Skip to main content
8 min read

How we stopped over 150,000 DDoS attacks in one year

Dries Degreef

Dries Degreef

Author

Learn how RoyaleHosting mitigated over 150,000 DDoS attacks in 12 months without customer downtime. Discover our multi-layered protection approach and Application Shield technology.

How we stopped over 150,000 DDoS attacks in one year

DDoS protection has always been a top priority at RoyaleHosting. We've invested heavily in infrastructure that stops attacks before they reach your servers—and it's working. Over the past 12 months, we've mitigated over 150,000 DDoS attacks without any customer downtime.

Attacks are getting bigger and more frequent

As RoyaleHosting grew, we expanded network capacity and improved infrastructure to support more customers. With that growth came more attacks—both in volume and sophistication. DDoS attacks are becoming larger and more complex, requiring stronger defenses.

DDoS Attacks
DDoS Attacks

Multi-layered protection approach

In August 2021, we rebuilt our infrastructure and DDoS mitigation strategy from the ground up. We integrated Corero as our primary protection layer for high-capacity volumetric attacks that reach multiple terabits per second. But no single protection layer is perfect—some attacks can bypass general defenses and still impact applications.

That's why we built Application Shield, our second protection layer that stops attacks Corero can't catch.

Application Shield: stopping sophisticated attacks

Application Shield is our custom-built DDoS protection layer integrated directly into our network infrastructure. It protects against sophisticated attacks targeting specific applications—game servers, VPN servers, web applications, and more. When attacks bypass other protection layers, Application Shield stops them before they harm your applications.

Application Shield traffic
Application Shield traffic

Screenshot of the Application Shield dropping DDoS traffic.

Performance matters. Application Shield uses advanced filtering techniques that are CPU-intensive, so we offload as much processing as possible to server NICs. We use Mellanox ConnectX-4/Netronome NICs to handle filtering, minimizing CPU and memory impact. This approach improves performance for customers and enables us to filter attacks that would have been impossible before.

CPU Usage
CPU Usage

Screenshot of CPU usage on the Application Shield servers during an attack.

Shield panel: control your firewall

We believe you should have full control and visibility over your infrastructure. That's why we built Shield panel—an intuitive interface that lets you manage your network firewall without contacting support. See what's happening, adjust rules, and respond to threats instantly.

Shield panel interface
Shield panel interface

Screenshot of a beta version of the firewall panel.

Why application-layer protection matters

Many hosting providers offer volumetric DDoS mitigation, but application-based attacks require different defenses. With RoyaleHosting's multi-layered protection, your servers and applications stay online—no matter what. Our team can help build custom DDoS protection tailored to your needs. Contact our team to learn more.