Core Capability

Keep Your Services Online
During DDoS Attacks.

Neurowall drops attack traffic at the network driver level — before the Linux kernel allocates memory for it. Legitimate traffic continues flowing. Applications stay online.

272K+
Active rules, zero sync failures (verified)
250k+
IP block rules with no throughput impact
7
DDoS protection modules
The Problem

Attacks are growing.
Tolerance for downtime is not.

Even modest attacks can overwhelm under-provisioned infrastructure. Cloud-based mitigation adds latency. Traditional appliances need expensive upgrades.

Increasing Attack Volumes

Attack traffic grows year over year. Infrastructure designed for normal traffic levels may not absorb even moderate attacks.

Cloud Mitigation Adds Latency

Scrubbing center redirects add round-trip latency for all traffic — attack or legitimate. On-premise filtering keeps latency low.

Hardware Upgrade Costs

Traditional appliances require hardware upgrades to handle higher attack volumes. Software filtering scales with CPU and NIC.

Slow Response Time

Manual mitigation during an attack costs time. Pre-configured rate limits and blocklists activate automatically.

How It Works

Drop attack traffic before
it costs you anything.

Incoming Traffic
legitimate + attack mixed
↓
Neurowall XDP Filter
NIC driver level — before kernel sk_buff allocation
↓
XDP_DROP↓attack traffic
XDP_PASS→Applications

Because XDP runs at the network driver, dropped packets never allocate kernel memory, never traverse netfilter, and never reach userspace. The per-packet cost of a drop decision is measured in nanoseconds.

DDoS Resilience Under Load

During sustained attacks, the system remains responsive for legitimate traffic. CPU usage scales with packet rate — not attack sophistication.

Protection Mechanisms

Seven modules.
One platform.

MechanismDescription
Per-source rate limitingToken bucket algorithm — limits packets per source IP before they overwhelm services
IP blocklistsBlock known attack sources via AbuseIPDB, OTX, MISP, and custom threat feeds
CIDR-based filteringBlock entire subnets associated with attack infrastructure
Protocol filteringDrop traffic on unused protocols to reduce attack surface
Connection trackingIdentify and filter stateless flood traffic
DNS sinkholePrevent DNS amplification by blocking known reflector domains
Allowlist bypassTrusted sources always pass — protection never blocks legitimate partners
Attack Coverage

Every major flood type.
Stopped at the edge.

Neurowall inspects and drops malicious packets per attack signature — before they reach connection state, application logic, or backend services.

01

Rate Limiting

General-purpose backstop

Limits excessive requests from a single source against a configured per-IP rate — the general-purpose backstop that sits behind the six flood-specific modules below. Every source, regardless of protocol, is measured against a token-bucket budget before it can consume protected resources.

  • Detects: requests per source, key, or endpoint over a configurable time window.
  • Allows: traffic that stays inside the configured rate and burst budget.
  • Drops: requests that exceed the rate or burst threshold, before they reach the application.

Neurowall: per-source token bucket enforced at the XDP layer — tunable at runtime, with no traffic interruption while thresholds change.

Full Guide →

02

SYN Flood

Protocol attack

Floods the connection backlog with SYN packets to exhaust half-open connection slots — a classic resource-exhaustion pattern. Each individual SYN can look like a normal handshake attempt, so no static policy rule alone can catch it; what matters is the rate and pattern across many connections at once.

  • Detects: abnormal SYN rate per source against backlog capacity.
  • Allows: legitimate handshakes that complete the normal three-way exchange.
  • Drops: excess SYNs before they ever occupy a backlog slot.

Neurowall: dedicated SYN flood module, benchmarked sustaining ~96K PPS with 375,000 policies loaded and the system still responsive.

Full Guide →

03

ACK Flood

Protocol attack

Sends unsolicited ACK packets with no matching connection in an attempt to consume state-tracking resources. Each individual ACK looks like ordinary TCP traffic in isolation — exactly why a stateless firewall rule can't distinguish it from legitimate traffic without checking it against real connection state.

  • Detects: ACKs that don't correspond to any tracked connection.
  • Allows: ACKs that match an established session.
  • Drops: unsolicited or out-of-state ACKs at the edge.

Neurowall: validates ACKs against tracked connection state; off by default, enabled for gateway deployments with predictable session patterns.

Full Guide →

04

ICMP Flood

Volumetric attack

Floods the target with ICMP echo requests to saturate available bandwidth or exhaust CPU cycles spent generating echo replies. Unlike protocol attacks, the goal here is raw volume — enough traffic that the link or the host's packet-processing capacity fills up regardless of any single packet's validity.

  • Detects: ICMP echo rate and aggregate burst volume per source and in total.
  • Allows: normal diagnostic ICMP traffic within configured volume limits.
  • Drops: excess echo requests once the configured rate or volume ceiling is hit.

Neurowall: dedicated ICMP module, benchmarked sustaining ~83K PPS in the same 375,000-policy test as the SYN flood above.

Full Guide →

05

FIN Flood

Protocol attack

Floods the target with FIN packets for connections that don't exist, aiming to consume connection-teardown processing rather than backlog capacity. Because FIN handling touches the same connection-tracking state as legitimate teardown traffic, this module is tuned to avoid flagging ordinary session closes as attacks.

  • Detects: FIN packets with no corresponding tracked connection.
  • Allows: FIN packets that correctly close an existing, tracked session.
  • Drops: FINs for connections the system never established.

Neurowall: verifies FIN against tracked TCP state; off by default to avoid false positives on legitimate teardown traffic, tunable per deployment.

Full Guide →

06

RST Flood

Protocol attack

Floods the target with RST packets aimed at forcing established, legitimate connections to close — a targeted disruption of active sessions rather than pure resource exhaustion. A forged RST can terminate a real session if its source, sequence number, and state aren't checked against what the connection actually expects.

  • Detects: RSTs whose source, sequence, or state doesn't match the connection they claim to close.
  • Allows: RSTs that are consistent with the connection's real state and sequence.
  • Drops: forged or out-of-state RSTs before they can tear down a legitimate session.

Neurowall: validates RST source, sequence, and state before honoring it; off by default alongside FIN, same false-positive-avoidance rationale.

Full Guide →

07

UDP Cost Filter

Volumetric / amplification attack

Covers UDP-based amplification attacks — DNS, NTP, memcached-style reflection — where a small forged request generates a disproportionately large response directed at the victim, multiplying attacker bandwidth many times over. UDP traffic is scored by amplification risk rather than treated as one uniform category.

  • Detects: UDP traffic patterns and ports associated with known amplification vectors.
  • Allows: low-cost UDP traffic that carries no amplification risk.
  • Drops: high-cost, reflector-prone UDP requests before they reach an amplifier.

Neurowall: filters UDP by amplification-risk cost, plus a DNS sinkhole that blocks known reflector domains outright.

Fragmentation Flood Guide →

Buyer Guides

Comparing vendors and total cost.

DDoS Protection Comparison

NeuroWall vs Cloudflare, AWS Shield, Akamai Prolexic, Radware DefensePro and Imperva.

Read Guide →
DDoS Protection TCO

What DDoS protection really costs — software, bandwidth and infrastructure compared.

Read Guide →
Gaming DDoS TCO

Game-server DDoS protection costs across NeuroWall, AWS, cloud scrubbing and managed hosting.

Read Guide →
Business Benefits

What your organization gains.

Maintain Availability

Keep applications online during attacks. Filter at the edge, not at the application layer where damage is already done.

Reduce Blast Radius

Attack traffic is absorbed at the gateway. Backend services, databases, and internal infrastructure remain unaffected.

Lower Mitigation Costs

On-premise protection without per-attack cloud scrubbing charges. Predictable cost regardless of attack frequency.

Respond Automatically

Pre-configured rate limits and blocklists activate the moment attack traffic arrives. No manual intervention required.

Distributed Defense

Deploy across multiple gateways for defense at every network entry point. Centrally managed from one control plane.

Full Visibility

70+ Prometheus metrics expose attack traffic, block rates, and system health in real time through Grafana dashboards.

Get started

Ready to improve your DDoS resilience?