DDoS ProtectionOperator runbook

DDoS Protection

Understand the DDoS Protection workflow, permissions, safety boundaries, and the five guides in this section.

Get help
On this page

DDoS Protection gives Group Admin and authorised NOC teams one control plane for telemetry health, learned baselines, attack evidence, and reviewed response. Open DDoS Protection from the Group Admin or NOC navigation.

Detection is not traffic scrubbing. A healthy telemetry source proves that observations are arriving; it does not prove that unwanted traffic is being filtered. Network-changing actions run only through a verified connector and the configured approval workflow.

Use this five-guide path

  1. Overview: understand access, workflow, and safety boundaries on this page.
  2. Telemetry and protected scope — declare authorised networks, connect flow sources, and activate monitoring.
  3. Detection policies and analytics — configure BPS, PPS, and FPS policies and interpret traffic.
  4. Investigate an attack — validate evidence, identify affected targets, and manage the incident lifecycle.
  5. Mitigation and recovery — prepare connectors, approve a narrow response, verify it, and roll it back.

Access and permissions

Role or permission Access
Group Admin View and configure the complete workspace.
NOC user View the workspace; changes require the relevant DDoS permission.
Manage DDoS Policies Change setup, telemetry, protected scope, detection policies, and traffic classifications.
Manage DDoS Mitigation Configure or test response connectors and BGP, manage exclusions and attack lifecycle, and propose, approve, or cancel responses.
View DDoS Sensor Token Activate monitoring, rotate a sensor token, and see its one-time plaintext value.

Standard Operators, Sub-Operators, and Managers cannot open this workspace. A tenant also needs an active capacity plan or its one-time 14-day decision trial. Starting a trial requires Group Admin confirmation; expiry never creates an invoice or starts a paid plan automatically.

Operating workflow

  1. Complete the network profile and declare only address space you are authorised to monitor.
  2. Connect at least one telemetry source and wait for decoded flow records.
  3. Configure enabled BPS, PPS, and FPS detection policies.
  4. Activate monitoring and let the baseline learn normal traffic.
  5. Validate each alert against fresh telemetry and independent network evidence.
  6. Use a verified connector and the configured approvals only when a response is justified.

Workspace map

Area Purpose
Overview, Traffic, Destinations Current traffic posture, selectable time series, content, exchange, and exporter visibility.
Connectivity Observed AS paths, IPv4/IPv6 visibility, announced prefixes, RPKI state, and exchange declarations.
Attacks, Analytics, Sources, Targets, Protocols Incident evidence, baselines, vectors, affected destinations, sources, protocols, and ports.
Telemetry, Detection Source health plus capacity presets and custom BPS/PPS/FPS policies.
Response & BGP, Runbook Verified connectors, mitigation exclusions, approval workflow, and the printable response sequence.

Before you activate

  • Confirm ownership or written authority for every protected prefix.
  • Add management, DNS, collector, BGP, and other critical infrastructure to the mitigation exclusions.
  • Choose an approval mode that matches the organisation’s change-control policy.
  • Document an independent verification method and rollback owner before enabling any response connector.
Need help applying this guide?Browse related guidance or ask the support team for help.