DNS
Replies from resolvers abused as reflectors
Ruk-Com protects your network, web services and APIs with VACUUM scrubbing and L3–L7 policies. Filter attack traffic before it reaches your systems, with support from our Network and Security team.
DDoS scrubbing
Filter attacks before your servers
950 Gbps is scrubbing capacity, not bandwidth per server or per customer.
A server firewall controls traffic that has already reached the host. When an upstream link is saturated, that is too late. Scrubbing before the protected access link is central to volumetric DDoS defense.
The response is logical communication from workload to user. Actual routing depends on deployment.
Attack and legitimate traffic reach the scrubbing layer, which separates policy-matched threats from allowed traffic. Event metadata informs the operations team’s policy review.
Logical illustration: response routing depends on deployment; this is not an actual PoP or network map.
Multiple illustrative flows run concurrently. No real attack or traffic is generated.
Our team reviews scrubbing, uplink and server capacity to identify bottlenecks, then plans routing and bandwidth around your actual traffic.
Reflection uses external services to send replies to the victim’s IP. Amplification occurs when those replies are larger than the requests. Many simultaneous replies concentrate load on the target’s network.
The VACUUM solution separates and filters this traffic before the protected link, using vector analysis and policies suited to the actual service.
The attack source impersonates the victim’s IP.
The reflector sends its reply toward the victim.
Drop packets identified as attacks before the uplink.
Replies from resolvers abused as reflectors
Time services exposed to unsuitable requests
Discovery services exposed to the internet
Responses from directory services
Cache services exposed externally
These protocols can be abused as reflectors. Response size depends on the request and each service’s configuration.
Select a scenario to see where packets, sessions or HTTP requests are inspected, alongside the path of allowed users.
The response is logical communication from workload to user. Actual routing depends on deployment.
An attacker spoofs the victim’s source IP in requests to external services that can return larger replies. Those replies head toward the victim through the scrubbing layer, where policy-matched traffic is dropped before the protected link.
Packet sizes are conceptual, not measured amplification ratios. DNS, NTP, SSDP, CLDAP and memcached behave differently.
Multiple illustrative flows run concurrently. No real attack or traffic is generated.
Scrubbing separates traffic and forwards what policy allows. Blackholing drops traffic to the target and affects service reachability. Stopping an attack by discarding target traffic is not the same as preserving service.
Gbps measures data volume. DDoS can also pressure packet processing, connection establishment and application work, so protection needs several measurements.
The data volume a link carries. Useful for assessing volumetric attacks and scrubbing capacity.
Many small packets can pressure network equipment even without saturating bandwidth.
Connection establishment rate, considered alongside concurrent sessions and system capacity.
HTTP request rate, evaluated against endpoint cost and origin resources.
950 Gbps is not a pps, cps or rps rating and does not specify bandwidth delivered to each workload.
Network scrubbing and application protection complement one another. Select control points and policies for each protocol rather than applying web controls to every service.
UDP/ICMP floods and reflected traffic can consume bandwidth needed by legitimate users. Filtering must sit upstream of the link being protected.
Volumetric → Upstream Scrubbing → Drop / Clean delivery
Vectors can span layers; protocol names alone are not enough to classify an attack.Inspect TCP/UDP behavior, including SYN floods and connection pressure. Apply supported state checks, rate policies and exceptions.
TCP / UDP → Protocol inspection → Allow / Drop / Rate control
Validate services such as games, VPNs or API transports. Arbitrary TCP/UDP does not use HTTP CAPTCHAs.HTTP floods, expensive requests and slow HTTP behavior require HTTP context and origin-load visibility after authorized TLS termination.
HTTPS → Network filtering → TLS → HTTP policy → Application
Browser challenges require compatible clients. Web/API deployments need context-appropriate rate, authentication and WAF policies.After network filtering, HTTP behavior and vulnerabilities still matter. Evaluate WAF and rule tuning alongside your DDoS plan.
Effective filtering depends on normal traffic baselines, coordination with system owners and checks after policy changes. Ruk-Com connects network and application operations.
Map IPs, protocols, ports, normal peaks and critical transactions.
Define thresholds, allowlists, change authority and coordination channels.
Use vector and bottleneck evidence to select supported controls.
Check reachability, errors, latency and origin load after changes.
Record the event, controls, observed impact and follow-up work.
Data scope, reporting cadence and support level are agreed before service activation.
Start with your exposed services and acceptable impact. Normal traffic and operating constraints differ by workload.
Distinguish HTTP floods from campaigns and check checkout/login impact.
Managed WAF ↗Review client behavior, authentication and costly endpoints without forcing CAPTCHAs onto APIs.
Cloud IaaS ↗Define protocols, ports and sessions needed by services such as games or VPNs.
Cloud IaaS ↗Assess IPs, uplinks, ingress/egress paths and coordination with enterprise network/SOC teams.
Colocation ↗Share your system details so our team can assess bottlenecks, connectivity and L3–L7 scope before defining the service and commercial terms.
Consult our team on LINE ↗Our team confirms the service scope, pricing and terms before you get started.
IPs/prefixes, current providers and actual ingress/egress paths.
Ports/protocols, normal/peak bandwidth and critical services.
Domains, TLS termination and web/API client constraints.
Attack history, contacts, change windows and rollback approach.
Working with our specialists across Technology and Cyber Security: monitoring, anomaly analysis, planning and coordinated response.
Technology · Performance, capacity and operations
Cyber Security · Risk, vulnerabilities and threat monitoring
Data access, changes and support levels follow the permissions and service scope agreed with our team.
Meet Ruk-Com AgentVACUUM scrubbing at 950 Gbps, with L3–L7 protection planned around your network, servers and applications.
Technical concept references: DDoS mitigation · Reflection / amplification · Application-layer DDoS
References explain technical concepts and do not identify a vendor deployment or partnership for Ruk-Com.