EDGE SECURITY

Stop the flood at the subscriber’s port, not after it reaches your core.

Anti-spoof filtering, DDoS containment and abuse blocking run in the same XDP data plane that forwards the traffic. No scrubbing appliance, no detour, no separate box to licence.

0 ms

latency tax — no scrubber detour, no tromboning

≈2.5%

data-plane CPU for DDoS fanout at production load

~7%

sustained CPU with spoof filtering, flood control and abuse drop all enforcing

line rate

where the filtering happens — not in a side path

Protect the network from abuse, and the subscriber from collateral

The hard part is not blocking traffic. It is blocking the attack without taking the customer off the internet.

Anti-spoof at the source

Traffic leaving a subscriber port with someone else’s source address — or a private-range address that should never appear — is dropped where it enters, not traced back later.

Read the brief →

Per-victim DDoS fanout

Don’t chase the attacker’s address. Protection is applied per subscriber and per attack type at line rate, so the victim stays reachable while the flood is dropped.

Read the brief →

Surgical abuse blocking

Block the attack, not the customer. The offending flow is stopped while the rest of that subscriber’s traffic keeps running.

Read the brief →

Botnet containment

When a subscriber’s line is rented out or a device is recruited, containment happens at their port instead of after the traffic has crossed your core.

Read the brief →

Abuse and congestion together

One data plane protects the network from abuse and the subscriber from congestion — the two problems are usually solved by two separate boxes.

Read the brief →

A platform that is small on purpose

OrionOS ships the kernel, the forwarding path, the BNG daemon and very little else. A vulnerability in a package you never shipped is one you never patch.

Read the brief →

The briefs behind this page

Ten technical briefs cover edge security and DDoS in detail.

Point it at your own traffic

A proof of concept runs on your own x86 against your own subscribers. Send subscriber count and busy-hour throughput and we size it with you.

Need Solution?

Contact us if you need a solution.