Protection

Our mitigation solutions seamlessly scale to handle attacks from a few Gbps up to several 100 Gbps without service degradation. You can also request a custom capacity for your needs.

Detailed Attack Analytics

Gain detailed insight into attacks and traffic patterns via an interactive analytics dashboard. See what happened with graphs, top source IPs, source ASNs, source countries, IP samples and more.

Customizable Protection Profiles

Tailor rules and policies to fit the unique requirements of your applications or network segments. You can also create custom mitigation rules to fit your needs.

Seamless Integration

Integrate DDoS Protection with your existing cloud, on-prem, or hybrid infrastructure easily and efficiently. You can also use our API to integrate it with your other systems.

Our DDoS Protection solutions

Benefit from our different DDoS Protection solutions to implement our DDoS Protection into your network.

Tievolu Cloud DDoS Protection

Cloud DDoS Protection

Our flagship product, our PYRUS DDoS Protection, is a state-of-the-art solution that combines pattern filters, application-layer filtering, and advanced AI/ML algorithms to detect and block threats directly in our scrubbing center. This allows you to offload all your DDoS attacks to our scrubbing center and to focus on your core business. This service is available without any additional costs for all our IP Transit customers.

Tievolu On-premise DDoS Protection

On-premise DDoS Protection

We also offer a on-premise PYRUS DDoS Protection solution. This allows you to install a managed PYRUS DDoS Protection sensor and appliances in your infrastructure. We will do the installation and management and setup the protection for your needs. This is perfect for large networks they already have a huge bandwidth and want to filter all their traffic in their own infrastructure.

Tievolu Hybrid DDoS Protection

Hybrid DDoS Protection

Our Hybrid DDoS Protection solution combines the benefits of our Cloud DDoS Protection and our On-premise DDoS Protection. This allows you to filter your traffic in your own infrastructure and to offload larger attacks to our scrubbing center. This if you want to filter some attacks on your end and just want to offload high volume attacks to our scrubbing center.

We would like to consult you which solution is best for you. Contact us today! Contact us

Tievolu Collin Schneeweiß

Start protecting your network today

Contact our expert Collin Schneeweiß today to protect your network from DDoS attacks and get your personal offer.

Contact us LinkedIn