Origin Protection (OP)

Comprehensive Anti-DDoS Solutions for Large-Scale Networks

Origin Protection for Mission-Critical Infrastructure

Nexusguard Origin Protection is a leading-edge, purpose-built service designed to safeguard mission-critical services across large-scale networks. Tailored to meet the unique demands of environments managing hundreds of Class C networks, Origin Protection provides robust protection against evolving threats while adapting to diverse infrastructure requirements. The service offers flexible deployment options, including Nexusguard Bastions for on-premise or hybrid setups and Nexusguard Fully Managed Service for cloud-based solutions. 

How it works

Swiftly divert malicious traffic for immediate threat mitigation.

Real-time Detection and Traffic Diversion

When a malicious attack is detected, the Event Notifier App immediately delivers alerts via email, SNMP Trap, or syslog. Nexusguard then leverages the Border Gateway Protocol (BGP) to announce the route of the targeted /24 IP prefix to the internet. On-demand, traffic is seamlessly diverted to Nexusguard’s globally distributed scrubbing centers, where it undergoes rigorous cleansing. 

Advanced Threat Analytics & Mitigation

Leveraging sophisticated flow data collection and real-time analytics, the service rapidly detects and mitigates potential DDoS threats, ensuring immediate protection with minimal latency.

Traffic Scrubbing and Clean Traffic Delivery

Once the malicious traffic is filtered out, clean and legitimate traffic is securely routed back to customer networks through Generic Routing Encapsulation (GRE) tunnels, ensuring uninterrupted service and robust protection

Core Capabilities for Unmatched Network Defense

Safeguard against Volumetric Attacks

Protects CSPs and downstream customers from the largest L3-L4 DDoS attacks using best-of-breed DDoS attack mitigation techniques

Smart Mode Detection

AI-driven Smart Mode dynamically learns and adapts to traffic patterns, enabling rapid detection of cyber threats with pinpoint accuracy while minimizing false positives.

Automated Traffic Diversion

Cloud Diversion App delivers highly autonomous, fully automated traffic redirection, ensuring seamless operations and enhanced reliability — all without manual intervention.

Surgical Mitigation

Automatically removes attack traffic while ensuring the flow of legitimate traffic is uninterrupted.

Flow Data Analysis

Multi-layered detection engine meticulously analyzes traffic data, identifying anomalies and potential threats with precision.

Clean Traffic Delivery

Once scrubbed, clean traffic is securely routed back to customer networks through GRE tunnels, Direct Connect or VLAN, ensuring uninterrupted service.

Strategic Advantages for 24/7 Uptime

End-to-end Defense

Delivers comprehensive protection for IPv4 / 6 network address blocks
Delivers comprehensive protection for IPv4 / 6 network address blocks

Individual IP Protection

Provides individual IP address protection for mission-critical online services
Provides individual IP address protection for mission-critical online services

Uninterrupted Service

Enhances end-user confidence and trust
Enhances end-user confidence and trust
We want to make the network environment for our customer as safe as they feel at home. Nexusguard offers a customized internet security solution so that our customers can continue to interact with us the way supposed to be and the way they want to—all the way without interruption.
We chose to partner with Nexusguard because of its specialty in DDoS mitigation. In fact, they not only focus on DDoS attacks, they are also curious about and strive to address the pain points they face.
Our customers are extremely satisfied with Nexusguard DDoS Protection solutions because they have sophisticated tools that give them visibility into their networks. With Netpluz mitigation facility commissioned in Singapore, powered by Nexusguard, our customers can expect proactive and intelligent mitigations to ensure only clean traffic reaches their network.
The Nexusguard solution secures our network with enterprise-grade SLAs. Most importantly, it ensures all business-essential applications have the uptime that they require.
When we have queries and new service requests, the Nexusguard team were able to attend to us promptly. This is a good partnership that every business would want to ensure our business plans are implemented smoothly.

FAQs

If my network already has a firewall, do I still need DDoS protection?

Yes, DDoS protection is essential even if you have a firewall, as firewalls are not designed to mitigate the large-scale and sophisticated attacks characteristic of DDoS incidents.

How does your service impact network performance?

Our DDoS protection solution is designed to minimize any impact on legitimate traffic, ensuring that your network performance remains optimal during mitigation.

What support options are available for customers?

We offer 24/7 customer support to assist with any inquiries, monitoring, and mitigation efforts, ensuring that your business remains protected at all times.

How does your service differentiate from competitors?

Our service offers advanced mitigation techniques, real-time threat intelligence, and 24/7 support to ensure maximum protection against evolving DDoS threats.

How do you charge for your DDoS protection services?

Nexusguard prices network-level DDoS protection based on the size of the protected network, the required protection intensity at Layers 3 to 4, and any additional services needed. Contact us for customized plans that address your network's protection needs and budget.

DDoS Protection

Anti-Flooding Protection

A robust set of rules designed to counter flood attacks, including IP, TCP, UDP, ICMP, SSL/TLS, and SIP floods. These attacks overwhelm systems by flooding them with excessive requests, depleting resources and blocking legitimate traffic. Anti-flooding ensures systems remain responsive and operational.

Flexible Detection Modes

Normal Mode

Continuously monitors traffic, offering advanced warnings and triggering responses if thresholds are exceeded within a set timeframe.

Rapid Mode

Focuses on bursty traffic and hit-and-run attacks, enabling quick threat detection through active traffic monitoring.

Smart Mode

Uses Nexusguard’s AI-driven Deep Learning system for dynamic traffic profiles, ensuring precise detection and minimizing false positives.

Baselining

Smart Baselining

Leveraging advanced deep learning, Smart Baselining continuously analyzes network traffic to establish accurate baseline thresholds. This intelligent approach minimizes false alarms, enhances the speed of anomaly detection, and enables rapid threat mitigation.

Flexible Connectivity (GRE/ DC/ VLAN)

GRE/ DC/ VLAN

Origin Protection supports Direct Connect as an alternative for returning clean traffic directly from Nexusguard’s scrubbing centers to customer networks. CSPs with data centers in the vicinity of Nexusguard’s PoPs or shared facilities can establish a direct physical connection for enhanced performance. Direct Connect is not limited to nearby IDCs; it can also be extended via Virtual Private Connect (VPC) service providers, offering flexible connectivity options.

Traffic Diversion

Cloud Diversion (Off-Net)

Nexusguard’s Origin Protection module includes a Cloud Diversion feature, which seamlessly redirects customer traffic within minutes when it surpasses a predefined bandwidth threshold. This automated process requires no on-premise appliances or customer intervention, ensuring a smooth and hassle-free experience.

Enhanced Cloud Diversion (On-Net)

On-Net integrates a Cloud Diversion agent into the customer’s routing domain, enabling communication and routing information sharing with the customer router within the same ASN. Customers have full control, including the ability to withdraw the /24 network, ensuring flexibility in routing management. This speeds up decision-making and reduces mitigation time.

During peacetime, the customer router announces routes directly to the internet. During an attack, routes are announced to the Nexusguard Cloud using the “attack” BGP community, triggering immediate mitigation.

BGP Flow Spec

Traditional methods like Remotely-Triggered Black Hole (RTBH) use BGP to drop all traffic to an under-attack server, including legitimate traffic. BGP Flow Specification (FlowSpec) offers a more precise alternative, enabling rapid deployment of filtering and policing across BGP peer routers to mitigate DDoS attacks without completely blocking access.

Nexusguard employs FlowSpec to match specific flows based on source, destination, L4 parameters, and packet data (e.g., length, fragment). It dynamically installs actions at border routers to:

  • Drop traffic matching the flow,
  • Redirect traffic to a VRF (Virtual Route Forwarding) for analysis, or
  • Police traffic at a defined rate.

Customer Portal

Service Dashboard

Designed to provide complete visibility and control, the Customer Portal is a powerful, user-friendly platform for managing security and performance. Featuring an integrated dashboard and detailed analytics, it enables customers to view and configure detection and mitigation settings tailored to their specific service plans. From monitoring real-time traffic — including raw and clean bandwidth — to tracking network performance metrics like cached bandwidth and request volumes, the portal offers a comprehensive overview of their digital environment.

Customers can stay ahead of threats by viewing ongoing and stopped DDoS attacks, analyzing potential risks, and exploring detailed insights such as visitor geography, source IPs, connection speeds, and more. The portal also provides access to detailed event logs, downloadable raw logs, and monthly reports for deeper analysis.

Resources

Datasheet

Nexusguard Origin Protection Datasheet

Whitepaper

View All
August 18, 2024

Comprehensive Anti-DDoS Solutions for Large-Scale Networks

We delve into the comprehensive features and capabilities offered by Nexusguard's Origin Protection service, tailored to meet the requirements of large-scale environments managing extensive networks.

April 20, 2020

The Pros & Cons of Self-administered BGP Diversion

Evaluate the different route diversion options and their impact and highlight the different facets one should consider before deciding whose hands to entrust their keys to.

Looking for Simpler DDoS Protection?

Contact us today to learn more about how Nexusguard can help