Technology

How NetIO stops an attack

Incoming traffic is analysed and filtered in real time: malicious packets and requests are dropped, while legitimate users reach your services with minimal added latency. The same engine powers our services and the software we license to operators.

Mixed traffic Clean traffic Incoming traffic users · bots · attacks NetIO filtering Packet filtering · L3–L4 App filtering · L7 / WAF Bot mitigation Malicious traffic dropped Your origin protected
Legitimate / clean traffic Malicious traffic
1

Ingest

Traffic reaches a filtering node via a protected IP address, a tunnel or a BGP announcement — or is processed inline on your own servers under licence.

2

Analyse

Per-resource baselines, statistical and behavioural models, and signature heuristics classify every flow in real time.

3

Mitigate

Floods, malformed packets and abusive requests are dropped or challenged; rate limits and WAF rules are applied surgically.

4

Deliver

Clean traffic is forwarded to your origin over the same path, keeping latency low and legitimate connections intact.

Volumetric mitigation · L3–L4

Filters high-bandwidth floods — SYN, UDP, ICMP, DNS and NTP amplification, reflection and fragmentation — before they saturate your uplinks.

Protocol & state-exhaustion defence

Protects firewalls, load balancers and servers from connection-table and resource-exhaustion attacks such as SYN, ACK and TCP state floods.

Application-layer protection · L7

Detects and blocks HTTP and HTTPS floods and slow-rate attacks, with an integrated WAF for OWASP-class web-application threats.

Bot mitigation

Separates real users from automated clients using challenge-response, JavaScript validation and TLS/HTTP fingerprinting.

Behavioural detection

Learns normal traffic patterns per resource and flags anomalies automatically — adaptive thresholds keep false positives low without manual tuning.

Flexible deployment

Run inline on premises, or divert traffic to NetIO nodes via BGP and GRE — switch between models without re-architecting your network.

Attack coverage

What we filter

Coverage spans the full stack, from packet floods that saturate an uplink to application abuse that looks like ordinary browsing.

SYN flood UDP flood ICMP flood DNS amplification NTP / SSDP / Memcached reflection IP fragmentation TCP state exhaustion (ACK / RST) Connection floods HTTP / HTTPS flood Slowloris & slow-rate SSL/TLS exhaustion DNS query flood Layer-7 bot attacks Scraping & application abuse Credential stuffing OWASP Top 10 exploitation
Commodity hardwareStandard x86-64 servers
Supported LinuxNo proprietary appliance
REST API & metricsSIEM-friendly logging
IPv4 and IPv6Dual-stack filtering
Software licensing

Run the same engine yourself

The software is delivered as installable packages for industry-standard server hardware running supported Linux distributions — no proprietary appliance required, which lowers total cost of ownership.

Licence

Software licensing

Deploy NetIO on premises or within your own network and retain full control of your traffic and data.

  • Term licences — 12, 24 or 36 months
  • Perpetual licences with annual maintenance
  • Transparent, quoted pricing
  • For ISPs, hosting and cloud providers, data centres and enterprises
Alongside the software

Professional services

Hands-on help from engineers with real operational experience.

  • Deployment and configuration
  • Integration with existing infrastructure
  • Training for your technical team
  • Time-and-materials or fixed-fee engagements
Managed service

Protection as a service

The same software, operated by NetIO on our filtering nodes — protection as a subscription, with nothing for you to run.

  • Website, server and network connection models
  • Protected IPv4 and IPv6 addresses included
  • Ideal where in-house capacity is not the priority
  • White-label resale available to operators
See the services

Want a technical evaluation?

We are happy to walk your engineers through the architecture, the filtering policy model and the API.