Incapsula's dns DDoS Protection Services

Incapsula DDoS Protection

  • Available as an always-on or on-demand service
  • Powerful network of globally positioned Data Centers
  • Application (Layer 7) and Network (Layers 3,4) DDoS protection
  • Blanket DDoS protection for all types of services (UDP/TCP, SMTP, FTP, SSH, VoIP, etc)
  • Backed by a 24x7 security team and a 99.999% uptime SLA.

Our Approach

Incapsula’s multi-faceted approach to DDoS protection leverages a suite of complementary anti-DDoS solutions that together offer blanket protection from all DDoS threats.

Each of these solutions defends a different set of critical online assets from DDoS attacks.

Incapsula Web Application Protection

Incapsula’s Web Application Protection is an always-on, cloud-based DDoS mitigation service which automatically detects and mitigates all types of DDoS attacks launched at websites and web applications.

This service is built on-top of Incapsula’s Content Delivery Network (CDN) and leverages Incapsula’s PCI DSS compliant Web Application Firewall (WAF) technology. As a result, in addition to securing your website against DDoS threats, Incapsula also guards against exploitation of application vulnerabilities and accelerates page load times by optimizing all content delivery. Read More »

Incapsula Infrastructure Protection

Enabled via GRE tunneling and leveraging Border Gateway Protocol (BGP) routing, Incapsula’s Infrastructure Protection is an on-demand security service that safeguards critical network infrastructure from volumetric and protocol-based DDoS attacks, such as UDP, SMTP or SYN Floods, executed directly or via DNS/NTP amplification.

Infrastructure Protection can be used to protect entire subnets, secure all network elements, and inspect all incoming communication. Read More »

Incapsula DNS Protection

The DNS Protection service secures client DNS servers from DNS-targeted DDoS attacks. Deployed as an always-on solution, the service automatically identifies and blocks malicious queries that target DNS servers, while also accelerating DNS responses. Read More »

Features

Comprehensive DDoS Protection

Incapsula protects applications and infrastructure against all types of DDoS threats. These include network-based attacks (e.g., Slowloris, ICMP or TCP & UDP floods) as well as application layer attacks (e.g., GET flood) that attempt to overwhelm server resources. Supporting Unicast and Anycast technologies, the service leverages a many-to-many defense methodology, automatically detecting and mitigating advanced DDoS attacks that exploit application and Web server vulnerabilities, hit-and-run DDoS events, and large botnets.

Comprehensive DDoS Protection

High-Capacity Network

As the size of network DDoS attacks, such as SYN flood and DNS amplifications, continues to grow, organizations require robust network capacity to mitigate any threat that might come their way. Incapsula's CDN offers high capacity to thwart multi-gigabit DDoS attacks.

Automatic Detection and Activation

Incapsula offers automatic always-on DDoS protection, well-equipped to handle Hit and Run DDoS events, consisting of short bursts of traffic in random intervals over a long period of time. This type of attack can wreak havoc with DDoS protection solutions that need to be manually activated on every burst.

Automatic detection and activation enables Incapsula’s DDoS protection to take full responsibility for both detection and mitigation of all attacks.

Automatic DDoS Protection
Real-Time Control and Visibility

Real-Time Control

Incapsula's Real-Time view supports the mitigation process by providing accurate visibility into Layer 7 traffic. Through Incapsula's dashboards you can monitor Layer 7 DDoS attacks in real time, analyze the malicious traffic flow and adjust your security measures, while also benefiting from live and accurate feedback on every action taken.

By providing accessible and actionable live information, Incapsula's Real-Time view serves as an important security tool which enables data-driven response to DDoS threats and any other unwanted scenarios.

Blocking Any Type of Attack

Incapsula's DDoS Protection service can detect and block the following types of DDoS attacks. Note that Incapsula proxies Web requests, so network layer DDoS attacks are never relayed to the client's origin servers. Therefore, Incapsula's DDoS protection can mitigate all network level attacks.

  • TCP SYN+ACK
  • TCP FIN
  • TCP RESET
  • TCP ACK
  • TCP ACK+PSH
  • TCP Fragment
  • UDP
  • Slowloris
  • Spoofing
  • ICMP
  • IGMP
  • HTTP Flood
  • Brute Force
  • Connection Flood
  • DNS Flood
  • NXDomain
  • Mixed SYN + UDP or ICMP + UDP Flood
  • Ping of Death
  • Smurf;
  • Reflected ICMP & UDP
  • As well as other attacks
Why Incapsula?

Fast and Easy Onboarding

DDoS Protection can be rolled out without the need for any additional hardware or software. This enables effortless and near-instant deployment, while also allowing our clients to maintain their existing hosting and application infrastructures.

Cost-Effective DDoS Protection

Incapsula's cloud-based service offers 24x7 protection against all DDoS attacks without the need for multi-gigabit Internet connections or any additional hardware. Using Incapsula eliminates the setup and overhead costs associated with over-provisioning and deployment of additional on-premise appliances.

Collaborative Security

Incapsula protects websites using collective knowledge about security threats, including new and emerging DDoS attack methods. Using crowdsourcing techniques, new security information is aggregated across the entire network and new mitigation rules are applied in real-time, across all protected websites.

World-Class 24x7 Support

Incapsula's managed DDoS protection services are supported by a dedicated team of experienced SOC (Security Operations Center) engineers. Their responsibilities include: proactive response and event management, continuous real-time monitoring, adept policy tuning, summary attack reports and 24x7 support.