How to prevent DDoS attacks without compromising network performance

Scroll to read the guide. 

Manged Anti-DDoS_750x600

  • This guide has been created for IT and security professionals who need to block DDoS attacks without slowing down network performance.

As businesses expand their digital footprint, protecting internet-facing applications has become just as important as keeping them online. Traditionally, many enterprises have faced a trade-off: strong Distributed Denial of Service (DDoS) protection often comes at the cost of network performance.

That trade-off is no longer acceptable.

In 2025, DDoS attacks saw a rapid rise with an increase of 121% - and through automation and AI they are becoming more sophisticated. At the same time, users expect real-time performance from cloud applications, video, financial services and digital platforms.

The question is no longer whether to protect against DDoS attacks, but how to prevent them effectively without degrading user experience due to poor performance of connectivity.

What is a DDoS attack?

A DDoS (Distributed Denial of Service) attack is a cyber-attack in which multiple systems flood a target, such as a website, application or network, with overwhelming volumes of traffic to disrupt its availability on the internet. These attacks are often launched using large botnets.

DDoS attackers typically adopt the two categories of attack below to overwhelm a target.

1. Pipe saturation attack

A pipe saturation attack is a volumetric attack that generates a massive amount of illegitimate traffic (e.g. 1 Tbps) towards a target.

These attacks aim to create congestion or clogging between the target and the internet by consuming all available bandwidth.

Examples include DNS reflection/amplification attacks and UDP/ICMP flooding.

2. Resource exhaustion attack

A resource exhaustion attack is classified as either a Protocol Attack or an Application Attack.

These attacks aim to exhaust the resources of a target’s network equipment or servers, causing slowdowns, outages or complete service failure. Protocol Attacks target network equipment (e.g. firewalls and load balancers), while Application Attacks target application servers and their computing resources.

Protocol Attacks include SYN flooding and TCP flag abuse, while Application Attacks include GET/POST floods and Layer 7 application attacks.

Why should DDoS attacks be avoided?

DDoS attacks don’t just interrupt services, they create serious business risk.

  • Revenue loss: Service downtime, disrupted operations or poor user experience.

  • Reputational damage: Loss of customer trust.

  • Security risks: Attacks can mask data breaches or unauthorised access.

  • Regulatory exposure: Potential penalties from data protection failures.

As organisations rely more on always-online digital services, preventing DDoS attacks is essential to maintaining business continuity and protecting critical assets.

What is the best way to mitigate DDoS attacks?

DDoS mitigation cannot be fully effective solely within a target’s premises (on-prem) because it does not stop malicious traffic before it saturates the internet connection. On-premises Anti-DDoS solutions can only protect against relatively small-scale attacks that are below the bandwidth capacity of the target’s internet connection.

The most effective approach is to deploy DDoS protection globally using a distributed, automated mitigation system known as Scrubbing Centres (SCs). SCs detect and filter malicious traffic near the attack source, effectively eliminating congestion, and then deliver legitimate “clean” traffic back to the target’s premises.

Key advantages of globally-distributed mitigation systems include:

  • Upstream traffic filtering to stop attacks before they hit a target’s network.

  • Global scrubbing capacity to absorb large-scale attacks near the DDoS attack source.

  • Reduced cross-regional DDoS traffic, helping to maintain high network performance.

Nowadays, modern Anti-DDoS services are now built on globally distributed, network-level intelligence rather than isolated tools installed on enterprise premises.

Enterprises can subscribe to online Anti-DDoS services and benefit from:

  • Detects threats earlier through continuous traffic analysis.

  • Filter malicious traffic upstream before congestion occurs.

  • Maintain service availability during high-volume attacks.

  • Eliminate manual intervention with automated response systems.

This approach not only improves security but also reduces operational complexity and cost.

What factors to consider when you evaluate an Anti-DDoS solution?

When evaluating an Anti-DDoS (Distributed Denial of Service) solution, organisations should balance security capability, connectivity performance, cost and deployment simplicity according to their own risk exposure.

Key considerations include:

  1. Mitigation capacity of scrubbing centres
    Ensure the solution can handle massive volumetric attacks, ideally over 3 Tbps, using a globally-distributed network of scrubbing centres.

    Globally-distributed SCs accept requests from Internet users and absorb malicious DDoS traffic and pass legitimate traffic to the protected servers.

  2. Attack scrubbing technology
    Mitigation scope: Look for technology capable of intelligently mitigating multiple types of DDoS attack, including volumetric, protocol and application-layer attacks, with a high level of accuracy.

  3. Operation mode: Always-on vs. on-demand
    The operational mode of an Anti-DDoS service should align with the enterprise’s risk profile.
    1. Always-on: Best suited to high-risk organisations that cannot tolerate downtime and are frequently targeted.
    2. On-demand: More cost-effective for organisations that are rarely targeted.

  4. Traffic diversion
    There are two common methods of diverting enterprise traffic to cloud-based scrubbing centres within Anti-DDoS services.
    1. Reverse proxy
      Under a Reverse Proxy setup, the enterprise changes its protected domain’s A records or CNAME records to IP addresses associated with the Anti-DDoS provider’s scrubbing centres.
      Once the DNS records are updated, all traffic is routed through the globally distributed SCs for DDoS detection and mitigation.

    2. BGP (Border Gateway Protocol) redirection
      SCs can use BGP to announce the enterprise’s protected IP prefixes to the internet, enabling traffic to be diverted to the globally distributed scrubbing centres for DDoS detection and mitigation.
      Enterprises can choose either approach depending on their operational requirements.

  5. Mitigation lead time
    This refers to how quickly the solution can effectively mitigate an attack once protection is triggered.
    1. Always-on mode: Ideally, attack detection and mitigation should occur within less than one minute.
    2. On-demand mode: Since traffic diversion to scrubbing centres is required, activation takes longer than always-on mode. Activation should occur within three minutes. 

  6. Connectivity performance - latency
    Latency is introduced when DDoS protection is enables and is typically added due to two key factors.
    1. Traffic diversion method
      1. Reverse proxy
        1. Reverse proxy introduces latency by intercepting, inspecting and scrubbing traffic before it reaches the enterprise’s protected servers. 
        2. While necessary for protection, this process can add significant time due to the ‘cleaning’ process which involves traffic analysis, malicious traffic drop, Network Address Translation (NAT) and SSL termination.
        3. It typically adds around 30ms to 100ms to Round Trip Time (RTT). 
      2. BGP redirection
        1. BGP redirection introduces latency through traffic re-routing and analysis within the scrubbing centres. Unlike Reverse Proxy, NAT, SSL/TLS termination and similar internal processing are generally not involved.
        2. BGP redirection adds around 3ms to 50ms of additional latency, which is usually shorter than that of the Reverse Proxy approach. 
    2. Proximity
      The physical distance between scrubbing centres and the enterprise’s data centres also contributes to latency. Latency within the same city is typically below 10ms.

  7. Cost and integration
    1. Costing: Evaluate whether the pricing is proportionate to the scope and quality of protection provided.
    2. Ease of integration: The solution should integrate smoothly with existing network components, such as CDNs and WAFs, whether deployed in the cloud or on-premise. 

PCCW Global’s approach: global protection without latency trade-offs

PCCW Global’s Managed Anti-DDoS solution is designed to eliminate the traditional compromise between performance and protection.

At its core is a private, high-performance global network, combined with 10 strategically located scrubbing centres and over 8 Tbps of mitigation capacity.

How PCCW Global’s Managed Anti-DDoS service is different from others:

  • Provides a wide range of DDoS protection, from volumetric floods to application attacks.

  • Achieves high mitigation accuracy through the deployment of advanced detection technologies.

  • Ensure network reliability with dedicated, high-capacity network resources exclusively allocated for Anti-DDoS services.

  • Minimise latency (e.g. ~2 ms within the same city) through strategically located scrubbing centres.

  • Reduce mitigation lead time by routing traffic through PCCW Global’s private network.

  • Offer flexible and cost-effective pricing plans tailored to customers with different risk profiles.

  • Enable real-time monitoring and detection for immediate identification of anomalies and attacks.

  • Provide automated mitigation capabilities to respond to threats at machine speed.

This ensures attacks are mitigated before they impact applications or infrastructure.

Our global scrubbing centres: 

Global Scrubing Centres

The performance advantage: low latency, even during an attack

By minimising the distance traffic travels, PCCW Global ensures that applications remain fast, responsive and reliable, even during active DDoS attacks.

For enterprises running latency-sensitive services, this is critical to maintaining both performance and user experience.

When should businesses implement DDoS protection?

Enterprises should consider DDoS protection if they:

  • Operate internet-facing applications or platforms.

  • Depend on real-time or latency-sensitive services.

  • Require high availability and uptime guarantees.

  • Operate in regulated industries.

In reality, most modern businesses fall into at least one of these categories.

Maintaining a resilient, high-performance network, website or application

Preventing DDoS attacks is no longer just a security measure, it is a core regulatory and business requirement for digital operations.

By adopting a managed Anti-DDoS solution, enterprises can:

  • Prevent and mitigate attacks before disruption occurs.

  • Maintain low latency and high application performance.

  • Protect critical services.

  • Reduce operational complexity and infrastructure costs.

  • Strengthen long-term cyber resilience.

With the right approach, businesses no longer have to choose between security and speed, they can have both.

Want to know more?

Discover how our Managed Anti-DDoS and other security solutions can help protect your business.