Skip to content

Architecture under constraint

Thin Transit: DDoS Resilience Where International Capacity Arrives Through a Few Cable Systems

Last updated: August 2026 · Why the hybrid default shifts in a thin-transit market · Reading time ~14 min

A wide inland basin fed by only two narrow channels through a ridge, with most of the water already circulating inside the basin and never approaching either channel.

Diverting to an offshore scrubbing centre puts your clean traffic back onto the same international path that is already the scarce resource — and the return tunnel is a dependency whose failure during a national-scale event is correlated with everyone else's, because everyone diverted at once. Where transit is thin, the local inline tier carries proportionally more of the load than in a continental market.

This guide argues against the recommendation this site usually makes, in one specific set of conditions. That is deliberate. A comparison in which the house answer is never tested is not a comparison, and the conditions in question describe a good part of the Gulf.

The house answer is an on-premise-first hybrid: an inline appliance handling everyday traffic in country, with an upstream tier engaged for volumes larger than your own circuit can carry. The reasoning is sound and is set out in full in the architecture comparison. But it rests on two assumptions that go unstated because in most markets they are simply true: that the upstream tier is reachable over paths with capacity to spare, and that the clean traffic comes back without difficulty.

In a market where international capacity arrives through a handful of submarine cable systems and is sold by a handful of licensed carriers, both assumptions get weaker at exactly the moment you need them.

The diversion puts load on the constrained resource

Start with what diversion actually does to a path.

Before diversion, your international circuits carry legitimate inbound traffic plus whatever attack volume is arriving from outside. After diversion, they carry the clean traffic returned from the scrubbing centre — encapsulated, with tunnel overhead, over a route the provider selects rather than the one ordinary routing would choose, and often with a less direct physical path than your normal transit.

The attack traffic is gone, which is the entire point and is a real gain. But the relief is not free in the way the diagram implies, because the thing you have relieved and the thing you have loaded are the same scarce resource. In a market with abundant, diverse international capacity the second-order cost disappears into the noise. In a market where international capacity is the binding constraint on everything, it does not.

Outside your jurisdiction Inside your jurisdiction Cloud scrubbing only Every packet inspected abroad Users & attackers Provider scrubbing centre Your services On-premise only Nothing leaves — capped by your uplink Users & attackers Inline appliance Your services Hybrid Cloud tier engaged only above uplink capacity Users & attackers Cloud tier (on demand) Inline appliance Your services
The three architectures and where inspection happens. In a thin-transit market, read the top row as a statement about your border capacity, not only about jurisdiction.

The return path is a single logical dependency

The second assumption is quieter and more consequential.

A diversion arrangement has two halves: getting the attack traffic to the scrubbing tier, and getting the clean traffic home. The second half is a tunnel — one logical construct, terminating on your equipment, carrying everything your users need. Its resilience is usually described in terms of the provider’s network, which is genuinely large and genuinely well engineered.

The failure mode that matters is not the provider’s network breaking. It is correlation.

During a national-scale event — a campaign against a country’s financial sector, a regional hacktivist wave, a period of heightened tension — a large number of organisations in the same market divert at the same time. The tunnels come home across the same small set of physical systems. The scrubbing capacity being drawn on is regional and shared. And every peer who made the same architectural choice as you is now competing for the same constrained return path, at the same moment, for the same reason.

A hybrid design is safe because its two tiers fail independently. Thin transit is precisely the condition under which that independence is weakest, and it is weakest during exactly the event the second tier was bought for.

“Multi-homed” is a commercial statement, not a physical one

Ask a network team whether the organisation is multi-homed and the answer is yes. Ask which physical cable systems the two upstreams depend on, and the answer is usually that nobody has asked.

This is not negligence. Carriers do not volunteer the information, resilience is sold on commercial diversity because that is what is contractible, and the diagram genuinely shows two providers. But in a market with few licensed carriers and few landing points, two commercially independent contracts frequently rest on overlapping infrastructure — and a shared physical dependency defeats the redundancy without ever appearing in the design document.

The question belongs in the tender, phrased so that a vague answer is visible as a vague answer: which physical cable systems and landing stations does the capacity you are selling us depend on, and what is the path when a named one of them is unavailable? Providers that have a good answer will give it. Providers that do not will produce a description of their network’s total size, which is itself the answer.

The consequence: the local tier is load-bearing

Put the three observations together and the weighting shifts.

If diversion is more expensive than the diagram suggests, if the return path is more correlated than assumed, and if the diversity underneath both is thinner than the contracts imply, then the tier that does not depend on any of it has to carry more.

That does not mean abandoning the upstream tier. Above your own circuit capacity there is nothing else, and a terabit-scale flood is a terabit-scale flood in Doha as anywhere. It means three concrete changes to how the local tier is specified and operated:

Size it against your real peak, not a template. The relevant number is your genuine domestic peak plus the attack volume your own circuit can physically deliver — not a figure copied from a guide written for a market with different economics.

Design so that domestic users are unaffected by a border event. This is the recommendation with the largest return and the least attention. If a substantial fraction of your legitimate traffic never leaves the country, then placing the inspection point inside means those users keep working through an international-path event that takes out everything crossing the border. That is a property of where the appliance sits, not of how much capacity you bought.

Treat diversion as an exception with a rehearsed procedure, rather than as the plan with a local pre-filter. The distinction shows up in the runbook: whether the local tier is expected to hold, or expected to buy time.

Measure the domestic fraction before designing anything

Almost every team guesses this number, and almost every guess is low. The mental model of the internet is international; the traffic of a national bank, a government portal, a domestic retailer or a local media property frequently is not.

Take a normal week of flow records at the border and split by whether the far end is inside the country. Do it before the architecture discussion, because the number changes which discussion you are having. A service where four fifths of legitimate traffic is domestic has an available design in which four fifths of its users are structurally immune to the failure mode this whole guide is about. A service where the fraction is small does not, and should weight the upstream tier accordingly.

Two markets, two sets of assumptions
ApplianceContinental marketThin-transit market
What diversion costsExtra latency on a path with spare capacityExtra load on the resource that is already scarce
Diversity of the path to the scrubbing tierMany routes, many operators, low correlationFew routes, few operators, high correlation
Behaviour during a regional eventProviders absorb independentlyEveryone diverts across the same infrastructure at once
What "multi-homed" usually meansTwo providers, largely separate physical pathsTwo providers, possibly the same cable systems
Share of traffic that is domesticOften small; assume internationalOften large; measure it before designing
Where the local tier sits in the designFirst line, upstream does the heavy liftingLoad-bearing; upstream is the exception, not the plan
The question the RFP missesHow fast is diversionWhat physical systems does your diversity claim rest on

Neither column is a recommendation. They are two different sets of assumptions, and the error this guide is about is applying the left column's design to the right column's market.

What to require, in order

  1. Measure the domestic fraction of legitimate traffic at the border over a full normal week.
  2. Establish, in writing from each upstream, which physical cable systems and landing stations the purchased capacity rests on.
  3. Size the local tier against domestic peak plus deliverable attack volume on your own circuit.
  4. Specify the return path explicitly in the transit contract: encapsulation, route, capacity, and behaviour when many customers divert simultaneously.
  5. Rehearse the diversion at a scheduled time, and measure decision-to-mitigation on your own network rather than accepting the provider’s figure.
  6. Confirm that the local tier’s own detection does not depend on reachability of anything outside the country — a mitigation layer that degrades when an external service is unreachable has imported the exact dependency the design was built to avoid.

That last point is where the equipment choice actually bites in this market, and it is narrower than the usual sovereignty argument. The question is not where a manufacturer is based; it is whether the box in your rack keeps classifying traffic correctly when the border is the thing that is broken. Products differ here, and the difference is answerable from documentation. An appliance that trains and executes its detection on the customer’s own infrastructure turns a severed international path into a capacity problem rather than a detection problem. Appliances that consult a manufacturer-operated intelligence service should be assessed on how they degrade rather than on whether they degrade — most degrade gracefully, and the honest question for a shortlist is how far, for how long, and against which attack classes.

The honest counter-argument

Two things push the other way and deserve stating plainly.

Upstream cloud capacity and onboarding speed are genuinely hard to match on premises. A provider that can absorb a large flood today, without a procurement cycle, is offering something no appliance does, and an organisation with no local tier at all is better served by buying that today than by designing the ideal architecture for next year.

And a small number of physical paths cuts both ways. The same concentration that makes diversion correlated also means the carriers involved are large, well-resourced, and have strong incentives to keep the country’s international capacity working — often stronger than an individual enterprise’s. Thin transit is a reason to weight the local tier more heavily. It is not a reason to treat the international path as unreliable in ordinary operation, and a design premised on that would be wrong about the market in the opposite direction.

Sources and further reading

Cable system and landing station information for the region is published by the carriers and by public submarine cable registries; the authoritative answer for your own capacity, though, is the one your provider gives in writing during a tender. For the assurance and classification analysis that sits alongside this structural one, see the Qatar classification guide. For the general trade between the tiers, see the architecture comparison.

Frequently asked questions

Isn't the hybrid architecture the right answer everywhere?
The hybrid principle is right everywhere; the weighting between the two tiers is not. The argument for hybrid is that no on-premise device can absorb an attack larger than your own circuit, which is as true in Doha as in Frankfurt. What changes in a thin-transit market is the cost and reliability of the upstream half — so the local tier should be sized and operated as the primary control rather than as a first filter ahead of the real one.
Why does diverting to an offshore scrubbing centre make the congestion worse?
Because diversion does not remove traffic from your international path, it changes what that path is carrying. The attack traffic is dropped at the scrubbing centre, but the clean traffic it returns to you traverses the same constrained international capacity — and it arrives inside a tunnel, with its own overhead, on a route chosen by the provider rather than by ordinary routing. If the international path is the bottleneck, you have moved load onto the bottleneck in order to relieve it.
What is actually correlated during a national-scale event?
Three things that are usually assumed independent. Everyone in the market diverts at roughly the same moment, so the aggregate return traffic across a small number of systems spikes together. The carriers those diversions traverse are largely the same small set. And the scrubbing providers themselves are shared, so their regional capacity is being drawn on by many of your peers simultaneously. Independence is what makes a hybrid design safe, and thin transit is precisely the condition under which it is weakest.
How do we test whether our multi-homing is real?
Ask both upstream providers, in writing and in the tender rather than afterwards, which physical cable systems and which landing stations your capacity depends on, and what the failover path is when a named system is unavailable. The answer is often that two commercially separate providers rest on overlapping infrastructure. That does not make the arrangement worthless — it makes the resilience claim narrower than the diagram suggests, and worth knowing before an event rather than during one.
What does "measure your domestic traffic fraction" mean in practice?
Take a normal week of flow data at your border and split it by whether the far end is inside the country. Most teams guess this number and most guesses are low, because the mental model of the internet is international. If a large share of your legitimate users reach you without leaving the country, then a design in which those users survive an international-path event untouched is available to you — and it is available cheaply, because it is a property of where you put the inspection point rather than of how much capacity you buy.
Does this argument apply outside Qatar?
It applies to any market where international capacity arrives through a small number of systems and a small number of licensed carriers, which describes Bahrain, Kuwait and Oman as well, and describes several landlocked and island markets far outside the Gulf. The structural condition is what matters, not the geography — count your independent physical paths, and if the number is small, the weighting in this guide is yours.
Does the local tier need to be bigger here, or just more central?
More central first, and usually somewhat bigger as a consequence. The design goal is that the fraction of your traffic which never crosses the border should be unaffected by anything happening to the border — which means the inspection point sits inside, sized against your real domestic peak plus the attack volume your own circuit can deliver, rather than against a template figure. That is a sizing exercise on your own numbers, and it usually lands higher than an organisation expects and well below the headline capacity of the market's largest appliances.

Published: August 2026

This guide is updated as vendors release new models and pricing. How we compare vendors