Network Protection (NP)

Ensure Zero Degradation in Network Quality of CSP Infrastructures

Protect Network Quality and Eliminate Attack-Induced Congestion

Nexusguard Network Protection is a purpose-built solution designed to strengthen the local network infrastructure of CSP partners. By proactively mitigating malicious attack traffic that targets network availability, this specialized service minimizes congestion and ensures secure, uninterrupted operations. The result is enhanced resilience and reliability for partner networks, safeguarding critical connectivity even under attack.

How it works

Effective Network Protection begins with deploying an on-premise Bastions server — a critical component in defending CSP networks against malicious attacks. This solution's effectiveness hinges on maintaining sufficient Internet bandwidth across the CSP's backbone infrastructure, ensuring uninterrupted service continuity.  With this foundation, the Bastions server can activate immediate protection during an attack while maintaining seamless Clean Pipe service delivery without disruption.

Together, Clean Pipe and Network Protection form a layered defense mechanism, delivering comprehensive protection against diverse threats. Clean Pipe caters to the security needs of downstream customers, while Network Protection ensures CSP operational resilience and uninterrupted service delivery. This integrated security approach not only meets critical business requirements but also solves complex infrastructure challenges, delivering scalable protection tailored to today's threat environment.

Core Capabilities for Protecting Network Integrity

Safeguard Against Volumetric Attacks

Protects partner CSPs’ local infrastructure from the largest L3-L4 DDoS attacks

Robust and Efficient Mitigation

Automatically removes attack traffic while ensuring the flow of legitimate traffic is unimpeded

Multi-layered Defense

Advanced multi-layered detection engine that identifies traffic anomalies through deep data analysis

Proven Proprietary Technologies

Leverages Nexusguard detection and mitigation technologies, eg. NetShield to pinpoint and nullify malicious patterns

Secure Clean Traffic Delivery

Following scrubbing, clean traffic is routed back to partner CSP networks via local routing through Nexusguard Bastions servers

Operational Gains from Uninterrupted Network Performance

Maximized Network Availability

Prevents congestion to CSP backbones from volumetric attacks
 
Prevents congestion to CSP backbones from volumetric attacks
 

Network Quality Assurance

Ensures network quality remains uncompromised within CSP backbone
Ensures network quality remains uncompromised within CSP backbone

Cost-Efficient Operation

Reduces switchovers to cloud protection, lowering operating costs
Reduces switchovers to cloud protection, lowering operating costs

Comprehensive IP Protection

Secures all registered IP prefixes effectively
Secures all registered IP prefixes effectively

Auto-Mitigation Support

Backed by an in-house Security Operations Centre for seamless auto-mitigation offload
Backed by an in-house Security Operations Centre for seamless auto-mitigation offload
We want to make the network environment for our customer as safe as they feel at home. Nexusguard offers a customized internet security solution so that our customers can continue to interact with us the way supposed to be and the way they want to—all the way without interruption.
We chose to partner with Nexusguard because of its specialty in DDoS mitigation. In fact, they not only focus on DDoS attacks, they are also curious about and strive to address the pain points they face.
Our customers are extremely satisfied with Nexusguard DDoS Protection solutions because they have sophisticated tools that give them visibility into their networks. With Netpluz mitigation facility commissioned in Singapore, powered by Nexusguard, our customers can expect proactive and intelligent mitigations to ensure only clean traffic reaches their network.
The Nexusguard solution secures our network with enterprise-grade SLAs. Most importantly, it ensures all business-essential applications have the uptime that they require.
When we have queries and new service requests, the Nexusguard team were able to attend to us promptly. This is a good partnership that every business would want to ensure our business plans are implemented smoothly.

DDoS Protection

Anti-Flooding Protection

A robust set of rules designed to counter flood attacks, including IP, TCP, UDP, ICMP, SSL/TLS, and SIP floods. These attacks overwhelm systems by flooding them with excessive requests, depleting resources and blocking legitimate traffic. Anti-flooding ensures systems remain responsive and operational.

NTIF (Network Threat Intelligence Feed)

Powered by a dynamic IP reputation database, NTIF policies block threats based on the historical behavior and risk profiles of malicious IP addresses. This intelligence-driven approach proactively prevents attacks before they can disrupt operations or compromise security.

Flex Filter

A highly customizable tool that defines mitigation policies tailored to customer network traffic patterns and security needs. Flex Filter goes beyond standard anti-flood measures by offering enhanced metrics and comprehensive data visualization.

Traffic Policing

This technique sets traffic thresholds post-mitigation, ensuring controlled data flow before sending it to other systems or networks. Acting as a safeguard, it prevents network congestion and minimizes disruptions across shared network resources.

SMART Filter

SmartFilter is a cutting-edge mitigation tool within NetShield, powered by Nexusguard’s Smart Detection mode. It automatically generates and adapts mitigation rules in real-time, dynamically responding to evolving attack strategies to ensure optimal protection.

At its core, SmartFilter employs a smart feedback mechanism, which continuously monitors traffic against a clean traffic level baseline, applying mitigation actions when deviations occur. During attacks, it self-adjusts — dropping malicious traffic or allowing legitimate traffic to flow — ensuring optimal performance and robust security at all times.


Flexible Detection Modes

Normal Mode

Continuously monitors traffic, offering advanced warnings and triggering responses if thresholds are exceeded within a set timeframe.

Rapid Mode

Focuses on bursty traffic and hit-and-run attacks, enabling quick threat detection through active traffic monitoring.

Smart Mode

Uses Nexusguard’s AI-driven Deep Learning system for dynamic traffic profiles, ensuring precise detection and minimizing false positives.

Baselining

Smart Baselining

Leveraging advanced deep learning, Smart Baselining continuously analyzes network traffic to establish accurate baseline thresholds. This intelligent approach minimizes false alarms, enhances the speed of anomaly detection, and enables rapid threat mitigation.

Clean Traffic Delivery

Local route integration

Once scrubbing is complete, clean traffic is redirected back to partner CSP networks through local routing, facilitated by Nexusguard Bastion servers.

Looking for Simpler DDoS Protection?

Protect your critical infrastructure effortlessly with Nexusguard’s reliable and easy-to-manage DDoS protection. Speak with one of our network security experts to learn how we can simplify your security operations and give you peace of mind.