DDoS (Distributed Denial of Service) attacks flood your server with fake traffic until it can't respond to real visitors. They're more common than you think — not just for big companies. Game servers, small e-commerce sites, and even personal projects get targeted. Here's what's actually happening and how to defend against it.
What Happens During a DDoS Attack
Attackers control thousands of compromised devices (a botnet). They instruct these devices to simultaneously send traffic to your server's IP address. Your server's CPU and network card get overwhelmed processing all those requests — and legitimate users can't get through.
Volumetric Attacks
Flood your bandwidth with garbage traffic (UDP floods, ICMP floods). Often 100Gbps+.
Protocol Attacks
Exploit weaknesses in TCP/IP — SYN floods, fragmented packets. Exhaust server resources.
Application Layer
Target HTTP endpoints — sending legitimate-looking requests faster than your app can respond.
How Hoststack's DDoS Protection Works
All Hoststack plans — hosting, VPS, VDS and game servers — include network-layer DDoS protection at no extra cost. Here's what that means in practice:
Upstream Scrubbing
Traffic to your IP passes through scrubbing centres before reaching your server. Malicious traffic is identified and dropped; clean traffic is forwarded.
BGP Blackholing
During very large attacks (100Gbps+), we can null-route your IP for up to 30 minutes to protect network stability for other customers.
Rate Limiting
Our routers enforce per-IP rate limits, blocking source IPs sending abnormal packet volumes.
SYN Cookie Protection
TCP SYN floods are absorbed at the network layer before they reach your server's kernel.
What You Should Configure on Your Server
Network-layer protection handles volumetric attacks, but application-layer protection is your responsibility. Here's what to set up:
- Cloudflare (free plan) — Put Cloudflare in front of your website. It hides your real IP and absorbs HTTP floods before they reach your server. Enable "I'm Under Attack" mode during an incident.
- Fail2ban — Automatically bans IPs that fail SSH login too many times or trigger your web app's rate limits. Essential on any VPS.
- UFW firewall rules — Only expose the ports you actually use. Close everything else. A game server only needs its game port and SSH — not 65,000 open ports.
- Rate limiting in Nginx/Apache — Add
limit_req_zonerules to cap requests per IP per second at the web server level. - Disable ICMP if not needed — Some attack types use ICMP echo floods. Blocking ICMP won't affect most applications.
Game Servers Deserve Special Attention
Game servers are uniquely targeted because competitive players sometimes DDoS opponents. If you're hosting Minecraft, FiveM, CS2 or Rust, consider:
- Never expose your real server IP — use a reverse proxy or TCPShield.
- Use Hoststack's Game VPS plans which include game-aware DDoS filtering that understands UDP game packets vs flood traffic.
- Enable IP whitelisting if your player base is small and consistent.
DDoS-Protected Hosting Included Free
All Hoststack plans include network-layer DDoS protection at no extra cost.
View DDoS Protected VPS