Skip to content
DEFLECTO
Services

From the packet to the application.

One managed edge terminates the traffic, filters it at L3, L4 and L7, and forwards what survives to your origin. Take the parts you need, or hand us the whole edge and stop thinking about it.

Talk to an engineerAttack traffic is never metered
Attack matrix

What hits you, and what stops it.

Each vector below is answered by one named mechanism sitting at a specific layer. Follow a mechanism to the section that explains it.

SYN and UDP floods

Spoofed and malformed packets are dropped below the socket. No connection state is allocated for them, so the flood never buys itself a place in a queue.

DNS and NTP amplification

Reflected responses arrive unsolicited. Nothing at the edge asked for them, so nothing accepts them, and the volume is absorbed away from anything you own.

HTTP request floods from botnets

Every client pays CPU before it is served. A botnet's only real advantage is that requests are cheap to send, and this is what puts a price on each one.

Low and slow connection exhaustion

Concurrency, header timeouts and body read rates are capped per client. An idle socket cannot hold a worker open waiting for a request that will never finish.

Credential stuffing

Attempts are budgeted per account, per address and per session, and each attempt carries a CPU cost, so replaying a leaked password list stops being cheap.

SQL injection and payload attacks

Query strings, headers and bodies are inspected against a maintained OWASP ruleset before your application parses them. Requests are scored, not guessed at.

Vulnerability scanning

Probes for known paths score as anomalies and the budget runs out long before the scanner finishes enumerating. You get the log either way.

Direct-to-origin attacks

Your address is never published and the origin accepts connections only from our network, so an attacker who learns the IP still has nothing to connect to.

Proof of work

A suspicious request gets a bill, not a block page.

A client that looks wrong for its context is handed a computational puzzle instead of a verdict. Solving it costs CPU. A browser pays that once, in a moment nobody notices, and carries a token afterwards. A flood pays it on every single request, and that is the whole idea: volume stops being free, and the arithmetic that makes renting a botnet worthwhile stops working.

Difficulty tracks load. Quiet traffic is barely touched, pressure raises the price automatically, and nobody has to decide to switch something on while the site is already struggling. There is nothing for a person to read, click or identify, so accessibility and conversion are not the currency you pay security in.


A challenged request is never metered. Quota counts legitimate requests forwarded to your origin, so traffic that gets challenged, refused or dropped costs you nothing at all.

One visitor

Pays once, notices nothing.

A few milliseconds of CPU inside a page that is already loading, then a token that carries the rest of the session. No image grid, no puzzle to squint at, no third party sitting in the request path deciding whether your customer is a person.

One flood

Pays again on every request.

The advantage of a botnet is that a request costs almost nothing to send. Charging CPU per request removes the advantage: the attacker runs out of budget before your origin runs out of workers, and no legitimate visitor was blocked to get there.

Network layer

Nothing hostile reaches a machine you pay for.

Volumetric

Volumetric DDoS protection

SYN, UDP, ICMP and amplification floods are absorbed across the network and dropped at the edge. There is nothing for you to scale up mid-incident, because the packets never arrive at a machine you pay for.

Layers
L3 and L4
Filtering
Per packet, below the socket
Trigger
Automatic, no action from you
Protocols
TCP, UDP, ICMP, DNS, NTP
Origin

Origin cloaking

Filtering the front door achieves nothing while the back door is public. Your real address stays unpublished and the origin accepts connections only from our network, so an attacker who finds the IP still cannot open a socket to it.

Exposure
Origin address never published
Access
Allow list at the network level
Transport
GRE and IPsec tunnels
Scope
TCP and UDP, not only HTTP
Application layer

Requests are scored, not guessed at.

Above the packet, the question is no longer whether traffic is malformed. It is whether a well formed request was meant for you.

Layer 7

Managed WAF and L7 mitigation

A modern flood looks like traffic you want. A maintained OWASP ruleset, per-route rate limits and behavioural scoring separate the two, and the tuning is our work rather than a config file handed to you. Blanket blocking would cost you the customers you were trying to serve, which is the failure mode nobody reports.

  • Maintained OWASP ruleset
  • Limits per route, per address, per session
  • Anomaly scoring instead of binary blocking
  • Tuning done by our team
Delivery

Globally distributed delivery

A visitor is answered by the nearest location. A flood is split across the network instead of converging on one link, which is what makes volume survivable at all. The same distribution keeps latency low for the requests you actually wanted.

  • Anycast routing to the nearest location
  • Automatic failover between locations
  • TLS terminated at the edge
  • Optional caching for static responses
Operations

Detection is half of it. Someone still has to answer.

Monitoring

Monitoring and 24/7 response

Automation settles the ordinary case in milliseconds. The rest is a person noticing that something is unusual, working out what it is, and telling you afterwards what happened. That work is included rather than sold back to you as a support tier.

  1. Watch

    Traffic, latency and challenge rates are sampled per site, continuously, not only as an edge-wide average that hides you inside it.

  2. Escalate

    An anomaly the automation does not settle on its own reaches a person, at any hour, on the channel you nominated.

  3. Report

    Afterwards you get a written account of what arrived, what was dropped and what changed, in a form you can forward to your own stakeholders.

Emergency

Emergency onboarding

If you are already under attack you are in no position to run a procurement process. We can bring you onto the network in minutes, before you are a customer, and settle the paperwork once you are back online.

  • Same-day onboarding
  • DNS or BGP redirection
  • Guided migration, step by step
Attack in progress

Do not wait on a form. Email support@deflecto.net and say what is being hit.

Who it is for

Built for teams that cannot absorb downtime.

The pattern repeats across every sector: the traffic that matters most arrives at the worst possible moment, and so does the attack.

iGaming and betting

Peaks are published in advance and extortion arrives on the same schedule.

FinTech and payments

A second offline is a transaction that did not settle and a customer deciding whether to trust you.

E-commerce

A campaign tells everyone, including an attacker, exactly when downtime would hurt most.

SaaS and API

You signed an availability number, and Layer 7 pressure is not a clause your customers will read.

Media and streaming

Delivery already runs near the ceiling, so a flood shows up as buffering before it shows up as downtime.

Public sector

Services citizens must be able to reach, including on the day someone decides they should not.

Next step

Put the network in front of your origin.

Tell us what you run and where it hurts. You will talk to an engineer rather than a sales script, and if you are being hit right now, say that first.