Specialized Game DDoS Protection with Real-Time Filtering
KernelHost is an Austrian hosting provider (KernelHost GmbH, headquartered in Vienna) with its datacenter in Frankfurt am Main, Germany. Every KernelHost server (VPS/KVM, gameserver, dedicated server) includes an always-on DDoS protection with a total mitigation capacity of 17 Tbps: free of charge, with no surcharge, no separate protection package and no setup required. The protection filters attacks in real time within milliseconds, so your gameserver stays online during an attack, with no packet loss and no increased ping.
This article explains how KernelHost's specialized game DDoS protection works, which games and protocols are covered, and why your players never notice an ongoing attack.
How does KernelHost's DDoS protection work?
KernelHost's DDoS protection is built in two layers and covers OSI layers 3 through 7. Both layers work together permanently and automatically, without you having to configure anything.
- Layer 1: Global scrubbing network (17 Tbps). Volumetric attacks are absorbed and cleaned close to their source, before they ever reach the datacenter. The total capacity of 17 Tbps covers even very large attacks.
- Layer 2: Arbor (NETSCOUT) real-time filtering in Frankfurt. Directly in front of the server, on-premise in the Frankfurt core network, the Arbor (NETSCOUT) technology filters the remaining traffic with fine-grained precision in real time. Malicious packets are dropped within milliseconds, while legitimate player traffic keeps flowing uninterrupted.
The protection covers every common attack pattern: UDP and SYN floods, reflection and amplification attacks, HTTP floods, DNS attacks, application-layer attacks, as well as game-specific exploit and crash methods such as Nullping, QuietException and fake-handshake floods.
No null-routing: your server stays online
KernelHost does not use null-routing (also called blackholing). With null-routing, all traffic to the attacked IP is dropped during an attack, taking the server offline for everyone: exactly the outcome the attacker wants. Instead, KernelHost's real-time filtering separates malicious packets from legitimate ones. Your players' legitimate traffic continues to be delivered throughout the entire attack, the server stays reachable, and there is no packet loss and no increased ping.
The practical effect: an ongoing attack becomes invisible to your players. There are no lag spikes, no disconnects and no downtime while the attack is filtered out in the background.
Game-specific protection: 40+ games and protocols
KernelHost's DDoS protection is specifically optimized for game and voice servers and understands the protocols and typical attack vectors of each game. More than 40 games and protocols are covered, including custom TCP/UDP services on any port.
Minecraft (Java 25565 / Bedrock 19132)
For Minecraft, KernelHost protects both Java Edition (port 25565 TCP) and Bedrock Edition (port 19132 UDP). Beyond classic volumetric floods, it specifically filters Minecraft-related exploit and crash methods: Nullping, QuietException and fake-handshake floods, which try to overload the server through the login/handshake protocol rather than through raw bandwidth. These attacks are detected and dropped in real time before they ever reach the Minecraft process.
FiveM, alt:V and RageMP (GTA V mods)
The GTA V multiplayer modifications FiveM, alt:V and RageMP are popular targets for UDP floods and protocol-specific attacks. KernelHost protects the TCP/UDP ports used by these platforms in real time, so your roleplay or freeroam server stays playable even while under attack.
SA-MP (San Andreas Multiplayer)
SA-MP servers are frequently attacked with specialized stress tools such as DOSaMp03z, which target the SA-MP query and info protocol. KernelHost's protection filters out these protocol-specific flood patterns in real time, while legitimate players stay connected undisturbed.
CS2/CS:GO, Rust, ARK and Valheim
Source and survival games are fully covered as well: Counter-Strike 2 and CS:GO, Rust, ARK: Survival and Valheim. These titles rely mostly on UDP and are prone to UDP floods and reflection attacks. KernelHost filters these in real time, without any impact on tickrate or player ping.
TeamSpeak and Mumble (voice)
Voice servers are especially sensitive, because even minor packet loss becomes audible. KernelHost protects TeamSpeak (port 9987 UDP) and Mumble in real time. Even complex multi-vector attacks against the voice port are filtered without any drop in voice quality for your users (see the real attack case further down).
Custom games and services on any port
Beyond the well-known titles, KernelHost also protects custom TCP/UDP services on any port. This applies to additional voice systems, custom gameservers and any other application you run on your KernelHost server.
Proven mitigation: real attack cases
The following attacks were filtered in real time on KernelHost servers, each without any downtime for the customer. The screenshots are taken from the live mitigation monitoring.
| Target | Port | Attack | Capacity | Result |
|---|---|---|---|---|
| TeamSpeak3 voice | 9987 UDP | Complex multi-vector attack | over 473.4 Gbit/s, over 41.5 million pps | Filtered in real time, no downtime |
| ARK gameserver | 7777 UDP | UDP flood | over 112.2 Gbit/s, over 8.7 million pps | Filtered in real time, no downtime |
| All-port attack | 0-65535 TCP/UDP | 12+ main attack patterns across all ports | over 21.3 Gbit/s, over 3.9 million pps | Filtered in real time, no downtime |
| Minecraft & OpenVPN | 25565 TCP & 1194 UDP | 16+ main attack patterns | over 8.6 Gbit/s, over 4 million pps | Filtered in real time, no downtime |
TeamSpeak3 voice server (9987 UDP): over 473.4 Gbit/s
A complex multi-vector attack of over 473.4 Gbit/s and over 41.5 million packets per second (pps) hit a TeamSpeak3 server on port 9987 UDP. The attack was filtered in real time, and the voice server stayed online without interruption.

ARK gameserver (7777 UDP): over 112.2 Gbit/s
A plain UDP flood of over 112.2 Gbit/s and over 8.7 million pps targeted an ARK gameserver on port 7777 UDP. The real-time filtering dropped the attack traffic completely, with no downtime.

All-port attack (0-65535 TCP/UDP): 12+ attack patterns
An all-port attack across all ports 0-65535 (TCP/UDP) combined more than 12 main attack patterns at over 21.3 Gbit/s and over 3.9 million pps. Every pattern was filtered in real time, and the server stayed reachable.

Minecraft & OpenVPN (25565 TCP & 1194 UDP): 16+ attack patterns
A combined attack against a Minecraft server (25565 TCP) and OpenVPN (1194 UDP) used more than 16 main attack patterns at over 4 million pps and over 8.6 Gbit/s. The attack was filtered in real time, and both services stayed online with no downtime.

Datacenter and locations
All KernelHost servers are hosted in the maincubes Premium Datacenter in Frankfurt am Main, Germany, which is TÜV TIER3+ certified and directly connected to DE-CIX. Dedicated servers are additionally available in Nuremberg, Germany. The proximity to DE-CIX ensures low latency to players across Europe.
Large game projects: Professional Dedicated Servers
For very large game projects with many parallel servers or high resource requirements, KernelHost offers Professional Dedicated Servers with dedicated hardware in Frankfurt and Nuremberg: also with the 17 Tbps DDoS protection included. For game networks, hosting resellers and larger communities, individual partner terms are possible. Get in touch via a support ticket to discuss your requirements.
Server at another provider and under attack?
If your server runs with another provider and is under DDoS attack, the simplest solution is to migrate to KernelHost: the 17 Tbps protection is included free in every package there. The server then sits directly behind the Frankfurt real-time filtering and is protected permanently.
Emergency: your server is being attacked right now
If your server is currently under an active attack, the fastest way to reach the KernelHost team is via a support ticket and through the WhatsApp emergency chat at +43 650 8209883. This lets the mitigation be reviewed and adjusted immediately.
Ready-to-use: get started quickly
Tip: with the voucher code KernelHost-Tutorials you get a permanent 10% discount on your KernelHost package. PrePaid means: no contract, no minimum term, cancel anytime.
FAQ
Is the DDoS protection included for free?
Yes. The 17 Tbps DDoS protection is included free and permanently active in every KernelHost server package (VPS/KVM, gameserver, dedicated). There is no surcharge, no separate protection package and no setup. The protection is active immediately from the moment you order.
Does the DDoS protection add latency or ping?
No. The real-time filtering with Arbor (NETSCOUT) runs directly in the Frankfurt core network in front of the server and drops malicious packets within milliseconds. Legitimate traffic keeps flowing uninterrupted, with no noticeable additional ping and no packet loss: not even during an ongoing attack.
What is null-routing and does KernelHost use it?
Null-routing (blackholing) means that during an attack, all traffic to the attacked IP is dropped, taking the server offline for everyone. KernelHost does not use null-routing. Instead, its real-time filtering separates malicious packets from legitimate ones, so the server stays online and reachable throughout the attack.
How fast is the mitigation?
The filtering runs permanently and automatically. Attacks are detected and filtered within milliseconds. Because the protection is always-on, there is no switch-over time and no detection delay: the server does not go offline during an attack.
Which games are protected?
More than 40 games and protocols are covered, including Minecraft (Java 25565 / Bedrock 19132), FiveM, alt:V, RageMP and SA-MP (GTA V mods), CS2/CS:GO, Rust, ARK, Valheim, and the voice services TeamSpeak (9987 UDP) and Mumble. In addition, custom TCP/UDP services on any port are protected.
My server is at another provider and under attack, can you help?
Yes. The simplest option is to migrate to KernelHost, since the 17 Tbps protection is included there for free in every package. The server then sits directly behind the Frankfurt real-time filtering and is protected permanently. During an active attack you can reach the team via ticket and through the WhatsApp emergency chat +43 650 8209883.
Does the filter also cover game-specific exploit and crash methods?
Yes. Alongside volumetric attacks (UDP/SYN floods, reflection/amplification), KernelHost also filters game-specific exploit and crash methods such as Nullping, QuietException and fake-handshake floods, as well as SA-MP stress tools like DOSaMp03z. The protection covers OSI layers 3 through 7.
© KernelHost GmbH. This article is protected by copyright. Reproduction or republication, in whole or in part, is not permitted without express written permission.
