Clean Pipe (CP)

Maximize Service Availability to Internet Access Clients

Deliver Uninterrupted Connectivity with Rapid Attack Mitigation

The Clean Pipe service is designed for downstream clients directly connected to ISPs in partnership with Nexusguard, leveraging the advanced capabilities of Nexusguard Bastions. These clients prioritize seamless and secure connectivity, relying on the ISP’s internet access to reach their critical network assets. By subscribing to the Clean Pipe service, they gain an additional layer of security, effectively mitigating network congestion caused by the disruptive impact of volumetric DDoS attacks, ensuring uninterrupted operations and enhanced protection for their network infrastructure.

How it works

Maximizing Efficiency and Ensuring Uninterrupted Operations

The Clean Pipe service is designed to maximize the efficiency of the subscribed internet access by eliminating the burden of superfluous traffic. By adeptly filtering out malicious traffic, it ensures uninterrupted network availability and optimal resource utilization, enabling smooth operations.

Advanced Threat Detection and Local Scrubbing

Employing advanced flow data collection and analysis, the service quickly identifies potential DDoS threats, allowing for rapid response. Traffic from targeted IP prefixes is then redirected to a local scrubbing engine via local routing.

Seamless Clean Traffic Routing 

Once malicious traffic is removed, the Clean Pipe service seamlessly routes clean traffic back through the ISP’s local routing. This ensures downstream clients enjoy fast, reliable connectivity, free from disruptions caused by malicious traffic, and can focus on their online activities with confidence.

Essential Capabilities for Localized DDoS Mitigation

Safeguard against Volumetric Attacks

Protects CSPs and downstream customers from the largest L3-L4 DDoS attacks using best-in-class DDoS attack mitigation techniques

Surgical Mitigation

Automatically removes only attack traffic while ensuring the flow of legitimate traffic is uninterrupted

Flow Data Analysis

Multi-layered detection engine meticulously analyzes traffic data, identifying anomalies and potential threats with precision

Secure Clean Traffic Delivery

After neutralizing threats, clean traffic is routed back to client networks through ISP local routing, ensuring uninterrupted access to their online assets

Benefits of Clean Pipe

Real-Time Protection

Shields against DDoS attacks in real-time
Shields against DDoS attacks in real-time

Consistent Uptime

Ensures high availability and 24/7 connectivity
Ensures high availability and 24/7 connectivity

Cost-effective Security

Manages security costs efficiently with live network insights
Manages security costs efficiently with live network insights

Continuous Availability

Provides superior end-user satisfaction
Provides superior end-user satisfaction

Optimized Mitigation

Mitigates risks effectively through optimized strategies
Mitigates risks effectively through optimized strategies
We want to make the network environment for our customer as safe as they feel at home. Nexusguard offers a customized internet security solution so that our customers can continue to interact with us the way supposed to be and the way they want to—all the way without interruption.
We chose to partner with Nexusguard because of its specialty in DDoS mitigation. In fact, they not only focus on DDoS attacks, they are also curious about and strive to address the pain points they face.
Our customers are extremely satisfied with Nexusguard DDoS Protection solutions because they have sophisticated tools that give them visibility into their networks. With Netpluz mitigation facility commissioned in Singapore, powered by Nexusguard, our customers can expect proactive and intelligent mitigations to ensure only clean traffic reaches their network.
The Nexusguard solution secures our network with enterprise-grade SLAs. Most importantly, it ensures all business-essential applications have the uptime that they require.
When we have queries and new service requests, the Nexusguard team were able to attend to us promptly. This is a good partnership that every business would want to ensure our business plans are implemented smoothly.

FAQs

If I am a CSP or SI, do you provide a franchise option for offering DDoS protection services?

Yes, we offer franchise options for CSPs and SIs looking to deliver enterprise-grade DDoS protection services to their customers. Contact us to explore partnership possibilities.

DDoS Protection

Anti-Flooding Protection

A robust set of rules designed to counter flood attacks, including IP, TCP, UDP, ICMP, SSL/TLS, and SIP floods. These attacks overwhelm systems by flooding them with excessive requests, depleting resources and blocking legitimate traffic. Anti-flooding ensures systems remain responsive and operational.

NTIF (Network Threat Intelligence Feed)

Powered by a dynamic IP reputation database, NTIF policies block threats based on the historical behavior and risk profiles of malicious IP addresses. This intelligence-driven approach proactively prevents attacks before they can disrupt operations or compromise security.

Flex Filter

A highly customizable tool that defines mitigation policies tailored to customer network traffic patterns and security needs. Flex Filter goes beyond standard anti-flood measures by offering enhanced metrics and comprehensive data visualization.

Traffic Policing

This technique sets traffic thresholds post-mitigation, ensuring controlled data flow before sending it to other systems or networks. Acting as a safeguard, it prevents network congestion and minimizes disruptions across shared network resources.

SMART Filter

SmartFilter is a cutting-edge mitigation tool within NetShield, powered by Nexusguard’s Smart Detection mode. It automatically generates and adapts mitigation rules in real-time, dynamically responding to evolving attack strategies to ensure optimal protection.


At its core, SmartFilter employs a smart feedback mechanism, which continuously monitors traffic against a clean traffic level baseline, applying mitigation actions when deviations occur. During attacks, it self-adjusts — dropping malicious traffic or allowing legitimate traffic to flow — ensuring optimal performance and robust security at all times.

Flexible Detection Modes

Normal Mode

Continuously monitors traffic, offering advanced warnings and triggering responses if thresholds are exceeded within a set timeframe.

Rapid Mode

Focuses on bursty traffic and hit-and-run attacks, enabling quick threat detection through active traffic monitoring.

Smart Mode

Uses Nexusguard’s AI-driven Deep Learning system for dynamic traffic profiles, ensuring precise detection and minimizing false positives.

Baselining

Smart Baselining

Leveraging advanced deep learning, Smart Baselining continuously analyzes network traffic to establish accurate baseline thresholds. This intelligent approach minimizes false alarms, enhances the speed of anomaly detection, and enables rapid threat mitigation.

Traffic Diversion

BGP Flow Spec

Traditional methods like Remotely-Triggered Black Hole (RTBH) use BGP to drop all traffic to an under-attack server, including legitimate traffic. BGP Flow Specification (FlowSpec) offers a more precise alternative, enabling rapid deployment of filtering and policing across BGP peer routers to mitigate DDoS attacks without completely blocking access.

Nexusguard employs FlowSpec to match specific flows based on source, destination, L4 parameters, and packet data (e.g., length, fragment). It dynamically installs actions at border routers to:

  • Drop traffic matching the flow,
  • Redirect traffic to a VRF (Virtual Route Forwarding) for analysis, or
  • Police traffic at a defined rate.

Customer Portal

Service Dashboard

Designed to provide complete visibility and control, the Customer Portal is a powerful, user-friendly platform for managing security and performance. Featuring an integrated dashboard and detailed analytics, it enables customers to view and configure detection and mitigation settings tailored to their specific service plans. From monitoring real-time traffic — including raw and clean bandwidth — to tracking network performance metrics like cached bandwidth and request volumes, the portal offers a comprehensive overview of their digital environment.

Customers can stay ahead of threats by viewing ongoing and stopped DDoS attacks, analyzing potential risks, and exploring detailed insights such as visitor geography, source IPs, connection speeds, and more. The portal also provides access to detailed event logs, downloadable raw logs, and monthly reports for deeper analysis.

Resources

Datasheet

Nexusguard Clean Pipe Datasheet

Whitepaper

View All
November 29, 2024

Securing Network Resilience: Safeguarding ISP Downstream Clients with Clean Pipe Protection

We will look into the attributes and benefits provided by Clean Pipe, designed to safeguard both IPv4 and IPv6 network addresses of ISP’s direct connect downstream clients against volumetric and protocol-based DDoS attacks, such as UDP, ICMP and SYN floods.

Looking for Simpler DDoS Protection?

Protect your critical infrastructure effortlessly with Nexusguard’s reliable and easy-to-manage DDoS protection. Speak with one of our network security experts to learn how we can simplify your security operations and give you peace of mind.