92 Tbps
DDoS Shield.
Three layers of protection — network, application, and transit — working together before a single malicious packet reaches your server.
Traffic hits us
not you.
Every packet passes through our scrubbing stack before it touches your server. Legitimate traffic flows through. Everything else gets dropped at the edge.
Three shields.
One platform.
Each layer is purpose-built for a different class of attack. Together they cover every vector — from packet floods to slowloris bots.
L3/L4 Scrubbing
— In-house + upstream
Volumetric and protocol attacks — UDP floods, SYN floods, ICMP amplification — are absorbed at the network edge before they reach your server's NIC. We combine OVH's VAC scrubbing backbone with custom rules deployed directly at our ISPs, plus dedicated XDP/eBPF bridge nodes for kernel-level PPS filtering.
-
OVH VACOVH's scrubbing centers absorb volumetric attacks up to 92 Tbps via anycast re-routing. Traffic is scrubbed and clean packets returned over GRE tunnels.
-
Custom ISP rulesBGP Flowspec rules deployed directly at Airtel and Fusionnet at the network edge. Drops traffic before it enters our infrastructure — zero bandwidth cost.
-
XDP/eBPF bridge nodesDedicated bare-metal bridge servers running XDP programs in the kernel's fast path. Process millions of packets per second with sub-microsecond decision latency.
-
PPS rate limitingeBPF maps track per-source PPS counters. Sources exceeding thresholds are instantly blackholed without entering the network stack.
-
Protocol anomaly filteringXDP programs inspect TCP flags, UDP payloads, and ICMP types to drop malformed or amplified traffic patterns at wire speed.
L7 HTTP/HTTPS/WebSocket
— In-house
Application-layer attacks survive network scrubbing because they look like legitimate requests. Our L7 stack runs software rate limiting, machine learning classifiers, Shulker Tunnels, and our custom Go reverse proxy to distinguish real users from bots, scrapers, and slow-burn HTTP floods at the request level.
-
Software rate limitingPer-IP, per-path, and per-session request rate windows. Configurable burst allowances mean real users never get 429'd during normal spikes.
-
ML anomaly classifierA lightweight gradient-boosted model scores every request on headers, timing, TLS fingerprints, and behavioral patterns. Known bot signatures are rejected in under 2ms.
-
Shulker TunnelsYour real IP is never exposed. Tunnels route traffic through our edge PoPs so origin IPs stay hidden from attackers — even on DevSpaces and VPSes.
-
Custom Go balancerOur in-house reverse proxy handles TLS termination, connection pooling, WebSocket upgrades, and per-backend health checks with zero off-the-shelf dependencies.
-
Slowloris & CC protectionConnection lifetime limits, incomplete request timeouts, and per-IP connection caps defeat slow-send attacks and challenge-collapsar floods automatically.
IP Transit
DDoS Mitigation
For raw IP transit customers — bare metal servers, VPSes, and DevSpaces with direct IP exposure — traffic passes through our eBPF filtering pipeline and OVH's IP Transit VAC before reaching your assigned IP. Upstream protection rules are applied at the peering level, stopping volumetric attacks before they consume your transit capacity.
-
In-house XDP/eBPF filteringTraffic destined for your IP passes through our eBPF-powered filtering plane. Custom programs apply per-IP and per-protocol rules at kernel speed before packets hit any userspace process.
-
Upstream protection rulesBGP communities and Flowspec rules pushed to our transit providers enforce rate limits and protocol policies at the peering layer — far upstream of our network.
-
OVH IP Transit VACOVH's VAC is applied to all IP transit prefixes. Detected attacks trigger automatic scrubbing via anycast GRE, with return traffic via normal routing.
-
Per-IP traffic baselineseBPF maps maintain rolling per-IP traffic baselines. Sudden deviations trigger automatic upstream null-route or scrubbing center activation within seconds.
-
Full TCP/UDP coverageUDP reflection, NTP amplification, DNS amplification, SYN floods, and ACK floods are all detected and mitigated at the transit layer without any action required from you.
What we
stop.
Every known DDoS vector across all three OSI layers — covered by at least one protection layer, most by two or three.
| Attack type | L3/L4 Scrubbing | L7 HTTP | IP Transit | Typical volume |
|---|---|---|---|---|
| UDP Flood | ✓ | — | ✓ | 1–300 Gbps |
| SYN Flood | ✓ | — | ✓ | 10M–2B pps |
| ICMP Amplification | ✓ | — | ✓ | 10–100 Gbps |
| DNS Amplification | ✓ | — | ✓ | 10–500 Gbps |
| NTP Reflection | ✓ | — | ✓ | 50–400 Gbps |
| HTTP Flood / CC Attack | — | ✓ | — | 100K–10M rps |
| Slowloris | — | ✓ | — | Low volume |
| Bot / Scraper flood | — | ✓ | — | Low-medium |
| WebSocket abuse | — | ✓ | — | Medium |
| TLS exhaustion | — | ✓ | — | Medium |
| BGP hijack / transit | — | — | ✓ | Routing-level |
| IP spoofing floods | ✓ | — | ✓ | 10–500 Gbps |
Built on
serious iron.
Our protection stack doesn't rely on a single vendor. We layer best-in-class upstream providers with our own in-house filtering for defense-in-depth.
Every product.
Protected.
DDoS protection isn't an add-on. Every Shulker product ships with the right protection layer for its threat model — at no extra cost.
Minecraft Hosting
Network and application layer protection. Game-protocol aware. TCP/UDP flood protection on your server's port, plus HTTP filtering for web map and store traffic.
VPS / Bare Metal
Network scrubbing and IP transit VAC cover your assigned IP. eBPF filtering at the hypervisor and transit layers. Full 92 Tbps umbrella.
DevSpaces
Traffic enters via Shulker Tunnels — your real IP is never exposed. ML-scored HTTP/WebSocket filtering on the edge PoPs before reaching your container.
Global Transit
OVH VAC + upstream Flowspec protect your raw IP transit. Designed for high-traffic services that need clean BGP-delivered transit at scale.
Tunnels
All traffic through tunnel PoPs is L7-filtered. Origin IP concealment means attackers can't bypass Shulker's scrubbing by targeting you directly.
Web Stores
Checkout flows, payment callbacks, and API endpoints protected by rate limiting and bot filtering. No revenue lost to cart-filling bots.
Common
questions.
No. All Shulker products include DDoS protection at no additional cost. Minecraft plans include L3/L4 and L7 filtering; VPS and bare metal include transit-layer VAC; DevSpaces are protected via tunnels.
Clean traffic latency impact is under 1ms in normal conditions. Scrubbing centers are geographically distributed, and the XDP/eBPF pipeline runs in the kernel fast path without touching userspace.
L3/L4 attack onset triggers mitigation within seconds via BGP re-announcement. L7 filtering is always-on with no onset delay — every request is scored as it arrives.
Yes. Your panel shows network graphs with flagged attack events. We are also building an attack analytics dashboard — join Discord to follow the rollout.
Open a support ticket immediately. Our team deploys custom upstream Flowspec rules and eBPF programs for novel attack patterns — usually within minutes during business hours, and 24/7 for critical outages.
Yes. Our Go balancer handles WebSocket upgrades and applies per-connection rate limiting and anomaly detection to long-lived WS connections, protecting game servers and real-time apps.
Start
protected.
Every plan ships with DDoS protection.
No config, no waiting, no extra cost.
No credit card required for free tier

