← Back to Labs

DDoS Mitigation Lab

Run a reflection flood, a SYN flood, or an HTTP work flood through anycast, stateless filters, scrubbing, origin shielding, and route-level admission control.

Attack profilePick the shape of the flood before you step through the defence
Current vector
DNS reflection flood
High bandwidth and high packet rate attack. The link and first packet-processing layers are the likely bottlenecks.
Attack sources435 Gbps attack40.8 Mpps packet loadDNS reflection floodAnycast edge1 ingress site441 Gbpssingle edge carries all trafficStateless gateACLs, cookies, Retrydropped so far 0%435 Gbps attack remainsScrubbing pathclassify, drop, tunnel441 Gbps clean path budgetstandby until diversionShielded originbypass still possible441 Gbps vs safe 12.0 GbpsoverloadedpktYou cannot fix the right layer until you know whether the bottleneck is bits, packets, state, or work.single public edge carries 441 Gbps
Attack entering the edge
435 Gbps attack + 5.8 Gbps legitimate
40.8 Mpps malicious packet load
Traffic removed so far
0% of the attack
0.0 Gbps discarded before the next expensive layer
Next expensive layer
441 Gbps
safe budget 12.0 Gbps · status overloaded
Origin access posture
origin still exposed to bypass risk
a direct path can skip the outer defences
Step 1 / 6Name the budget that is failing first

A DDoS attack is not just “too much traffic”. One flood can kill the public link, another can exhaust handshake state, and another can burn origin CPU on expensive routes.

Arrow keys to navigate · R to reset

Tap dots to jump to any step

Read the full article →Take the quiz →