DDoS Protection

Traffic protection built to
keep services reachable.

Hostigan combines always-on mitigation, real-time traffic analysis, and layered filtering to help separate legitimate connections from hostile traffic.

MITIGATION PROFILE
Hostigan infrastructureMulti-layer traffic filtering
Designed for resilience
Operational profile
24/7Always-on monitoring
L3/4/7Protection layers
XDPeBPF-based analysis
Infrastructure principles

Protection that works across the traffic path.

Filtering begins at the network edge and continues through specialized mitigation systems designed for different attack patterns.

Continuous detection

Connections are monitored in real time so suspicious traffic can be identified quickly.

Intelligent filtering

Multiple filtering stages help distinguish real users and applications from attack traffic.

Application-aware controls

Specialized filters support protocols and workloads that need more than generic packet filtering.

Flexible mitigation

Baseline protection is complemented by stronger inline options for larger or more complex projects.

How it is built

A layered path from routers to application-aware filters.

The published Hostigan approach combines router-level screening, XDP/eBPF filtering, redundant mitigation systems, and reverse-proxy assistance for selected protocols.

Network-layer mitigation

High-volume hostile traffic is screened before it can consume the resources behind a hosted service.

  • Router-level traffic screening
  • Redundant filtering systems
  • Symmetric traffic analysis

Workload-aware filtering

Protocol-specific controls are available for game traffic and common remote-access services.

  • Game and query-aware filters
  • Connection authentication controls
  • Support-assisted custom mitigation
Global threat surface

Attacks arrive from everywhere.
They stop in Europe.

Hostile traffic does not respect borders — floods come from compromised hosts on every continent. Each one is drawn toward your service and absorbed at our Frankfurt and Amsterdam scrubbing centres, so what reaches your server is what you actually wanted.

Drag to rotate
30 TbpsScrubbing capacity
2EU scrubbing centres
1,284Attacks blocked · 30 days
  • Web protectionHTTP and HTTPS floods filtered before they reach your site or its database.
  • Network protectionVolumetric and protocol attacks scrubbed at the edge, at line rate.
  • Game protectionGame-aware UDP filtering that drops the flood without dropping your players.
Scrubbing network

Attacks stopped
before they reach you.

Hostile traffic is scrubbed at the network edge, in the same European facilities your server already runs in. Nothing to enable, nothing to pay extra for, and no traffic detour through another continent to get filtered.

30 TbpsScrubbing capacity
2Scrubbing centres
99.99%Network uptime SLA
< 10sMitigation onset
FrankfurtGermany · DE-CIX
Active
30 TbpsMitigation capacity
< 3 msAverage latency
  • Hardware-accelerated scrubbing at line rate
  • BGP blackhole and selective null-routing
  • Tier-1 transit with multi-upstream redundancy
  • Custom eBPF / XDP filters per workload

What gets filtered.

Volumetric floodsUDP and ICMP floods that try to saturate the link before anything else can get through.
Protocol attacksSYN, ACK and fragmentation floods aimed at exhausting connection state rather than bandwidth.
AmplificationDNS, NTP, memcached and SSDP reflection, where a small request returns a very large answer.
Application layerHTTP floods and slow-request attacks that look like real visitors until you count them.
Included, never upsold

Protection is not an add-on here.

Plenty of providers quote a low base price and put mitigation behind an enterprise tier. Every Hostigan server ships with the full scrubbing capacity from the first day, whether it is a web hosting plan or a dual-socket dedicated machine.

  • Enabled by default on every plan
  • No per-attack or per-gigabit surcharge
  • Same capacity on the cheapest plan as the largest
  • Engineers on call around the clock
Why it ships by default

Built for the ones who
can't afford to go dark.

Most providers quote a tempting base price and then put mitigation behind an enterprise tier — so the moment you actually need it is the moment you get an invoice. We take the opposite view: an attack is not an upsell opportunity. The same scrubbing capacity that keeps a game server standing through a hostile night protects the cheapest web hosting plan we sell, from the day it is provisioned.

How it compares

What "DDoS protection included" usually means.

Providers use the same phrase for very different things. This is how our mitigation lines up against the two packaging models you will meet most often.

DDoS mitigation features compared across Hostigan, budget hosts and paid add-on tiers
CapabilityHostiganTypical budget hostSold as a paid add-on
Always-on filteringIncludedPartial or limitedIncluded
Included in every planIncludedNot availableNot available
L3 / L4 protectionIncludedPartial or limitedIncluded
L7 / application layerIncludedNot availablePartial or limited
High packet-rate handlingIncludedNot availablePartial or limited
Mitigation within secondsIncludedPartial or limitedPartial or limited
Multiple scrubbing centresIncludedNot availableIncluded
Custom eBPF / XDP filtersIncludedNot availablePartial or limited
Tier-1 transit backboneIncludedNot availableIncluded
Multi-upstream redundancyIncludedNot availablePartial or limited
No per-attack surchargeIncludedPartial or limitedNot available
  • Included
  • Partial or limited
  • Not available
Custom configurations

Need something we don't list?

Larger disks, a different CPU, more RAM, a specific storage layout — almost anything is possible. Tell us what the workload actually needs and we will prepare an individual offer.

Tell us the workload and budget — most quotes come back within one business day.
  • Larger or additional disksExtra NVMe capacity and custom RAID layouts.
  • A different processorHigher clock speeds or a specific core count.
  • More memoryAdditional RAM, including ECC on request.
  • Network & IP requirementsFaster uplinks, extra IPv4 ranges, private VLANs.