Anti-spoof filtering, DDoS containment and abuse blocking run in the same XDP data plane that forwards the traffic. No scrubbing appliance, no detour, no separate box to licence.
latency tax — no scrubber detour, no tromboning
data-plane CPU for DDoS fanout at production load
sustained CPU with spoof filtering, flood control and abuse drop all enforcing
where the filtering happens — not in a side path
The hard part is not blocking traffic. It is blocking the attack without taking the customer off the internet.
Traffic leaving a subscriber port with someone else’s source address — or a private-range address that should never appear — is dropped where it enters, not traced back later.
Don’t chase the attacker’s address. Protection is applied per subscriber and per attack type at line rate, so the victim stays reachable while the flood is dropped.
Block the attack, not the customer. The offending flow is stopped while the rest of that subscriber’s traffic keeps running.
When a subscriber’s line is rented out or a device is recruited, containment happens at their port instead of after the traffic has crossed your core.
One data plane protects the network from abuse and the subscriber from congestion — the two problems are usually solved by two separate boxes.
OrionOS ships the kernel, the forwarding path, the BNG daemon and very little else. A vulnerability in a package you never shipped is one you never patch.
Ten technical briefs cover edge security and DDoS in detail.
A proof of concept runs on your own x86 against your own subscribers. Send subscriber count and busy-hour throughput and we size it with you.
Contact us if you need a solution.