Incapsula DDoS Protection

  • Powerful backbone across globally distributed data centers
  • Layer 3 & 4 DDoS protection (e.g. UDP/ SYN Floods)
  • Layer 7 DDoS protection (e.g. Slowloris)
  • Support for unicast, anycast or hybrid modes
  • Stops any attack: from recurring hit-and-run DDoS to large botnet threats and complex exploits
  • “Always On”: auto-triggering of “under attack” mode
  • Transparent mitigation with less than 0.1% false positives
  • Instant activation of protection
  • Identification and differentiation between humans, good bots, bad bots, AJAX and APIs
  • Dedicated 24x7 support & security team

Solution Architecture

Incapsula's DDoS Protection Services: Solution Architecture
Core Features

Comprehensive DDoS Protection

Incapsula protects your website against all types of DDoS threats, including network-based attacks, like Sloworis, ICMP or TCP & UDP floods, and application layer attacks, such as GET flood, that attempt to overwhelm server resources. The service detects and mitigates advanced attacks that exploit application and Web server vulnerabilities, hit-and-run DDoS events and large botnet

Comprehensive DDoS Protection
High-Capacity Network to Handle Massive DDoS Attacks

High-Capacity Network

As the size of network DDoS attacks, such as SYN flood and DNS amplifications, continue to grow, organizations require robust network capacity to mitigate any threat that might come its way. Incapsula's CDN offers high capacity to thwart multi-gigabit DDoS attacks.

Transparent DDoS Mitigation

Incapsula protects your site not only from complete denial of service, but also from disruptions related to DDoS attacks, mitigation false-positives, etc. We offer transparent mitigation with less than 1% false positives, and without degrading the normal user experience in any way. This lets you enjoy true DDoS protection, even from lengthy attacks, without disrupting business performance.

Transparent DDoS Mitigation
Automatic DDoS Protection

Automatic Detection and Activation

Incapsula offers automatic always-on DDoS protection, well-equipped to handle Hit and Run DDoS event, consisting of short bursts of traffic in random intervals over a long period of time. This type of attack can wreak havoc with DDoS protection solutions that need to be manually activated on every burst.

Automatic detection and activation enables Incapsula’s DDoS protection to take full responsibility for both detection and mitigation of all attacks.

Real-Time Control

Incapsula's Real-Time view supports the mitigation process by providing accurate visibility into Layer 7 traffic. Through Incapsula's dashboards you can monitor Layer 7 DDoS attacks in real time, analyze the malicious traffic flow and adjust your security measures, while also benefiting from live and accurate feedback on every action taken.

By providing accessible and actionable live information, Incapsula's Real-Time view serves as an important security tool which enables data-driven response to DDoS threats and any other unwanted scenarios.

Real-Time Control and Visibility

Blocking Any Type of Attack

Incapsula's DDoS Protection Service can detect and block the following DDoS attacks. Note that Incapsula proxies web requests, so any network layer DDoS attacks are never relayed to the client's origin servers. Therefore, Incapsula's DDoS protection will mitigate all network level attacks.

  • TCP SYN+ACK
  • TCP FIN
  • TCP RESET
  • TCP ACK
  • TCP ACK+PSH
  • TCP Fragment
  • UDP
  • Slowloris
  • Spoofing
  • ICMP
  • IGMP
  • HTTP Flood
  • Brute Force
  • Connection Flood
  • DNS Flood
  • Mixed SYN + UDP or ICMP + UDP Flood
  • Ping of Death
  • Smurf
  • Reflected ICMP & UDP
Core Benefits

Fast and Easy Onboarding

DDoS Protection can be rolled out without the need for any additional hardware or software. Customers can provision this service simply by changing their website's DNS setting. This enables effortless and near-instant deployment, while also allowing our clients maintaining their existing hosting and application infrastructures.

Cost-Effective DDoS Protection

Incapsula's cloud-based service offers 24x7 protection against all DDoS attacks without the need for multi-gigabit Internet connections or any additional hardware. Using Incapsula eliminates the setup and overhead costs associated with over-provisioning and deployment of additional on-premise appliances.

Collaborative Security

Incapsula protects websites using collective knowledge about security threats, including new and emerging DDoS attack methods. Using crowdsourcing techniques, new security information is aggregated across the entire network and new mitigation rules are applied in real-time, across all protected websites.

World-Class 24x7 Support

Incapsula's managed DDoS protection services are supported by a dedicated team of experienced SOC (Security Operations Center) engineers. Their responsibilities include: proactive response and event management, continuous real-time monitoring, adept policy tuning, summary attack reports and 24x7 support.