Note:
Customers onboarded after September 10, 2026 are subject to the following instructions. If you are an existing Anti-DDoS Pro or Anti-DDoS Advanced customer, see historical documentation. What is DDoS Defender
DDoS Defender is designed to protect your business against various DDoS attacks and effectively improve business continuity and stability. It is suitable for industries with high business continuity requirements, such as gaming, internet, e-commerce, video, finance, and public sector.
The core capabilities of DDoS Defender include:
|
Multi-layer DDoS protection | Provides L3/4/7 DDoS protection and supports integration with EdgeOne for L7 protection policy configuration to defend against HTTP DDoS attacks. |
Abundant mitigation resources | Provides scrubbing cluster protection capabilities. Regions outside the Chinese mainland provide highly elastic protection based on the Anycast architecture, while regions within the Chinese mainland can be scaled to Tbps-level protection through protection capacity add-on. |
Flexible plans and add-on options | Provides two basic plans, Essential and Premium, and allows you to purchase additional protection capacity add-ons based on business needs. |
Security operations and observability | Provides operational capabilities such as attack analysis and unblocking center to help you monitor attacks and protection status in real time. |
Product Principles
DDoS Defender detects and cleans attack traffic through Tencent Cloud mitigation clusters:
1. Before reaching the protected resources, attack traffic is first diverted to Tencent Cloud DDoS mitigation clusters.
2. The mitigation clusters use a series of detection and identification algorithms to separate malicious attack traffic from normal business traffic and drop the attack traffic.
3. The normal business traffic after mitigation is reinjected to the protected resources without affecting normal access.
DDoS Defender supports establishing protection links for cloud resources (CVM, CLB, EIP, WAF, LH) and EO resources (site domains, L4 Proxy instances, BGP Transit CIDRs). For specific protected resource types, see DDoS Protection Capacity Description. Product Features
Multi-layer DDoS Protection
L3/4 DDoS Protection
DDoS Defender provides automatic detection and mitigation for network-layer and transport-layer attacks, such as UDP Flood, SYN Flood, TCP Flood, ICMP Flood, ACK Flood, FIN Flood, RST Flood, DNS/NTP/SSDP reflection attacks, empty connections, Frag Flood, Smurf, Stream Flood, Land Flood, malformed IP packets, malformed TCP packets, and malformed UDP packets.
L7 DDoS (CC) Protection
DDoS Defender provides protection capacity support for L7 DDoS (CC) attacks. Specific protection policy configurations, such as adaptive frequency control, intelligent client filtering, slow attack protection, and rate limiting, are provided by EdgeOne (EO).
Flexible Plans and Protection Capacity
Flexible Plans and Protection Capacity Add-ons
Two basic plans are provided: Essential and Premium. You can purchase additional protection capacity add-on(s) based on business needs to extend protection capacity or cover more regions. For details, see Billing Overview. Tiered Protection Capacity
Depending on the bound plan, three tiers of protection capacity are provided: Standard Protection, Advanced Protection, and Ultimate Protection, covering protection needs of different scales. For details, see DDoS Protection Capacity Description. Convenient Resource Binding
One-Click Protection Resource Association
You can quickly associate protected resources with protection instances to obtain DDoS Defender capabilities for specific resources.
Security Operations and Observability
Attack and Business Analysis
DDoS Defender provides multi-dimensional statistical reports that clearly display attack traffic, protection effectiveness, and business traffic trends, helping you stay informed of attack situations in real time.
Unblocking Center
When your business is blocked due to an attack, you can unblock it yourself through the unblocking center.
Why Choose DDoS Defender
1. Attack scale continues to grow, and traditional protection bandwidth struggles to cope: DDoS attack traffic has grown from dozens of Gbps in the early days to the Tbps level. DDoS Defender provides large-scale attack protection capabilities. Regions outside the Chinese mainland provide highly elastic protection based on the Anycast architecture, while regions within the Chinese mainland can elastically scale to the Tbps level through protection capacity add-on, handling large-scale attacks with ease.
2. Attack methods are diverse, and both the network layer and the application layer require protection capabilities: In addition to traditional traffic-based attacks, CC attacks targeting the application layer are becoming increasingly frequent. DDoS Defender provides complete L3/4 network-layer protection capabilities (capacity + policy configuration), and provides protection capacity support for L7 DDoS (CC) application-layer attacks. Combined with EdgeOne (EO) policy configuration capabilities, they form a complete multi-layer protection system.
3. Security incident response is delayed, and real-time observability is lacking: DDoS Defender provides security operations capabilities such as attack analysis, alarm notification, and the unblocking center, helping you stay informed and respond quickly when attacks occur, avoiding expanded business impact caused by information delays.
4. Complex procurement and access processes, and high Ops costs: DDoS Defender adopts package-based billing, and you can use it immediately after purchasing and binding the resources that need protection. You can also purchase additional protection capacity add-on(s) on demand later, without the need for re-procurement or migration.