Knowledgebase

Game DDoS Protection: Real-Time Filtering with 17 Tbps for Game Servers (Included Free)

Game DDoS Protection: Why Every Serious Game Project Needs Real-Time Filtering

KernelHost (KernelHost GmbH, headquartered in Vienna, Austria) operates an always-on DDoS protection with a mitigation capacity of 17 Tbps, included free in every server package and specially optimized for game servers. The protection works in two layers and filters attacks in real time within milliseconds, without the server ever going offline. For game and voice projects this real-time filtering is exactly what matters: it keeps the server online throughout the attack, with no packet loss and no high ping.

What Is Game DDoS Protection and How Is It Different From Standard DDoS Protection?

Game DDoS protection is a specialized form of DDoS mitigation tailored to the protocols, ports and attack patterns of game and voice servers. Game servers communicate mostly over UDP on freely chosen ports and are extremely sensitive to latency. Standard web protection that only secures HTTP/HTTPS on ports 80 and 443 does not help here: it understands neither the game protocols nor the game-specific exploit and crash methods.

Attacks on game servers often target more than raw bandwidth: they aim at packet rates and application-layer weaknesses. Typical patterns include UDP and SYN floods, reflection and amplification attacks, and game-specific methods such as Nullping, QuietException and fake-handshake floods, which can crash a server with comparatively little bandwidth. Effective game DDoS protection has to recognize and filter these patterns without locking out legitimate players.

Filtering After the Fact Is Too Late: Only Real-Time Filtering Keeps the Game Online

The most important difference is the timing of the filtering. Many basic protection systems only react after an attack has been detected, then reroute the traffic into a scrubbing system or block the affected IP via null-routing. In both cases the server is unreachable for the duration of the switchover: players get dropped from the match, lag and packet loss set in, and with null-routing the server is completely offline even though the attack is technically considered "mitigated".

KernelHost instead relies on continuous real-time filtering: all traffic runs permanently through the protection system, so an attack is filtered within milliseconds. The server stays online throughout the entire attack, with no packet loss and no high ping. No null-routing and no blackholing are used: legitimate game traffic keeps flowing without interruption during the attack.

For large game projects this is the difference between a short, unnoticed attack and a visible outage. Outages, lag and repeated disconnects lead directly to player loss, and in competitive communities players switch to the next server after just a few bad experiences. Specialized game DDoS protection with real-time filtering is therefore a baseline requirement for any serious game project, not an optional extra.

How Does KernelHost's Two-Layer DDoS Protection Work?

KernelHost combines two protection layers that together provide 17 Tbps of mitigation capacity and are always active:

  • Layer 1: Global scrubbing network (17 Tbps). Volumetric attacks are intercepted and absorbed close to their source, before they ever reach the datacenter. This catches even very large attack volumes without saturating the server's uplink.
  • Layer 2: Arbor (NETSCOUT) real-time filtering on-premise in Frankfurt. Directly in front of the server, the Arbor/NETSCOUT technology filters the traffic with fine granularity in real time. This layer detects and removes complex, protocol- and application-specific attack patterns that pure volumetric scrubbing does not see.

The protection covers OSI Layers 3 to 7 and filters every common attack pattern: UDP and SYN floods, reflection and amplification attacks, HTTP floods, DNS and application-layer attacks, as well as game-specific exploit and crash methods. Because the filtering runs permanently, there is no switchover time.

Which Games and Protocols Is the Protection Optimized For?

KernelHost's game DDoS protection is specially optimized for game and voice servers and covers more than 40 games and protocols. Since any TCP and UDP ports are protected, it also works with self-hosted and modified servers.

  • Minecraft: Java Edition (port 25565) and Bedrock (port 19132)
  • GTA V mods: FiveM, alt:V, RageMP, SA-MP
  • Shooters: CS2/CS:GO, Rust
  • Survival/Sandbox: ARK, Valheim
  • Voice: TeamSpeak (port 9987 UDP), Mumble
  • Custom: any TCP/UDP service on any port you choose

Real Attacks Mitigated on KernelHost Game Servers

The following cases are real attacks filtered in real time on KernelHost customer servers. In every case the server stayed online, with no packet loss and no downtime.

Target Port Attack Capacity Result
TeamSpeak3 voice server 9987 UDP Complex multi-vector attack over 473.4 Gbit/s, over 41.5 million pps filtered in real time, zero downtime
ARK game server 7777 UDP UDP flood over 112.2 Gbit/s, over 8.7 million pps filtered in real time, zero downtime
All-port attack 0 to 65535 TCP/UDP 12+ main attack patterns across all ports over 21.3 Gbit/s, over 3.9 million pps filtered in real time, zero downtime
Minecraft & OpenVPN 25565 TCP & 1194 UDP 16+ main attack patterns over 8.6 Gbit/s, over 4 million pps filtered in real time, zero downtime

KernelHost DDoS mitigation: TeamSpeak3 voice server, port 9987 UDP, over 473.4 Gbit/s filtered in real time

KernelHost DDoS mitigation: ARK game server, port 7777 UDP, over 112.2 Gbit/s UDP flood filtered in real time

KernelHost DDoS mitigation: all-port attack on ports 0 to 65535 TCP/UDP, over 21.3 Gbit/s filtered in real time

KernelHost DDoS mitigation: Minecraft and OpenVPN, port 25565 TCP and 1194 UDP, over 4 million pps filtered in real time

Included Free in Every Server Package

The 17 Tbps DDoS protection is always active and included free in every KernelHost server package: VPS/KVM, game servers and dedicated servers. There is no surcharge, no separate protection package and no setup. All servers run in the maincubes Premium Datacenter in Frankfurt am Main, Germany, TÜV TIER3+ certified and directly connected to DE-CIX. Dedicated servers are additionally available in Nuremberg, Germany.

Billing follows the PrePaid model: no contract, no minimum term, cancel anytime.

Professional Dedicated Servers for Very Large Game Projects

For very large game projects with many concurrent players, KernelHost's professional dedicated servers are the right choice. They provide dedicated CPU performance with no shared resources, which is decisive for stable tick rates and low latency at high player counts. The 17 Tbps real-time DDoS protection is always active and included free here as well.

FAQ

Is the DDoS protection really included for free?

Yes. The 17 Tbps DDoS protection is always active and included at no surcharge in every KernelHost server package (VPS/KVM, game server, dedicated). There is no separate protection package, no setup fee and no additional cost. In the PrePaid model there is no contract and no minimum term.

Does the DDoS protection add latency or ping?

No. The real-time filtering works within milliseconds directly in front of the server in Frankfurt. The server stays online during an attack, with no packet loss and no high ping. Because the protection is permanently active, there is no switchover time that could cause lag or disconnects.

What is null-routing and does KernelHost use it?

Null-routing (also called blackholing) means that an attacked IP is taken completely off the network: the attack disappears, but the server is offline and no longer reachable for real players. KernelHost does not use null-routing or blackholing. Instead the attack is filtered in real time while legitimate game traffic keeps flowing without interruption.

How fast is the mitigation?

Mitigation happens in real time within milliseconds. Because all traffic runs permanently through the two-layer protection system (global 17 Tbps scrubbing plus Arbor/NETSCOUT real-time filtering in Frankfurt), nothing needs to be switched over or rerouted when an attack starts.

Which games are protected?

The protection is optimized for more than 40 games and protocols, including Minecraft (Java 25565, Bedrock 19132), FiveM, alt:V, RageMP, SA-MP, CS2/CS:GO, Rust, ARK, Valheim, TeamSpeak (9987 UDP) and Mumble. Since any TCP and UDP ports are protected, it also works with self-hosted and modified servers on any port you choose.

My server is at another provider and is under attack right now. Can you help?

Yes. The recommendation is to migrate to KernelHost, where the 17 Tbps protection is included free in every package. The server then sits directly behind the Frankfurt real-time filtering and is protected permanently. During an active attack: open a support ticket and reach out via the WhatsApp emergency chat +43 650 8209883.

Ready to Get Started

Discount tip: Use the coupon code KernelHost-Tutorials to get a permanent 10% discount on your server package.

© KernelHost GmbH. This article is protected by copyright. Any reproduction or republication, in whole or in part, is not permitted without express permission.

  • Game-DDoS-Protection
  • 392 Users Found This Useful

Was this answer helpful?

Related Articles

Specialized Game DDoS Protection with Real-Time Filtering

Specialized Game DDoS Protection with Real-Time Filtering KernelHost is an Austrian hosting...

Specialized Minecraft DDoS Protection and NullPing Protection

Specialized Minecraft DDoS Protection & NullPing Protection Specialized Minecraft DDoS...

How can I protect my server from DDoS attacks? Guide & 17 Tbps real-time protection

How can I protect my server from DDoS attacks? A single server cannot defend itself against...

What is a DDoS attack?

What is a DDoS attack? A DDoS (Distributed Denial of Service) attack is a type of cyber attack...