NetFlow DDoS detection · ISP networks

Know what changed.
Respond before the incident spreads.

Turn NetFlow and IPFIX telemetry into a focused DDoS investigation—target, protocol, top sources, traffic delta and operator-reviewed response steps in one incident view.

  • NetFlow & IPFIX evidence
  • Adaptive baselines
  • Operator-approved action
Live traffic incident · Edge cluster anomaly active
Original diagram showing attack traffic detected from NetFlow, a protected ISP edge and an operator-reviewed response
Example topology · Detection and response context, not automatic traffic scrubbing.
60scontinuous
traffic context
L3/4flow-level
network signals
1 viewtarget, sources
and protocol
Humanapproval before
network action
Detection starts with context

Separate an attack-shaped change from ordinary busy traffic.

Strong DDoS pages lead with speed and scale. For an ISP operator, the useful question comes next: what changed, where, and which evidence supports the alert?

01

Volumetric floods

Spot sudden bandwidth growth, protocol concentration and target saturation against the learned traffic baseline.

UDP · ICMP · amplification
02

Connection surges

Surface rapid growth in flows and source distribution that may indicate SYN floods or resource-exhaustion attempts.

SYN · flow-rate anomalies
03

Targeted anomalies

See which destination, service and network segment changed—then inspect the sources contributing to the incident.

Targets · ports · sources
A response model your NOC can follow

Signal to decision, with the evidence kept attached.

ISPbills follows the same clear progression used by mature DDoS operations: observe, establish abnormality, investigate the affected network context, then review the response.

Active incidentUDP traffic is 8.7× above the learned baseline.94%
  1. 01
    CollectIngest flow records

    Receive sampled or unsampled NetFlow/IPFIX from supported edge and core exporters.

  2. 02
    DetectCompare against normal

    Surface unusual bandwidth, flow rate, protocol mix and destination concentration.

  3. 03
    ExplainBuild the incident picture

    Attach targets, top sources, ports, protocols and the traffic delta to one investigation.

  4. 04
    RespondReview the network action

    Use the evidence to choose rate limiting, firewall, blackhole or upstream escalation steps.

Clear product boundaries

Visibility and guided response—not a hidden autopilot.

DDoS changes can affect routing and customer reachability. ISPbills keeps the operator responsible for network-impacting decisions and clearly distinguishes detection from traffic scrubbing.

ISPbills does

Detect and explain flow anomalies

  • Learn expected traffic patterns
  • Identify targets and top sources
  • Preserve incident evidence
  • Guide operator response checks
ISPbills does not

Claim automatic global scrubbing

  • Absorb attack traffic off-network
  • Apply unreviewed router changes
  • Guarantee every spike is malicious
  • Replace an upstream transit response
Capacity-based monthly plans

Choose the tier that covers your monitored edge.

Every plan includes flow analysis, anomaly detection and the guided incident workflow. Checkout collects the exporter and capacity details needed for setup.

Growing networks

40Gbps

More headroom for larger or multi-edge networks.

৳25,000/month
Buy 40Gbps plan
  • Higher monitored capacity
  • Same detection workflow
  • Exporter rollout planning
High-capacity edge

100Gbps

Maximum listed capacity for busy ISP edges.

৳55,000/month
Buy 100Gbps plan
  • Highest listed tier
  • Incident workflow at scale
  • NOC contact captured at checkout
Deployment questions

Know what you are buying before traffic is exported.

The direct checkout asks for the information our team needs to prepare a safe rollout.

Which routers can export traffic data?

MikroTik Traffic Flow, Cisco, Juniper and other devices that export supported NetFlow or IPFIX records can feed the detector. The checkout asks for your exporter vendor and count so the rollout can be scoped correctly.

Does ISPbills automatically block traffic?

No. This product detects anomalies, organizes NetFlow evidence and guides the operator response. Your NOC reviews and applies any network-impacting action, such as a firewall rule, rate limit or upstream blackhole request.

Is this a traffic-scrubbing service?

No. ISPbills does not claim to absorb attack traffic in a global scrubbing network. It gives an ISP visibility and response context so the team can act locally or coordinate with its transit provider.

Will NetFlow export overload my router?

Export creates some overhead. Sampling, active/inactive timeouts and exporter placement should be sized for the device and link. Share your peak capacity and exporter count during checkout so setup can account for this.

What happens after the 14-day trial?

The 10Gbps tier starts after the trial unless you stop it. You can choose a higher tier during checkout or change the tier later from the portal.

Start with the monitored edge

Give your NOC an incident, not another wall of counters.

Configure and buyRequired setup details collected at checkout