Neurowall drops attack traffic at the network driver level — before the Linux kernel allocates memory for it. Legitimate traffic continues flowing. Applications stay online.
Even modest attacks can overwhelm under-provisioned infrastructure. Cloud-based mitigation adds latency. Traditional appliances need expensive upgrades.
Attack traffic grows year over year. Infrastructure designed for normal traffic levels may not absorb even moderate attacks.
Scrubbing center redirects add round-trip latency for all traffic — attack or legitimate. On-premise filtering keeps latency low.
Traditional appliances require hardware upgrades to handle higher attack volumes. Software filtering scales with CPU and NIC.
Manual mitigation during an attack costs time. Pre-configured rate limits and blocklists activate automatically.
Because XDP runs at the network driver, dropped packets never allocate kernel memory, never traverse netfilter, and never reach userspace. The per-packet cost of a drop decision is measured in nanoseconds.
During sustained attacks, the system remains responsive for legitimate traffic. CPU usage scales with packet rate — not attack sophistication.
| Mechanism | Description |
|---|---|
| Per-source rate limiting | Token bucket algorithm — limits packets per source IP before they overwhelm services |
| IP blocklists | Block known attack sources via AbuseIPDB, OTX, MISP, and custom threat feeds |
| CIDR-based filtering | Block entire subnets associated with attack infrastructure |
| Protocol filtering | Drop traffic on unused protocols to reduce attack surface |
| Connection tracking | Identify and filter stateless flood traffic |
| DNS sinkhole | Prevent DNS amplification by blocking known reflector domains |
| Allowlist bypass | Trusted sources always pass — protection never blocks legitimate partners |
Neurowall inspects and drops malicious packets per attack signature — before they reach connection state, application logic, or backend services.
Limits excessive requests from a single source against a configured per-IP rate — the general-purpose backstop that sits behind the six flood-specific modules below. Every source, regardless of protocol, is measured against a token-bucket budget before it can consume protected resources.
Neurowall: per-source token bucket enforced at the XDP layer — tunable at runtime, with no traffic interruption while thresholds change.
Floods the connection backlog with SYN packets to exhaust half-open connection slots — a classic resource-exhaustion pattern. Each individual SYN can look like a normal handshake attempt, so no static policy rule alone can catch it; what matters is the rate and pattern across many connections at once.
Neurowall: dedicated SYN flood module, benchmarked sustaining ~96K PPS with 375,000 policies loaded and the system still responsive.
Sends unsolicited ACK packets with no matching connection in an attempt to consume state-tracking resources. Each individual ACK looks like ordinary TCP traffic in isolation — exactly why a stateless firewall rule can't distinguish it from legitimate traffic without checking it against real connection state.
Neurowall: validates ACKs against tracked connection state; off by default, enabled for gateway deployments with predictable session patterns.
Floods the target with ICMP echo requests to saturate available bandwidth or exhaust CPU cycles spent generating echo replies. Unlike protocol attacks, the goal here is raw volume — enough traffic that the link or the host's packet-processing capacity fills up regardless of any single packet's validity.
Neurowall: dedicated ICMP module, benchmarked sustaining ~83K PPS in the same 375,000-policy test as the SYN flood above.
Floods the target with FIN packets for connections that don't exist, aiming to consume connection-teardown processing rather than backlog capacity. Because FIN handling touches the same connection-tracking state as legitimate teardown traffic, this module is tuned to avoid flagging ordinary session closes as attacks.
Neurowall: verifies FIN against tracked TCP state; off by default to avoid false positives on legitimate teardown traffic, tunable per deployment.
Floods the target with RST packets aimed at forcing established, legitimate connections to close — a targeted disruption of active sessions rather than pure resource exhaustion. A forged RST can terminate a real session if its source, sequence number, and state aren't checked against what the connection actually expects.
Neurowall: validates RST source, sequence, and state before honoring it; off by default alongside FIN, same false-positive-avoidance rationale.
Covers UDP-based amplification attacks — DNS, NTP, memcached-style reflection — where a small forged request generates a disproportionately large response directed at the victim, multiplying attacker bandwidth many times over. UDP traffic is scored by amplification risk rather than treated as one uniform category.
Neurowall: filters UDP by amplification-risk cost, plus a DNS sinkhole that blocks known reflector domains outright.
NeuroWall vs Cloudflare, AWS Shield, Akamai Prolexic, Radware DefensePro and Imperva.
Read Guide →What DDoS protection really costs — software, bandwidth and infrastructure compared.
Read Guide →Game-server DDoS protection costs across NeuroWall, AWS, cloud scrubbing and managed hosting.
Read Guide →Keep applications online during attacks. Filter at the edge, not at the application layer where damage is already done.
Attack traffic is absorbed at the gateway. Backend services, databases, and internal infrastructure remain unaffected.
On-premise protection without per-attack cloud scrubbing charges. Predictable cost regardless of attack frequency.
Pre-configured rate limits and blocklists activate the moment attack traffic arrives. No manual intervention required.
Deploy across multiple gateways for defense at every network entry point. Centrally managed from one control plane.
70+ Prometheus metrics expose attack traffic, block rates, and system health in real time through Grafana dashboards.