The subscriber edge that defends itself
DDoS detection and mitigation live where subscriber context lives: on the BNG. And the same platform carries your lawful-compliance duties, from NAT records to legal-request workflows, without a single extra box.
Four detection layers. One quiet NOC.
Each engine runs independently: disabling one never blinds another. Confirmation windows keep false positives out; sub-second fast-signal keeps reaction times in.
Signatures
SYN, UDP and ICMP floods, reflection/amplification patterns and port scans, classified per subscriber with per-class thresholds.
Volumetric
Absolute pps and bps ceilings catch brute-force floods immediately, independent of shape or signature.
Fanout / entropy
Destination-spread analysis spots scanners and carpet-bomb behavior that stays under volumetric radar.
Adaptive baseline
Per-subscriber history learns what normal looks like, so a quiet CPE turning into a cannon stands out instantly.
Illustrations mirror the shipping console. Identifiers are fictional.
11K+
incidents triaged automatically, 24h
98
concurrent mitigations, no operator action
156M+
NTP amplification packets dropped, 100% eff.
< 5s
fast-signal reaction window
Rounded figures from a single 24-hour window on the production reference cluster (FTTH ISP, Delhi). Mitigation defaults to targeted rate limits with one-click clear.
Compliance as a workflow, not a project
IPDR, NAT records, legal requests and scoped access are product features. Your regulator asks; the console answers.
Deterministic CGNAT logging
Port-block allocation makes every public IP and port range attributable. NAT sessions log continuously and export as IPDR.
IPDR search that answers
Given a public IP, NAT port, TCP flags, destination or username plus a time range, the console resolves the subscriber in seconds. Excel exports are unlimited.
Legal-request workflow
Requests from authorities are tracked as first-class objects: who asked, what was searched, what was exported, when.
A scoped LEA role
Law enforcement gets its own read-only role, limited to lawful lookup workflows. No shared admin passwords, ever.
Tamper-evident audit log
Every login, config change, lookup and mitigation lands in the audit trail with actor, source IP and full detail.
Least-privilege by default
Admin, operator, partner and LEA roles separate duties. Partners see only their own VLANs; API tokens are scoped and stored hashed.
From "who had this IP and port?" to a name, in seconds
The question every authority asks is the query the console is built around. Search billions of flow records by public NAT IP and port, private IP, destination, TCP flags or username, export the evidence to Excel, and log the whole lookup in the legal-request workflow.
- Search by NAT IP + port + timestamp, the lawful triple
- Unlimited Excel exports with every matching record
- Requests tracked end to end, with a full audit trail
- LEA role: scoped, read-only, no shared credentials
Security and compliance, answered
Detection uses four independent layers (signatures, volumetric thresholds, fanout/entropy and adaptive per-subscriber baselines) with confirmation windows before action, and mitigation defaults to targeted rate limits rather than blackholing. Every threshold is tunable live, per network or per BNG, whitelists are first-class, and every action lands in the audit trail with one-click clear.
Bring your worst attack to the demo
We will replay attack patterns against a live cluster and walk your compliance workflow end to end, with your regulator's questions in mind.
Runs on your hardware · One plan, every feature · Migrate in slices