ddos-mitigation

3 posts

cloudflare

Introducing Programmable Flow Protection: custom DDoS mitigation logic for Magic Transit customers (opens in new tab)

Programmable Flow Protection lets Magic Transit Enterprise customers define custom DDoS mitigation logic for proprietary UDP protocols. Customers write eBPF programs that identify valid and malicious packets, then deploy them across Cloudflare’s global network to pass, drop, or challenge traffic. Currently in beta for an additional cost, the system addresses the limitations of generic blocking and rate limiting. ## Custom Protection for Proprietary UDP - Existing Cloudflare protections understand established protocols such as TCP, DNS, NTP, RDP, and SIP. - Proprietary UDP protocols are harder to protect because Cloudflare cannot interpret their application-level payloads. - Customers can now define what constitutes “good” and “bad” traffic using their own protocol knowledge. - Programs can drop or challenge invalid packets before they reach the customer’s origin. ## Why Generic UDP Mitigation Falls Short - UDP is connectionless and optimized for speed, making it useful for gaming, VoIP, and streaming. - When traffic does not match a known protocol, mitigation typically falls back to: - Blocking a destination IP and port - Applying a generic rate limit - These approaches cannot distinguish legitimate packets from attack traffic, potentially causing lag or connection loss for real users. - Fixed rate limits may also be inappropriate: - A network expecting 1 Gbps may need stricter limits. - A network expecting 25 Gbps may require more permissive thresholds. ## How Programmable Flow Protection Works - Customers upload custom eBPF programs that run on every packet destined for their network. - Programs execute in userspace rather than kernel space, providing isolation and flexibility across different customers and use cases. - Execution occurs after Cloudflare’s existing DDoS protections, preserving baseline security coverage. - Like kernel-based XDP eBPF programs, these programs: - Compile to BPF bytecode - Pass safety and termination verification - Run inside a lightweight, isolated virtual machine - Cloudflare provides specialized helpers for: - Maintaining client state between packet executions - Performing cryptographic validation - Sending challenge packets to clients ## Example: Protecting a Proprietary Game Protocol - A gaming provider running on UDP port 207 could inspect its proprietary application header. - If the header contains a protocol-specific token, the customer’s eBPF program can: - Parse the packet - Extract part of the token, such as its final byte - Pass packets with the expected value - Drop packets that fail validation - This allows legitimate players’ traffic through even when attacks use randomized source addresses, ports, and payloads. Programmable Flow Protection is best suited to Magic Transit customers whose custom UDP protocols cannot be protected effectively by standard protocol-aware controls. By combining customer-specific packet logic with Cloudflare’s global network and stateful challenge mechanisms, it enables more precise mitigation than blanket blocking or generic rate limiting.

cloudflare

Introducing Custom Regions for precision data control (opens in new tab)

Cloudflare is expanding Regional Services with three new managed regions—Turkey, the UAE, and IRAP—and introducing Custom Regions. The feature lets customers define exactly where TLS termination and Layer 7 processing occur while still using Cloudflare’s global network for traffic ingestion and DDoS protection. This combines local data-sovereignty control with globally distributed security and performance. ## Global Security with Local Compliance - Traffic enters through the nearest Cloudflare data center, where Cloudflare applies global-scale Layer 3 and Layer 4 DDoS protection. - Before decryption, request metadata is inspected and traffic is routed over Cloudflare’s private backbone to a data center inside the customer’s designated region. - TLS termination and Layer 7 services—including WAF, Bot Management, and Workers—run only within that region. - After processing, traffic is re-encrypted and sent securely to the origin. - This design localizes data inspection without forcing customers to sacrifice Cloudflare’s global attack-mitigation capacity. ## Expanded Cloudflare Managed Regions - Regional Services originally supported the EU, UK, and U.S. - Cloudflare now offers 35 predefined regions. - Newly added options include: - Turkey - United Arab Emirates - IRAP, supporting Australian compliance - ISMAP, supporting Japanese compliance ## Custom Regions - Customers can define their own geographical boundaries instead of selecting only Cloudflare-managed regions. - Custom Regions support: - Individual countries - Arbitrary combinations of countries - Regions that exclude specified countries - Early-access use cases include: - Keeping AI prompts and responses within selected countries - Running country-specific promotions - Meeting government contractual requirements - Aligning regions with corporate structures such as EMEA, MENA, or APAC - Example definitions include North America, everywhere except North America, or countries where Fahrenheit is commonly used. ## How Region Enforcement Works - A region represents a set of Cloudflare data centers. - Managed regions use Cloudflare-defined membership. - Custom Regions use expressions, commonly based on the data center’s ISO country code: - `country_code == "TR"` selects Turkey. - `country_code in ["DE", "FR", "NL"]` selects Germany, France, and the Netherlands. - Negated expressions can exclude specific countries. - The same Regional Services architecture applies regardless of who defines the boundary; Custom Regions simply give the customer control over the membership rules. Custom Regions are best suited to organizations with precise sovereignty, compliance, performance, or organizational requirements. They provide fine-grained control over where sensitive traffic is decrypted and processed while preserving Cloudflare’s global network protections.

cloudflare

2025 Q4 DDoS threat report: A record-setting 31.4 Tbps attack caps a year of massive DDoS assaults (opens in new tab)

Cloudflare’s 2025 DDoS report describes a dramatic escalation in both attack frequency and scale. DDoS attacks more than doubled to 47.1 million, while botnets such as Aisuru-Kimwolf launched unprecedented HTTP floods, including a record 31.4 Tbps attack. Cloudflare concludes that autonomous, adaptive mitigation is increasingly essential as attacks grow more frequent, larger, and more sophisticated. ## Record Growth in DDoS Attacks - Cloudflare mitigated 47.1 million DDoS attacks in 2025, a 121% increase from 2024 and a 236% increase since 2023. - The network automatically mitigated an average of 5,376 attacks per hour: - 3,925 network-layer attacks - 1,451 HTTP attacks - In Q4 2025, attacks increased 31% from the previous quarter and 58% year over year. - Network-layer attacks accounted for 78% of Q4 activity. ## Network-Layer Attacks More Than Triple - Network-layer attacks rose from 11.4 million in 2024 to 34.4 million in 2025. - An 18-day campaign in Q1 generated approximately 13.5 million attacks against Cloudflare infrastructure and Magic Transit customers. - The campaign used multiple vectors, including: - SYN floods - Mirai-generated attacks - SSDP amplification - Cloudflare’s systems detected and mitigated the campaign automatically. ## The Aisuru-Kimwolf “Night Before Christmas” Campaign - Beginning December 19, 2025, the Aisuru-Kimwolf botnet attacked Cloudflare and its customers with HTTP floods exceeding 20 million requests per second. - The botnet is estimated to contain 1–4 million malware-infected devices, primarily Android TVs. - During the campaign, Cloudflare mitigated 902 hyper-volumetric attacks: - 384 packet-intensive attacks - 329 bit-intensive attacks - 189 request-intensive attacks - Average attack rates reached 3 billion packets per second, 4 Tbps, and 54 million requests per second. - Maximum observed rates reached 9 Bpps, 24 Tbps, and 205 million requests per second. ## Hyper-Volumetric Attacks Reach New Records - Hyper-volumetric attacks increased 40% in Q4 compared with Q3. - Attack sizes grew more than 700% compared with large attacks in late 2024. - One attack reached 31.4 Tbps and lasted only 35 seconds. - Other record-scale attacks reached 205 million requests per second. - Telecommunications, service providers, and carriers were the primary targets, followed by gaming and generative AI services. - Cloudflare infrastructure itself faced HTTP floods, DNS attacks, and UDP floods. ## Most-Targeted Industries and Locations - Telecommunications, service providers, and carriers became the most-attacked industry, replacing Information Technology & Services. - Gambling and casinos ranked third, while gaming ranked fourth. - Computer software and business services climbed significantly in the top-ten rankings. - China, Germany, Brazil, and the United States remained among the most-attacked locations. - Hong Kong rose 12 places to become the second most-attacked location. - The United Kingdom climbed 36 places to rank sixth. Cloudflare’s data shows that organizations should prepare for attacks that combine enormous volume with rapidly changing techniques. Automated, network-scale defenses capable of identifying and adapting to large botnets are becoming a necessity rather than an optional protection.