Incapsula’s cloud-based DDoS protection secures your website against the largest and smartest DDoS threats, including network, protocol and application level attacks.
The service automatically and transparently mitigates all DDoS attacks, causing no business disruptions.
Incapsula’s DDoS protection services are backed by a 24x7 security team and 99.999% uptime SLA.Download Incapsula DDoS Protection Overview »
Incapsula DDoS Protection
- Powerful backbone across globally distributed data centers
- Layer 3 & 4 DDoS protection (e.g. UDP/ SYN Floods)
- Support for unicast, anycast or hybrid modes
- Layer 7 (applicative) DDoS protection (e.g. Slowloris)
- Stops any attack: from recurring hit-and-run DDoS to large botnet threats and complex exploits
- “Always On”: automatic triggering of “under attack” mode
- Transparent mitigation with less than 0.1% false positives
- Instant activation of protection
- Identification and differentiation between humans, good bots, bad bots, AJAX and APIs
- Dedicated 24x7 support & security team
DDoS Protection Capabilities
Comprehensive Protection Against any Type of DDoS Attack
Incapsula protects your website against all types of DDoS threats, including network-based attacks, like Sloworis, ICMP or TCP & UDP floods, and application-level attacks, such as GET flood, that attempt to overwhelm server resources. The service detects and mitigates advanced attacks that exploit application and Web server vulnerabilities, hit-and-run DDoS events and large botnet
High-Capacity Network to Handle Massive Network Attacks
As the size of network DDoS attacks, such as SYN flood and DNS amplifications, continue to grow, organizations require robust network capacity to mitigate any threat that might come its way. Incapsula's CDN offers high capacity to thwart multi-gigabit DDoS attacks.
Transparent DDoS Protection
Incapsula protects your site not only from complete denial of service, but also from disruptions related to DDoS attacks, mitigation false-positives, etc. We offer transparent mitigation with less than 1% false positives, and without degrading the normal user experience in any way. This lets you enjoy true DDoS protection, even from lengthy attacks, without disrupting business performance.
Automatic Detection and Activation
Incapsula offers automatic always-on DDoS protection, well-equipped to handle Hit and Run DDoS event, consisting of short bursts of traffic in random intervals over a long period of time. This type of attack can wreak havoc with DDoS protection solutions that need to be manually activated on every burst.
Automatic detection and activation enables Incapsula’s DDoS protection to take full responsibility for both detection and mitigation of all attacks.
Through Incapsula’s Real-time dashboards, you can monitor attacks in real time, analyze them while they are happening, and be able to spot issues and solve them in real time.
Fast, Easy Onboarding
DDoS Protection can be rolled out without the need for hardware, software, integration or web application code changes. Customers can provision this service simply by changing their website's DNS setting. This effortless deployment allows customers to be protected in a matter of minutes while maintaining their existing hosting provider and application infrastructure.
Incapsula protects websites using collective knowledge about DDoS threats, including new and emerging attack methods. Using crowdsourcing techniques, this information is aggregated across the entire service network to identify new attacks as they happen and to detect known malicious users. Based on this information, mitigation rules can be applied in real-time across all protected websites.
Cost-Effective Cloud-Based DDoS Protection
Incapsula offers a managed cloud-based service that gives you 24x7 defense against DDoS attacks without the need for multi-gigabit Internet connections and additional hardware and operational costs. This eliminates the costs associated with over-provisioning bandwidth and deploying additional servers and load balancers on premise.
World-Class Support by DDoS and Security Experts
Incapsula's DDoS Protection service provides organizations with continuous monitoring and mitigation by our dedicated team of experienced Security Operations Center (SOC) engineers. Our service includes proactive security event management and response, continuous real-time monitoring, adept policy tuning, summary attack reports, and 24x7 support.
Blocking Any Type of Attack
Incapsula's DDoS Protection Service can detect and block the following DDoS attacks. Note that Incapsula proxies web requests, so any network layer DDoS attacks are never relayed to the client's origin servers. Therefore, Incapsula's DDoS protection will mitigate all network level attacks.
- TCP SYN+ACK
- TCP FIN
- TCP RESET
- TCP ACK
- TCP ACK+PSH
- TCP Fragment
- HTTP Flood
- Brute Flood
- Connection Flood
- DNS Flood
- Mixed SYN+UDP or ICMP+UDP Flood
- TCP SYN+ACK
- Ping Of Death
- Reflected ICMP and UDP
- Zero-day DDoS attacks
- Attacks against common web servers such as Apache and II