During a DDoS attack you want to know three things: is this really an attack, how much of it reaches me, and what is being done about it? How attacks work and which defences go with them is covered in DDoS attacks: how to protect your infrastructure. This article is about the moment itself: what happens between the first spike and the end of the attack, and how you follow it as a customer in our dashboard.
Not every spike is an attack
The first misconception is that you want an alarm for every outlier. A backup going out, a release that makes thousands of clients update at once, or a scan across your whole range: they all look like the start of an attack. An alert that often turns out to be a false alarm is one you learn to ignore within a week, and then you miss the real one.
A sudden rise is therefore only a possible attack at first. We check the shape of the traffic, which takes a few seconds. If it is an attack, it appears for you as a confirmed attack. If not, the signal disappears without bothering you. Short signals that were not confirmed as an attack do not appear in your list and do not send a notification.
The attack then moves through mitigation active and ended. Mitigation starts automatically; nobody has to be woken up before the attack traffic is held back. The page updates live; there is no need to refresh.
The overview: what hit you, and how hard
The dashboard's home page has a widget with the attacks of the past 72 hours. Under Network → DDoS you find the full log, filterable by period, network, status and type.
The column that makes the difference is reached you. The peak tells you how big the attack was at our edge; this column tells you how much of it reached your port. An attack of tens of gigabits of which a fraction arrived is a different story from a small attack that came through in full. If a peak is the highest for that network in the past 90 days, it gets a marker: useful if you want to know whether the attacks on your network are growing.
One attack in detail
Open an attack and you first see the target and the kind of attack. That distinction decides what makes sense to do:
- Aimed at one address — one server or service is the target; measures can be limited to that address.
- Carpet bomb — the attack spreads across (almost) every address in your /24, so no single address receives suspiciously much traffic on its own. The page shows how many addresses were hit.
- Packet flood — the problem is not the number of bits but the number of small packets; that hurts routers and firewalls before it hurts your bandwidth.
The timeline shows two lines: what was offered at our edge and what reached you. The space between them is what was held back. You can switch between bits and packets per second, and a logarithmic scale keeps your normal traffic visible next to a peak a hundred times its size.
Attack vectors shows what the attack consists of, for example UDP packets of a fixed size, or fragments. To a technical reader that immediately says whether it is amplification. Origin gives the spread across countries and networks. We deliberately do not show single source addresses: with amplification they are other people's abused servers, and with spoofed senders they mean nothing.
What we did lists the measures that were taken automatically, in plain sentences, with the time they took effect. For example a rate limit on a particular kind of traffic towards your prefix, or an address made temporarily unreachable from the internet to protect the rest of your network. That last one is the emergency brake from the article on DDoS protection: sacrificing one address so the rest of your network stays reachable.
Every attack has an attack ID. If you are affected anyway, report it via Report a problem on the same page; the ID goes along, so we look at the same attack right away instead of first agreeing on a time window.
Traffic: also when nothing is wrong
The DDoS traffic tab shows offered and delivered traffic over any period from an hour to ninety days, per network or per address. Both lines are measured all the time, not only during an attack. That shows you your usual range, and with it when something falls outside it.
Notifications: you do not have to watch
You do not need the dashboard open. At the start and end of a confirmed attack the account owner and your NOC contacts receive an e-mail with the target, the peak, the vectors and the measures, plus a link to the attack page. Under the DDoS notifications tab you set whether you want to be told when an attack is confirmed and when it ends, and who else gets the mail. With the webhook add-on the same notification lands in Slack or Discord, or as signed JSON in your own system; a following article covers that.
DDoS protection at Xyphen IT
The DDoS overview is part of the dashboard for customers with IP transit or colocation on our network. If you want someone watching alongside you when things get tense, NOC as a Service fits with it. Curious what this looks like for your network? Get in touch and we will show you.