Attack Mitigation
How XDP filtering works, the attack zoo, and what to do during an incident.
- How XDP filtering worksHow OpenShield-XDP drops attack traffic at the NIC driver hook: the packet path, baseline spike detection, the eBPF maps, and why false positives stay low.
- Attack types explainedSYN and UDP floods, DNS/NTP/memcached amplification, ACK/RST and ICMP floods, carpet-bombing, and L7 HTTP attacks — and which product stops each.
- Reading attack logs and forensicsWhere attack history, timelines, and forensics live in the console, what each attack record field means, and how to tell a real attack from a traffic spike.
- During an attack: what to doA calm runbook for a live attack: confirm mitigation in the console, keep agent state, verify real traffic passes, whitelist critical IPs, and escalate.