
Clean Pipe (CP)
Deliver Uninterrupted Connectivity with Rapid Attack Mitigation

How it works

The Clean Pipe service is designed to maximize the efficiency of the subscribed internet access by eliminating the burden of superfluous traffic. By adeptly filtering out malicious traffic, it ensures uninterrupted network availability and optimal resource utilization, enabling smooth operations.
Employing advanced flow data collection and analysis, the service quickly identifies potential DDoS threats, allowing for rapid response. Traffic from targeted IP prefixes is then redirected to a local scrubbing engine via local routing.
Once malicious traffic is removed, the Clean Pipe service seamlessly routes clean traffic back through the ISP’s local routing. This ensures downstream clients enjoy fast, reliable connectivity, free from disruptions caused by malicious traffic, and can focus on their online activities with confidence.
Essential Capabilities for Localized DDoS Mitigation

Safeguard against Volumetric Attacks
Protects CSPs and downstream customers from the largest L3-L4 DDoS attacks using best-in-class DDoS attack mitigation techniques

Surgical Mitigation
Automatically removes only attack traffic while ensuring the flow of legitimate traffic is uninterrupted

Flow Data Analysis
Multi-layered detection engine meticulously analyzes traffic data, identifying anomalies and potential threats with precision

Secure Clean Traffic Delivery
After neutralizing threats, clean traffic is routed back to client networks through ISP local routing, ensuring uninterrupted access to their online assets
Benefits of Clean Pipe

Real-Time Protection

Consistent Uptime

Cost-effective Security

Continuous Availability

Optimized Mitigation

FAQs
Yes, we offer franchise options for CSPs and SIs looking to deliver enterprise-grade DDoS protection services to their customers. Contact us to explore partnership possibilities.
Features
DDoS Protection
A robust set of rules designed to counter flood attacks, including IP, TCP, UDP, ICMP, SSL/TLS, and SIP floods. These attacks overwhelm systems by flooding them with excessive requests, depleting resources and blocking legitimate traffic. Anti-flooding ensures systems remain responsive and operational.
Powered by a dynamic IP reputation database, NTIF policies block threats based on the historical behavior and risk profiles of malicious IP addresses. This intelligence-driven approach proactively prevents attacks before they can disrupt operations or compromise security.
A highly customizable tool that defines mitigation policies tailored to customer network traffic patterns and security needs. Flex Filter goes beyond standard anti-flood measures by offering enhanced metrics and comprehensive data visualization.
This technique sets traffic thresholds post-mitigation, ensuring controlled data flow before sending it to other systems or networks. Acting as a safeguard, it prevents network congestion and minimizes disruptions across shared network resources.
SmartFilter is a cutting-edge mitigation tool within NetShield, powered by Nexusguard’s Smart Detection mode. It automatically generates and adapts mitigation rules in real-time, dynamically responding to evolving attack strategies to ensure optimal protection.
At its core, SmartFilter employs a smart feedback mechanism, which continuously monitors traffic against a clean traffic level baseline, applying mitigation actions when deviations occur. During attacks, it self-adjusts — dropping malicious traffic or allowing legitimate traffic to flow — ensuring optimal performance and robust security at all times.
Flexible Detection Modes
Continuously monitors traffic, offering advanced warnings and triggering responses if thresholds are exceeded within a set timeframe.
Focuses on bursty traffic and hit-and-run attacks, enabling quick threat detection through active traffic monitoring.
Uses Nexusguard’s AI-driven Deep Learning system for dynamic traffic profiles, ensuring precise detection and minimizing false positives.
Baselining
Leveraging advanced deep learning, Smart Baselining continuously analyzes network traffic to establish accurate baseline thresholds. This intelligent approach minimizes false alarms, enhances the speed of anomaly detection, and enables rapid threat mitigation.
Traffic Diversion
Traditional methods like Remotely-Triggered Black Hole (RTBH) use BGP to drop all traffic to an under-attack server, including legitimate traffic. BGP Flow Specification (FlowSpec) offers a more precise alternative, enabling rapid deployment of filtering and policing across BGP peer routers to mitigate DDoS attacks without completely blocking access.
Nexusguard employs FlowSpec to match specific flows based on source, destination, L4 parameters, and packet data (e.g., length, fragment). It dynamically installs actions at border routers to:
- Drop traffic matching the flow,
- Redirect traffic to a VRF (Virtual Route Forwarding) for analysis, or
- Police traffic at a defined rate.
Customer Portal
Designed to provide complete visibility and control, the Customer Portal is a powerful, user-friendly platform for managing security and performance. Featuring an integrated dashboard and detailed analytics, it enables customers to view and configure detection and mitigation settings tailored to their specific service plans. From monitoring real-time traffic — including raw and clean bandwidth — to tracking network performance metrics like cached bandwidth and request volumes, the portal offers a comprehensive overview of their digital environment.
Customers can stay ahead of threats by viewing ongoing and stopped DDoS attacks, analyzing potential risks, and exploring detailed insights such as visitor geography, source IPs, connection speeds, and more. The portal also provides access to detailed event logs, downloadable raw logs, and monthly reports for deeper analysis.
Resources
Datasheet
Nexusguard Clean Pipe Datasheet
Whitepaper
View AllSecuring Network Resilience: Safeguarding ISP Downstream Clients with Clean Pipe Protection
We will look into the attributes and benefits provided by Clean Pipe, designed to safeguard both IPv4 and IPv6 network addresses of ISP’s direct connect downstream clients against volumetric and protocol-based DDoS attacks, such as UDP, ICMP and SYN floods.
Blog
View AllLooking for Simpler DDoS Protection?
