RUK-COM / DDOS PROTECTION

DDoS protection.
Keep customers connected.

Ruk-Com protects your network, web services and APIs with VACUUM scrubbing and L3–L7 policies. Filter attack traffic before it reaches your systems, with support from our Network and Security team.

L3 · L4 · L7Reflection / AmplificationManaged policy
VACUUM / SCRUBBING CAPACITY
950Gbps

DDoS scrubbing
Filter attacks before your servers

InternetAllowed + attack
VACUUMInspect & filter
WorkloadAllowed traffic

950 Gbps is scrubbing capacity, not bandwidth per server or per customer.

PROTECT THE PATH

Filter DDoS before
your uplink fills up

A server firewall controls traffic that has already reached the host. When an upstream link is saturated, that is too late. Scrubbing before the protected access link is central to volumetric DDoS defense.

PROTECTION OVERVIEW

The traffic path to your server

ILLUSTRATIVE
Legitimate usersUpstream scrubbingProtected linkWorkload
Attack trafficVACUUM scrubbingDrop / rate control
Scrubbing eventsTeam reviewPolicy adjustment

The response is logical communication from workload to user. Actual routing depends on deployment.

Allowed inputAttack / dropClean deliveryResponseTelemetryPolicy / challenge

Attack and legitimate traffic reach the scrubbing layer, which separates policy-matched threats from allowed traffic. Event metadata informs the operations team’s policy review.

Logical illustration: response routing depends on deployment; this is not an actual PoP or network map.

Multiple illustrative flows run concurrently. No real attack or traffic is generated.

Our team reviews scrubbing, uplink and server capacity to identify bottlenecks, then plans routing and bandwidth around your actual traffic.

VACUUM / REFLECTION & AMPLIFICATION

Amplification attacks.
Small requests, heavy impact.

Reflection uses external services to send replies to the victim’s IP. Amplification occurs when those replies are larger than the requests. Many simultaneous replies concentrate load on the target’s network.

The VACUUM solution separates and filters this traffic before the protected link, using vector analysis and policies suited to the actual service.

01
Spoofed source IP

The attack source impersonates the victim’s IP.

02
Reflectors send replies

The reflector sends its reply toward the victim.

03
VACUUM filters attack traffic

Drop packets identified as attacks before the uplink.

DNS

Replies from resolvers abused as reflectors

NTP

Time services exposed to unsuitable requests

SSDP

Discovery services exposed to the internet

CLDAP

Responses from directory services

memcached

Cache services exposed externally

These protocols can be abused as reflectors. Response size depends on the request and each service’s configuration.

EXPLORE THE MITIGATION

See how different
DDoS attacks are handled

Select a scenario to see where packets, sessions or HTTP requests are inspected, alongside the path of allowed users.

ATTACK SCENARIO

Small requests. Larger responses.

ILLUSTRATIVE
Legitimate usersUpstream scrubbingProtected linkWorkload
Spoofed-source requestExternal reflectorsVACUUM scrubbingDrop
Scrubbing eventsTeam reviewPolicy adjustment

The response is logical communication from workload to user. Actual routing depends on deployment.

Allowed inputAttack / dropClean deliveryResponseTelemetryPolicy / challenge

An attacker spoofs the victim’s source IP in requests to external services that can return larger replies. Those replies head toward the victim through the scrubbing layer, where policy-matched traffic is dropped before the protected link.

Packet sizes are conceptual, not measured amplification ratios. DNS, NTP, SSDP, CLDAP and memcached behave differently.

Multiple illustrative flows run concurrently. No real attack or traffic is generated.

How does scrubbing differ from blackholing?

Scrubbing separates traffic and forwards what policy allows. Blackholing drops traffic to the target and affects service reachability. Stopping an attack by discarding target traffic is not the same as preserving service.

MORE THAN A BANDWIDTH NUMBER

DDoS is about
more than Gbps

Gbps measures data volume. DDoS can also pressure packet processing, connection establishment and application work, so protection needs several measurements.

bps

Bits per second

The data volume a link carries. Useful for assessing volumetric attacks and scrubbing capacity.

pps

Packets per second

Many small packets can pressure network equipment even without saturating bandwidth.

cps

Connections per second

Connection establishment rate, considered alongside concurrent sessions and system capacity.

rps

HTTP requests per second

HTTP request rate, evaluated against endpoint cost and origin resources.

950 Gbps is not a pps, cps or rps rating and does not specify bandwidth delivered to each workload.

L3–L7 / LAYERED BY DESIGN

Protect the network,
connections and applications

Network scrubbing and application protection complement one another. Select control points and policies for each protocol rather than applying web controls to every service.

01L3 / VOLUME

Filter floods before uplinks fill up

UDP/ICMP floods and reflected traffic can consume bandwidth needed by legitimate users. Filtering must sit upstream of the link being protected.

Source / Destination · Protocol · Traffic pattern
CONTROL PATH

Volumetric → Upstream Scrubbing → Drop / Clean delivery

Vectors can span layers; protocol names alone are not enough to classify an attack.
02L4 / CONNECTION

Handle SYN floods and connection overload

Inspect TCP/UDP behavior, including SYN floods and connection pressure. Apply supported state checks, rate policies and exceptions.

Protocol / State · Port · Connection rate
CONTROL PATH

TCP / UDP → Protocol inspection → Allow / Drop / Rate control

Validate services such as games, VPNs or API transports. Arbitrary TCP/UDP does not use HTTP CAPTCHAs.
03L7 / APPLICATION

Reduce HTTP floods that slow your website

HTTP floods, expensive requests and slow HTTP behavior require HTTP context and origin-load visibility after authorized TLS termination.

Path / Method · Request rate · Application context
CONTROL PATH

HTTPS → Network filtering → TLS → HTTP policy → Application

Browser challenges require compatible clients. Web/API deployments need context-appropriate rate, authentication and WAF policies.
OPERATIONS / FROM SIGNAL TO ACTION

Plan with our team.
Get help during attacks.

Effective filtering depends on normal traffic baselines, coordination with system owners and checks after policy changes. Ruk-Com connects network and application operations.

01

Review normal traffic

Map IPs, protocols, ports, normal peaks and critical transactions.

02

Agree policies

Define thresholds, allowlists, change authority and coordination channels.

03

Analyze and mitigate attacks

Use vector and bottleneck evidence to select supported controls.

04

Check customer access

Check reachability, errors, latency and origin load after changes.

05

Review & improve

Record the event, controls, observed impact and follow-up work.

EVIDENCE THAT HELPS DECISIONS

Understand the attack and the response

  • Observed timing and vectors, with data coverage
  • Relevant peak bps/pps, connections and HTTP rates
  • Applied policies, changes and verified outcomes

Data scope, reporting cadence and support level are agreed before service activation.

BUILT AROUND YOUR WORKLOAD

Protection that fits your systems

Start with your exposed services and acceptable impact. Normal traffic and operating constraints differ by workload.

Web & ecommerce

Distinguish HTTP floods from campaigns and check checkout/login impact.

Managed WAF ↗

APIs & business platforms

Review client behavior, authentication and costly endpoints without forcing CAPTCHAs onto APIs.

Cloud IaaS ↗

TCP / UDP services

Define protocols, ports and sessions needed by services such as games or VPNs.

Cloud IaaS ↗

Enterprise infrastructure

Assess IPs, uplinks, ingress/egress paths and coordination with enterprise network/SOC teams.

Colocation ↗
DESIGN THE RIGHT PROTECTION

Talk to our Network team.
Plan your DDoS protection.

Share your system details so our team can assess bottlenecks, connectivity and L3–L7 scope before defining the service and commercial terms.

Consult our team on LINE

Our team confirms the service scope, pricing and terms before you get started.

What helps us scope the solution

01
Public IPs & routing

IPs/prefixes, current providers and actual ingress/egress paths.

02
Traffic & workload

Ports/protocols, normal/peak bandwidth and critical services.

03
HTTP & TLS

Domains, TLS termination and web/API client constraints.

04
Incidents & operations

Attack history, contacts, change windows and rollback approach.

Ruk-Com Agent

Agent support across every service

Working with our specialists across Technology and Cyber Security: monitoring, anomaly analysis, planning and coordinated response.

Technology · Performance, capacity and operations

Cyber Security · Risk, vulnerabilities and threat monitoring

Data access, changes and support levels follow the permissions and service scope agreed with our team.

Meet Ruk-Com Agent
BEFORE YOU START

Frequently asked questions

Does 950 Gbps mean my server receives 950 Gbps?
No. This is the service’s scrubbing capacity, not clean bandwidth per server, customer or PoP, nor a pps/cps/rps rating. Delivered bandwidth is defined in the agreed service scope.
How does VACUUM address amplification?
The approach routes traffic through upstream scrubbing before the protected link, identifies reflected traffic and applies drop/rate policies while forwarding allowed traffic. It is not an unconditional guarantee against every attack.
Why add this if I already have a server firewall?
A host firewall acts after traffic crosses the link to reach the server. If an attack saturates the uplink, legitimate traffic may never arrive. Host firewalls and upstream scrubbing are complementary.
Can L3/L4 scrubbing inspect encrypted HTTPS content?
Generic network filtering does not read encrypted HTTP payloads. L7 policy requires supported TLS termination and HTTP-aware components with authorized TLS handling under the agreed design.
Can browser challenges protect APIs and arbitrary TCP/UDP?
Controls differ by service. Browser challenges suit compatible clients; APIs may need rate/auth policies, while TCP/UDP services require protocol/session controls.
Will an attack have no service impact?
Scrubbing capacity alone cannot establish that. Impact depends on attack size/type, routing, uplinks, policies and application capacity. We assess the full path and verify real-user effects.
How do I start and request a quote?
Share public IPs, traffic, protocols, workloads and attack history. We then agree connectivity, required L7 modules, operating scope, pricing and terms before activation.
CAPACITY + CONTROL + CARE

Let Ruk-Com help manage
your DDoS protection

VACUUM scrubbing at 950 Gbps, with L3–L7 protection planned around your network, servers and applications.

Talk to Ruk-ComExplore monitoring with SOC Center

Technical concept references: DDoS mitigation · Reflection / amplification · Application-layer DDoS

References explain technical concepts and do not identify a vendor deployment or partnership for Ruk-Com.