DDoS mitigation, from the buyer’s side of the table.
Appliance comparisons, hybrid architecture, and the compliance rules — NIS2, DORA, KVKK, PDPL, data localization — that decide which designs you are allowed to deploy at all. Every figure here carries the source it came from, and no manufacturer supplied one.
Where to start
Foundations
The reference layer: what DDoS mitigation is, how the stages work, and the vocabulary the rest of the site assumes.
3 guides
Attack classes
How the DDoS attack classes differ in what they exhaust, what makes each one visible in telemetry, and which defensive tier can actually answer it.
19 guides
Mitigation techniques
Each defensive technique on its own terms: what it works against, what it does not, what it costs operationally and how to verify it before you need it.
10 guides
Architecture and procurement
Where inspection happens, who owns the mitigation decision, what survives a supplier interruption, and what five years of a given shape actually costs.
26 guides
Server and platform hardening
Command-level hardening and tuning for the servers themselves — kernel and network stack, web servers, Java application servers — with the ceiling stated honestly.
11 guides
Regulation and regional duties
How availability, reporting and supply-chain duties across the EU, Türkiye, the Gulf and Central Asia translate into architecture decisions and into evidence you either hold or do not.
10 guides
Operations
What to do during an incident, how to test a product honestly, and what has to be true before a stress test is lawful.
14 guides
Data
Structured, sourced and downloadable reference data: attack vectors, amplification factors, standards and vendor capabilities.
10 guides
Tools
Calculators that show their arithmetic: packet-rate capacity planning and five-year cost modelling, with no vendor defaults and no hidden assumptions.
2 guides
Vendors and alternatives
On-premises DDoS mitigation appliances compared on the same criteria, in alphabetical order, with vendor-stated figures labelled as such and a considerations paragraph for every product.
13 guides
Core references
What DDoS Mitigation Is, and What It Cannot Do
The reference definition, stage by stage
DDoS Mitigation Glossary
110 terms, defined as they are used
Cloud vs. On-Premise vs. Hybrid DDoS Protection: Cost, Latency and Sovereignty
Three architectures compared
Best On-Premise DDoS Mitigation Appliances in 2026
6 appliances compared
DDoS Mitigation Buyer's Guide for ISPs and Telecom Operators
Specifying and evaluating operator-grade mitigation
Why an On-Premise DDoS Appliance Lowers TCO Instead of Raising It
The business case, line by line
Two Layers, Two Vendors: Sourcing ISP and On-Premises DDoS Mitigation from Different Manufacturers
Executive architecture assessment
Linux Server DDoS Hardening: Every sysctl, conntrack and nftables Setting
Every sysctl and nftables tunable, its value and its check
NIS2 and DDoS: What Essential and Important Entities Must Implement
Directive duties turned into architecture
Vendor Jurisdiction Risk in DDoS Mitigation: Russian, Chinese, US and Israeli Exposure Compared
Four legal regimes compared
Recently updated

Attack class · Last updated August 2026
DNS Query Flood
A straight flood of valid DNS queries at a server that must answer every one. No amplification, no malformation, nothing to signature — which is exactly what makes it hard to separate from a busy day.

Attack class · Last updated August 2026
HTTP/2 Rapid Reset
A protocol feature turned into a weapon: open a stream, cancel it immediately, repeat. The concurrency limit that was supposed to bound the work never applies, because no stream stays open long enough to count.

Attack class · Last updated August 2026
ICMP Flood
The oldest flood still in circulation, and the one most often over-mitigated. What it costs, why blocking ICMP entirely breaks things you rely on, and the narrow set of message types that actually matter.

Attack class · Last updated August 2026
IP Fragmentation Attacks
Fragments that never complete, overlap, or arrive out of order force a receiver to hold reassembly state for packets that will never exist. It exhausts memory rather than bandwidth and is invisible to anything counting bit rate.

Attack class · Last updated August 2026
Pulse Wave Attacks
Repeated bursts, each ending before detection and diversion complete. The attack is not aimed at your capacity; it is aimed at the interval between noticing and acting, which is why more capacity does not help.

Attack class · Last updated August 2026
TCP ACK Flood
A flood of packets that look like they belong to established conversations. Every one forces a session-table lookup that finds nothing, and defences built around validating handshakes never see it coming.
What this site covers
Most DDoS buying advice is written either as a vendor brochure or as generic "what is a DDoS attack" filler. This site is aimed at the person who has to actually specify, budget and defend a mitigation architecture: what the appliance classes really differ on, where cloud scrubbing collides with data-residency law, how to size against your real uplink, and which questions belong in an RFP.
Our regional focus is Eastern Europe, Türkiye, Central Asia and the Gulf — markets where regulation, currency exposure and support geography change the answer, and where most English-language buying guides simply assume a US or Western European buyer.