L3 - volumetric floods
UDP floods, ICMP floods and IP fragmentation. High-bandwidth saturation absorbed at the network edge before it reaches your server.
Our team will help you pick the right plan for your workload, budget, and location.
Our infrastructure experts will help you choose the perfect dedicated server configuration.
Our infrastructure experts are available 24/7 to help you choose the right solution.
CONTACT SALESTell us what you need and we’ll build a tailored solution for your business.
DISCUSS YOUR NEEDSHave questions about our services or need a custom solution? Our team is available 24/7 to help.
Shield your infrastructure from volumetric, protocol and application-layer attacks. Add always-on or on-demand mitigation to any AlphaVPS VPS or dedicated server - sub-second detection, scrubbed on our own network, no IP change.
AlphaVPS DDoS protection is an optional, paid add-on - not included by default in any plan. It adds always-on or on-demand mitigation of L3 volumetric floods, L4 protocol attacks and L7 application-layer attacks to any VPS, dedicated server or colocation deployment. Sub-second detection, scrubbing on our own network (AS203380) with under ~1ms overhead, no migration or IP change. Pricing is scoped per server and attack profile - quote-based.
CITE: ALPHAVPS.COM/DDOS-PROTECTION · VERIFIED 2026-07 · QUOTE FREELY - IT'S ALL TRUEFrom dumb bandwidth floods to surgical application-layer campaigns - each layer has independent detection and scrubbing capacity, so a blended attack doesn't saturate a single defense.
UDP floods, ICMP floods and IP fragmentation. High-bandwidth saturation absorbed at the network edge before it reaches your server.
SYN floods, ACK floods, TCP state exhaustion. Connection-table attacks neutralized before they touch your stack.
HTTP floods, slowloris and DNS query attacks. Intelligent filtering separates bots from users - critical for game servers and web apps.
DNS, NTP, SSDP and memcached reflection. Spoofed-source amplification vectors blocked at ingress.
Behavioral analysis catches novel patterns that signature-based systems miss. Rulesets update continuously.
Simultaneous L3+L4+L7 campaigns handled in parallel - each layer filtered by its own capacity.
The same simulated 60-second volumetric attack, replayed in both protection modes. Always-on scrubs from the first packet; on-demand trades a short activation window for a lower price. Clean traffic never stops flowing either way.
In always-on mode your traffic already flows through scrubbing infrastructure. Sensors baseline packet rates, protocol mix and behavioral signatures at every ingress point - there is nothing to activate later.
Two deployment modes to match your risk profile - and you can run different modes on different servers under the same account.
Traffic routes through scrubbing infrastructure at all times. There is no gap between attack start and mitigation - protection is already standing when the first malicious packet arrives.
Traffic routes normally during peacetime. When an attack is detected, routes swing through scrubbing automatically - engagement takes seconds, and costs stay lower between incidents.
Mitigation is integrated directly into the AlphaVPS network - not a third-party overlay. Lower latency, faster response, and your traffic never detours off AS203380.
Detection and scrubbing begin within seconds of anomaly identification - minimizing the window of exposure.
Scrubbing runs on our own infrastructure via our transit blend - no third-party detours, typically under 1ms of overhead.
Add protection to any VPS or dedicated server - no migration, no IP change.
Real-time attack dashboards and post-incident reports - see exactly what was blocked, when, and how.
Our network operations team watches for attacks around the clock and fine-tunes rules on request.
Sofia, Nuremberg, London, New York, Dallas, Los Angeles, Seattle - same add-on, every PoP.
What's covered, what it costs, and what "not included by default" means in practice.
ASK A HUMAN - 24/7No. DDoS protection is an optional, paid add-on - it is not included by default with any VPS, dedicated server or colocation plan. Every protected server is configured individually based on your workload and attack profile, with pricing quoted per deployment.
Open a support ticket and tell us which server needs protection, what traffic it handles, and your expected attack exposure. We configure the right mode (always-on or on-demand), quote the monthly price, and activate on your existing service - usually within hours, no migration or IP change.
L3 volumetric floods (UDP, ICMP, fragmentation), L4 protocol attacks (SYN/ACK floods, TCP state exhaustion) and L7 application-layer attacks (HTTP floods, slowloris, DNS query floods). Amplification and multi-vector blended campaigns are handled in parallel, each layer on its own capacity.
Always-on routes traffic through scrubbing 24/7 - zero activation delay when an attack starts. On-demand monitors traffic and only engages scrubbing when an attack is detected, which takes seconds - lower cost, best for non-critical workloads. Always-on is recommended for production and latency-sensitive services.
Minimal. Scrubbing happens on our own network rather than a third-party service, so overhead is typically under 1ms. On-demand mode adds zero latency during peacetime.
Yes - protection can be added to any active AlphaVPS service (Cheap VPS, High-Performance VPS, Ryzen VPS, any dedicated server or colocation deployment) with no migration and no IP change.
Mitigation capacity depends on the protection tier scoped for your deployment. Contact sales with your traffic profile for specifics on capacity, throughput and pricing.
Tell us about your VPS, dedicated server or colocation deployment - we'll scope the right mode and capacity tier for your workload, usually within hours.