All posts
securitytechnical

How Our DDoS Protection Works

A technical look at the multi-layer DDoS mitigation protecting every XeroHost server.

X
XeroHost Team|

DDoS attacks are one of the biggest threats to game servers. Here's how XeroHost protects you — automatically, 24/7.

What is a DDoS attack?

A Distributed Denial of Service (DDoS) attack floods your server with traffic from thousands of sources, making it unreachable for legitimate players.

Game servers are a common target because:

  • They're always online and publicly accessible
  • Rival communities or griefers want to take them down
  • The cost of attacks has dropped dramatically

Our mitigation stack

Layer 3 / 4 — Network filtering

We filter malicious traffic at the network edge before it ever reaches your server. Our upstream providers offer 1+ Tbps of scrubbing capacity.

Common attacks blocked at this layer:

  • UDP floods
  • SYN floods
  • ICMP floods
  • Amplification attacks (DNS, NTP, SSDP)

Layer 7 — Application filtering

For game protocols, we deploy custom signatures that understand the game's traffic patterns and drop spoofed or malformed packets.

What you should know

  • Protection is automatic — no configuration needed
  • Mitigation kicks in within seconds of detecting an attack
  • Your server IP remains the same during and after an attack
  • We don't rate-limit legitimate traffic

Need help with a specific attack type? Open a ticket from your client portal.