DDoS detection and controlled response · ISP networks

Know what changed.
Respond before the incident spreads.

Turn sFlow, NetFlow, IPFIX, mirrored traffic and cloud flow logs into a focused DDoS incident—then coordinate approval-bound RTBH, scrubbing, blocklist or webhook response from one control plane.

  • Seven telemetry source types
  • Adaptive baselines
  • Native multihop BGP response
Live traffic incident · Edge cluster anomaly active
Original diagram showing attack traffic detected from NetFlow, a protected ISP edge and an operator-reviewed response
Example topology · Detection and response context, not automatic traffic scrubbing.
60scontinuous
traffic context
L3/4flow-level
network signals
2 lensesnetwork traffic
and attack intelligence
3 modesobserve, approve
or automate
Detection starts with context

Separate an attack-shaped change from ordinary busy traffic.

Strong DDoS pages lead with speed and scale. For an ISP operator, the useful question comes next: what changed, where, and which evidence supports the alert?

01

Volumetric floods

Detect sudden bandwidth and packet-rate growth against configurable limits and the learned traffic baseline.

UDP · TCP · ICMP
02

TCP protocol attacks

Surface SYN, SYN-ACK and FIN floods through packet rate, flow creation and protocol concentration.

SYN · SYN-ACK · FIN
03

Reflection and amplification

Identify abnormal DNS, NTP, SSDP, SNMP and GRE traffic directed at protected services.

DNS · NTP · SSDP · SNMP · GRE
04

Fragmentation attacks

Preserve protocol and target evidence when fragmented IP traffic departs from the expected profile.

IPv4 · IPv6 · fragments
05

Multi-vector incidents

Keep bandwidth, packets, flows, protocols and targets attached to one incident as the attack changes shape.

Combined techniques
06

Scoped anomalies

Tune thresholds globally or for an authorized prefix, host or protocol without losing the broader network baseline.

Host · subnet · protocol
A response model your NOC can follow

Signal to decision, with the evidence kept attached.

ISPbills follows a clear operational progression: collect, establish normal behaviour, detect abnormality, preserve evidence, apply the tenant’s response policy, verify, and withdraw temporary controls.

Active incidentUDP traffic is 8.7× above the learned baseline.94%
  1. 01
    CollectIngest network telemetry

    Normalize sFlow, NetFlow, IPFIX, mirrored traffic or supported cloud flow logs.

  2. 02
    DetectCompare against normal

    Evaluate bandwidth, packets per second and flow count against baselines and explicit thresholds.

  3. 03
    ExplainBuild the network and incident picture

    Separate inbound and outbound traffic, identify affected and attacking devices, then add ASN, official RIR, community and routing-security context.

  4. 04
    RespondApply controlled mitigation

    Use observe-only, approval-bound or verified automatic workflows with exact targets and timed withdrawal.

Clear product boundaries

Automation with visible limits and rollback.

DDoS changes can affect routing and customer reachability. ISPbills keeps detection separate from response, makes the control mode explicit, checks protected scope, the operator allowlist and an automatically discovered essential-address perimeter, and retains expiry and withdrawal state.

ISPbills does

Detect, explain and coordinate

  • Learn expected traffic patterns
  • Identify targets and attack vectors
  • Visualize AS paths, RPKI and route visibility
  • Provision isolated RouterOS blackhole or RTBH controls
Safety boundaries

Response remains tenant-controlled

  • Auto-protect essential network addresses
  • Allowlist any additional must-stay-up IP or CIDR
  • Limit mitigation to exact /32 or /128 targets
  • Expire and withdraw temporary actions
Capacity-based monthly plans

Choose the tier that covers your monitored edge.

Every plan includes flow analysis, anomaly detection and the guided incident workflow. Checkout collects the exporter and capacity details needed for setup.

Growing networks

40Gbps

More headroom for larger or multi-edge networks.

৳25,000/month
Buy 40Gbps plan
  • Higher monitored capacity
  • Same control plane
  • Multiple exporter definitions
High-capacity edge

100Gbps

Maximum listed capacity for busy ISP edges.

৳55,000/month
Buy 100Gbps plan
  • Highest listed tier
  • Incident workflow at scale
  • NOC contact captured at checkout
Deployment questions

Know what you are buying before traffic is exported.

The direct checkout asks for the information our team needs to prepare a safe rollout.

Which telemetry sources are supported?

The control plane supports sFlow, NetFlow v5/v9, IPFIX, SPAN or port mirroring, AWS VPC Flow Logs and Google Cloud VPC Flow Logs. Connected MikroTik RouterOS devices can receive the native ISPbills NetFlow or IPFIX collector target in one step, and health is shown only after real records are decoded.

Can ISPbills automate mitigation?

Yes, when the tenant deliberately configures it. A connected RouterOS 7 device can receive a dedicated eBGP multihop peer to the native ISPbills speaker in one click. ISPbills verifies Established state, announces only an approved attacked IPv4 /32 with the blackhole community, shows the active route count, and withdraws it on expiry. Local RouterOS blackhole remains available without BGP.

Is this a traffic-scrubbing service?

No. ISPbills does not claim to absorb attack traffic in a global scrubbing network. It gives an ISP visibility and response context so the team can act locally or coordinate with its transit provider.

Can private or infrastructure addresses be protected?

Yes. Authorized public and private IPv4 or IPv6 CIDRs can be declared. The mitigation allowlist is independent of protected scope, so peering, DNS, management, monitoring and other must-stay-up addresses can always be excluded.

How does ISPbills avoid blocking essential addresses?

ISPbills automatically excludes tenant router, OLT, managed switch and radio addresses, gateways, collector and BGP endpoints, connector addresses and the suspended-user pool. It rechecks this inventory before each RouterOS or BGP action, alongside the operator allowlist.

Does external intelligence automatically block an IP?

No. Official APNIC, ARIN and other RIR registration identifies allocation ownership, while licensed community feeds add investigation context. Neither authorizes mitigation. Possible RPKI origin, BGP hijack or route-leak warnings also require network-engineer validation.

What happens after the 14-day trial?

The service pauses and the tenant Group Admin must choose a paid plan or continue without DDoS Protection. ISPbills does not create an invoice or convert the trial automatically.

Start with the monitored edge

Give your NOC an incident, not another wall of counters.

Start 14-day trialNo card, automatic plan, or automatic invoice