OcNOS-SP  ·  FastNetMon  ·  BGP Flowspec  ·  RTBH

Detect and stop DDoS attacks inside your own network

In-network DDoS protection detects and mitigates attacks at the network edge on the router itself, instead of diverting traffic to an off-path scrubbing center. IP Infusion delivers it as one system: open switches and routers running OcNOS with BGP FlowSpec and RTBH, supported under one contract. sFlow telemetry feeds a FastNetMon detection engine, which pushes FlowSpec or RTBH rules back to the router for line-rate filtering in the ASIC.

Why In-Network DDoS Mitigation?

Filter attack traffic in hardware at the edge, with no traffic diversion.

The router running OcNOS drops attack traffic on the box that already carries the customer, so every packet stays on its normal path and clean traffic never leaves the forwarding plane. There is no off-path scrubbing center to route through, no per-packet detour, and no separate scrubbing capacity to buy and size.

The router running OcNOS with FastNetMon puts detection and mitigation directly at the network edge: sFlow telemetry streams from the router to FastNetMon continuously; when an attack is detected, FastNetMon pushes BGP Flowspec rules back to the router; the router installs the rules in the ASIC hardware at line rate. The entire loop completes in seconds, and clean traffic passes with no added latency.

Attack types detected and mitigated:

UDP Amplification SYN Flood TCP RST Flood ICMP Flood DNS Query Flood NTP Amplification Memcached Reflection Volumetric Bandwidth Saturation Fragmented Packet Attack

FastNetMon: the detection engine that triggers your mitigation

FastNetMon Advanced watches the sFlow the router exports and, the moment traffic crosses a per-host or per-subnet threshold you set, triggers mitigation automatically. It is production-grade software already running at hundreds of ISPs and hosting providers worldwide, so the detection engine on the page is the same one operators trust in production.

BGP FlowSpec: surgical filtering, pushed as a BGP route

When you need to block one attack without touching everything else, the router matches on source and destination IP, protocol, port, packet length, TCP flags, DSCP, and fragment type. The rule arrives over BGP and lands in the ASIC in milliseconds, so it drops, rate-limits, or redirects the matching traffic at line rate with zero CPU overhead. FlowSpec follows RFC 8955.

RTBH: stop a volumetric flood before it reaches you

For a large volumetric attack, the router blackholes the targeted prefix over BGP, either on operator command or automatically when FastNetMon sees traffic to that prefix cross threshold. The RTBH route propagates to your upstream peers and transit providers, so they drop the attack at their edge before it ever ingresses your network.

sFlow: the traffic feed that makes detection possible

The router exports sFlow from every edge interface using hardware-accelerated sampling at a rate you set, so detection sees the traffic without loading the CPU. The same feed goes to FastNetMon for DDoS detection and, at the same time, to Kentik, PRTG, Prometheus, or any sFlow collector you already run for traffic analytics. sFlow follows RFC 3176.

Hardware ACLs: block known bad actors once, forever

For traffic you already know is hostile, the router installs an ACL in the ASIC that permanently drops it by IP, subnet, protocol, or port, and rate-limits per interface, per VLAN, or per prefix. You configure it once and the hardware enforces it from then on, with no routing or processing overhead.

FastNetMon → OcNOS · automated response (example) ALERT
1 · FastNetMon detects anomaly via sFlow
ALERT  UDP flood → 203.0.113.50
14 Gbps · threshold 5 Gbps exceeded
2 · FastNetMon pushes BGP Flowspec to OcNOS
POST /api/flowspec/rule
match: dst 203.0.113.50/32 proto UDP
action: rate-limit 100Mbps
→ rule installed in ASIC
3 · OcNOS enforces at line rate in hardware
Flowspec rules active 14
Attack traffic dropped
Over-threshold rate-limited
✓ clean traffic passing normally

FastNetMon: the detection engine

FastNetMon Advanced is a dedicated DDoS detection engine used by hundreds of ISPs globally. It integrates natively with OcNOS via BGP Flowspec and RTBH. Consumes sFlow telemetry with configurable per-host, per-subnet, and per-protocol thresholds.

Learn about FastNetMon →
Seconds
Detect-to-mitigate loop: from sFlow anomaly to Flowspec rule in hardware
0ms
Added latency for clean traffic: filtering is in-line ASIC, not an off-path scrubber
0%
CPU overhead for hardware ACL and Flowspec enforcement: ASIC-accelerated
600+Operator Deployments
60+Countries
26Years in Networking
Reference Architecture

In-network DDoS detection and mitigation: full topology

Here is where every protection layer sits in a live network. Attack traffic from the internet arrives at the OcNOS edge routers, which stream sFlow to FastNetMon the whole time. The moment FastNetMon sees an anomaly it pushes BGP FlowSpec or RTBH back to the edge, and the router installs the rule in the ASIC in milliseconds. Your upstream peers can take the RTBH announcement too, so they drop the attack before it ever reaches you.

In-network DDoS protection topology with OcNOS edge and FastNetMon Attack traffic from botnet sources transits an upstream peer to two OcNOS-SP edge routers. The edge routers export sFlow telemetry to a FastNetMon detection engine. When an attack is detected, FastNetMon pushes BGP Flowspec or RTBH routes back to the edge routers via BGP, installing rules in the ASIC for line-rate filtering. Clean traffic continues to the protected customer or data center network. The upstream peer can also receive RTBH announcements over BGP to drop attack traffic before it ingresses the protected network. Attackers distributed botnet 10 to 100 Gbps Customers legitimate traffic HTTP/DNS/SSH Transit Peer eBGP / RTBH recv Tier-1 Internet RTBH /32 drops OcNOS Edge-01 UfiSpace S9600-72XC Qumran 2C (BCM88820) · 2.4 Tbps ASIC HARDWARE Flowspec + ACL drop line-rate · 0% CPU OcNOS Edge-02 UfiSpace S9600-72XC ECMP redundant ASIC Flowspec + ACL attack + clean FastNetMon Detection Engine sFlow analysis threshold-based detect sFlow ↑ BGP Flowspec ↓ + RTBH RTBH propagated upstream over eBGP → Protected Servers DC / hosted infra clean traffic only · 0ms added Customer Networks per-tenant policy managed DDoS service clean ✓ attack drop DETECT-TO-MITIGATE LOOP (EXAMPLE) 1. Anomaly detected FastNetMon telemetry 2. BGP Flowspec push FNM → OcNOS over BGP 3. ASIC rule installed OcNOS hardware enforce 4. Attack dropped at line rate total loop: seconds · 0ms clean-traffic latency
Attack traffic
Clean traffic
sFlow telemetry
BGP Flowspec / RTBH (control plane)
↳ hover any node for platform, ASIC, BGP, and policy detail
How It Works

From attack detection to blocked traffic in four steps

The detect-to-mitigate loop runs automatically. Once configured, the network stops an attack without operator intervention.

1

Collect

OcNOS exports sFlow telemetry from all edge interfaces to FastNetMon. Hardware-accelerated packet sampling: no CPU overhead, no impact on forwarding performance.

2

Detect

FastNetMon analyzes flow data against per-host and per-subnet thresholds. Identifies volumetric floods, SYN storms, UDP amplification, DNS floods, and NTP reflection attacks, typically in under 1 second.

3

Signal

FastNetMon automatically pushes BGP Flowspec rules (for surgical mitigation) or RTBH blackhole routes (for volumetric attacks) to OcNOS via BGP. Fully automated: no operator action required during the attack.

4

Mitigate

OcNOS installs Flowspec rules or RTBH routes directly in the ASIC hardware. Attack traffic is dropped or rate-limited at full line rate. Clean traffic continues unaffected. Rules are removed automatically when the attack subsides.

Use Cases

Where in-network DDoS protection fits

The same edge routers and switches carry DDoS protection whether you run a small regional ISP or a large data center, because the detection and mitigation ride on the box that is already at the edge.

ISP & SP Edge Protection

Protect peering edges and transit links from volumetric DDoS that would saturate customer-facing bandwidth. sFlow detection at the peering router with automatic BGP Flowspec mitigation stops floods before they reach downstream customers. Upstream RTBH coordination with transit providers stops attacks before they enter your network.

Data Center Perimeter

In-line DDoS filtering at the DC border, protecting hosted infrastructure and cloud workloads. Static hardware ACLs block known bad actors permanently. Dynamic Flowspec rules adapt to new attack signatures in real time. No traffic diversion to a scrubbing center means zero latency impact for clean traffic.

Managed DDoS Protection Service

Operators can offer per-customer DDoS protection as a managed service, billing by the protected prefix. FastNetMon supports per-customer threshold profiles. OcNOS enforces per-customer Flowspec rules. No shared scrubbing infrastructure: each customer's protection is dedicated and in-network.

Common Questions

DDoS Protection with OcNOS: FAQ

What is BGP Flowspec and how does OcNOS use it for DDoS mitigation?
BGP FlowSpec (RFC 8955, originally RFC 5575) is a BGP extension that distributes granular traffic filtering rules across routers, similar to pushing ACLs via BGP but with more granular match conditions. OcNOS matches on source IP, destination IP, protocol, source and destination port, packet length, TCP flags, DSCP, and IP fragment type. When FastNetMon detects an attack it pushes FlowSpec rules to OcNOS over BGP in milliseconds, and OcNOS installs them directly in the ASIC, where they drop or rate-limit the matching traffic at full line rate with zero CPU overhead.
How does FastNetMon integrate with OcNOS, and how fast is the response?
FastNetMon reads the sFlow the router exports and checks it continuously against the per-host and per-subnet thresholds you set. When traffic crosses a threshold, for example a UDP flood exceeding 5 Gbps to a single destination, it automatically pushes either a BGP Flowspec rule (for surgical, protocol-specific mitigation) or an RTBH blackhole route (for full prefix blackholing) over BGP to OcNOS. The whole detect-to-mitigate loop is automated and typically completes within seconds.
What types of DDoS attacks does this solution detect and mitigate?
The solution covers the attack types operators see most: volumetric floods (UDP amplification, ICMP flood, raw bandwidth saturation), protocol attacks (SYN flood, TCP RST flood, fragmented packet attacks), and application-layer attacks that flow analysis can catch (DNS query floods, NTP amplification, Memcached amplification). For precise mitigation, BGP Flowspec matches on protocol, port, TCP flags, and fragment type. For volumetric attacks where speed matters more than precision, RTBH blackholing drops all traffic to the targeted prefix at the edge.
Can OcNOS do DDoS mitigation without FastNetMon?
Yes. The router mitigates on its own through three independent mechanisms: static hardware ACLs (ASIC-accelerated, zero CPU overhead) that permanently block known bad actors, manual RTBH blackholing over BGP that you trigger by prefix, and reception of BGP Flowspec rules from any standard BGP speaker. If you already run a detection platform such as Arbor/Netscout, A10 Networks, or Kentik, OcNOS becomes your enforcement plane, taking Flowspec or RTBH commands from the detection system you already have.
What is RTBH blackholing and when should I use it instead of Flowspec?
Reach for RTBH (Remotely Triggered Black Hole) when a volumetric attack is large enough that dropping all traffic to the targeted destination, legitimate traffic included, is an acceptable trade to protect the rest of the network. It works by advertising the targeted prefix over BGP with a next-hop pointing to a discard interface, so every upstream router that receives the advertisement drops traffic for that prefix at its own edge, before it enters your network. Choose BGP Flowspec instead when you need surgical mitigation, for example blocking only UDP port 53 to a destination while letting TCP through. In practice operators often start with RTBH for speed, then switch to Flowspec for precision once the attack is characterized.
Does in-network DDoS mitigation with OcNOS replace a scrubbing center?
It depends on the attack, and in-network mitigation complements or partially replaces a scrubbing center. When the attack targets your own prefixes, OcNOS with FastNetMon responds faster (sub-2-second) and at lower cost than routing traffic through a scrubbing center, because the filtering happens in-line at the edge in hardware ASICs. When an attack is large enough to saturate your upstream links before it reaches your routers, the most effective approach is upstream RTBH with your transit providers combined with in-network Flowspec. Managed DDoS providers can also run OcNOS as the per-customer enforcement plane, with per-customer Flowspec rules and thresholds.
Get Protected

Protect your network on open hardware.

We'll walk through your topology, your threat model, and the right Flowspec and RTBH configuration for your environment.

Book a DDoS Demo Download OcNOS VM