Sitemap
Everything on this site
Every guide, dataset, tool and section, grouped the way the site is. The machine-readable version is the XML sitemap at the bottom.
118 pages listed
Foundations3
Attack classes19
- Carpet Bombing
- DDoS as a Smokescreen: What the SOC Should Watch in Parallel
- DNS Query Flood
- DNS Water Torture and Random Subdomain Attacks
- Hacktivist DDoS Campaigns: What Their Structure Means for Defenders
- How Modern Appliances Detect and Mitigate Carpet-Bombing DDoS Attacks
- HTTP Flood and Application-Layer Attacks
- HTTP/2 Rapid Reset
- ICMP Flood
- IP Fragmentation Attacks
- Multi-Vector DDoS
- Pulse Wave Attacks
- Reflection and Amplification Attacks
- Slowloris and Slow HTTP Attacks
- TCP ACK Flood
- TCP SYN Flood
- The DDoS Threat Landscape for Middle East Organisations: A Structural Reading
- TLS Handshake and Renegotiation Attacks
- UDP Flood
Mitigation techniques10
- Anycast for DDoS Mitigation
- Behavioural Baselining and ML Detection
- Behavioural, Threshold and Signature Detection Compared
- BGP FlowSpec for DDoS Mitigation
- DDoS Scrubbing: Diversion, Cleaning and Return
- DOTS: DDoS Open Threat Signaling
- Ingress Filtering: BCP 38, BCP 84 and uRPF
- Rate Limiting for DDoS Defence
- Remotely Triggered Black Hole Filtering (RTBH)
- SYN Proxy and SYN Cookies
Architecture and procurement26
- CapEx or Subscription: Two Ways to Pay for DDoS Protection
- Classification Decides the Architecture: A Qatar Assurance Reading of the DDoS Question
- Cloud vs. On-Premise vs. Hybrid DDoS Protection: Cost, Latency and Sovereignty
- DDoS Appliance Licensing Models Explained
- DDoS Appliance Sizing: Gbps Is Not Enough
- DDoS Mitigation Architecture Library
- DDoS Mitigation Buyer's Guide for ISPs and Telecom Operators
- DDoS Mitigation for Air-Gapped and Restricted Networks
- DDoS Protection for Banks and Payment Infrastructure
- DDoS Protection for Government and Critical Infrastructure
- DDoS Protection for Hosting Providers and Data Centres
- DDoS Protection for Online Gaming Platforms
- DDoS Protection for UAE Enterprises: Assurance, Residency and Architecture
- Firewall, IPS, WAF or DDoS Appliance: Which Control Owns Which Failure
- Inline or Out-of-Path, Always-On or On-Demand
- Local Detection or Cloud-Dependent Detection: What Changes
- On-Premise DDoS Mitigation for Regional ISPs on Constrained Budgets
- Sizing for the Peak You Already Have: DDoS Capacity Planning Around National Event Windows
- Sovereign Cyber Defence in the Gulf: Building National DDoS Mitigation Capacity
- Stateful and Stateless DDoS Defence: What Runs Out First
- Thin Transit: DDoS Resilience Where International Capacity Arrives Through a Few Cable Systems
- Turning DDoS Protection Into a Service Customers Pay For
- Two Layers, Two Vendors: Sourcing ISP and On-Premises DDoS Mitigation from Different Manufacturers
- Vendor Jurisdiction Risk in DDoS Mitigation: Russian, Chinese, US and Israeli Exposure Compared
- What Happens to Your DDoS Protection If the Vendor's Cloud Goes Offline?
- Why an On-Premise DDoS Appliance Lowers TCO Instead of Raising It
Server and platform hardening11
- Apache DDoS Hardening: MPM Choice, mod_reqtimeout and Per-IP Limits
- HAProxy DDoS Hardening and Tuning
- IIS DDoS Hardening: Dynamic IP Restrictions, Request Filtering and App Pool Queues
- JBoss / WildFly DDoS Hardening: Undertow Listener Limits and IO Threads
- Kubernetes Ingress DDoS Hardening
- Linux Network Stack Tuning for DDoS: NIC Queues, RSS/RPS and XDP
- Linux Server DDoS Hardening: Every sysctl, conntrack and nftables Setting
- nginx DDoS Hardening: Connection Limits, Rate Zones and Timeouts by Directive
- Tomcat DDoS Hardening: Connector Thread Pools, Timeouts and the Front Layer
- WebLogic DDoS Hardening: Work Managers, Message Timeouts and Overload Protection
- Windows Server DDoS Hardening: What Still Needs Tuning and What the OS Already Handles
Regulation and regional duties10
- Cybersecurity Cooperation Across the Turkic States: The DDoS Layer
- Data Residency and DDoS Mitigation in the GCC: Why Attack Traffic Shouldn't Leave the Country
- DDoS as a Licence Obligation: What Changes When Your Subscribers Are the Ones Harmed
- DDoS Protection and the NCA Essential Cybersecurity Controls: An Architecture and Evidence Guide
- DORA and DDoS Resilience Testing for EU Financial Entities
- Kazakhstan's Data Localisation Requirements and On-Premise DDoS Mitigation
- NIS2 and DDoS: What Essential and Important Entities Must Implement
- The Decision, the Evidence and the Answer: DDoS Readiness for a Knowledge Economy
- The SAMA Cyber Security Framework and DDoS Resilience: Architecture, Evidence and Testing
- Vision 2030 and the DDoS Layer: Why Traffic That Leaves Also Takes the Learning With It
Operations14
- A DDoS Mitigation Maturity Model, Level 0 to Level 5
- Authorised DDoS Testing, Legally and Safely
- DDoS Escalation Matrix
- DDoS Incident Response Runbook
- DDoS Mitigation KPIs That Actually Matter
- DDoS Mitigation RFP Template: Questions to Ask Every Vendor
- DDoS Post-Incident Review Template
- DDoS Readiness Assessment: How Prepared Is Your Network?
- DDoS Testing and Proof-of-Concept Methodology
- How Much Automation Is Too Much in DDoS Mitigation?
- How to Build a DDoS Test Lab, and the Acceptance Criteria to Use in It
- How to Read a DDoS Appliance Datasheet Without Being Misled
- How to Test False Positives in a DDoS Mitigation System
- The DDoS Buyer's Checklist, and the Claims That Need a Proof of Concept
Data10
- Data Methodology: How the Figures on This Site Are Handled
- DDoS attack vectors
- UDP reflection and amplification factors
- DDoS standards and primary references
- DDoS mitigation vendor capabilities
- Verified DDoS records, by metric
- Public DDoS threat reports
- DDoS-relevant CVEs
- Regulatory instruments with a DDoS dimension
- Vendor jurisdiction exposure, by mechanism
Tools2
Vendors and alternatives13
- A10 Thunder TPS Alternatives in 2026
- A10 Thunder TPS and A10 Defend: Architecture, Capabilities and Trade-offs
- Best On-Premise DDoS Mitigation Appliances in 2026
- Cloudflare Magic Transit On-Premise Alternatives: Keeping Traffic In-Country
- Corero SmartWall: Architecture, Capabilities and Trade-offs
- FortiDDoS vs Dedicated DDoS Appliances: When a Firewall-Family Product Is and Isn't Enough
- Fortinet FortiDDoS: Architecture, Capabilities and Trade-offs
- HARPP DDoS Mitigator: Architecture, Capabilities and Trade-offs
- NetScout Arbor AED Alternatives: Options Compared
- NETSCOUT Arbor Edge Defense: Architecture, Capabilities and Trade-offs
- Radware DefensePro Alternatives for Enterprises and ISPs
- Radware DefensePro: Architecture, Capabilities and Trade-offs
- The DDoS Mitigation Vendor Landscape, by Architecture