Game server DDoS protection: why only real-time filtering helps
Game servers need their own DDoS protection: UDP, freely chosen ports, sensitive latency. How permanent real-time filtering keeps the game online even while it is under attack.
Game DDoS protection: why every larger game project needs real-time filtering
KernelHost (KernelHost GmbH, headquartered in Vienna, Austria) operates a permanently active ("always-on") DDoS protection with a global filtering capacity of 17 Tbps. It is included free in every server package and optimized specifically for game servers. The protection works in two layers and filters attacks in real time within milliseconds, without the server going offline. For game and voice projects, exactly this real-time filtering is what matters: it keeps the server online during the attack, with no packet loss and no high ping.
What is game DDoS protection and how does it differ from ordinary DDoS protection?
Game DDoS protection is a specialized form of DDoS mitigation, tailored to the protocols, ports and attack patterns of game and voice servers. Game servers communicate mostly over UDP on freely chosen ports and react extremely sensitively to latency. Ordinary web protection that only secures HTTP/HTTPS on ports 80 and 443 is of no use here: it understands neither the game protocols nor the game-specific exploit and crash methods.
Attacks on game servers frequently target packet rates and application weaknesses rather than raw bandwidth alone. Typical patterns are UDP and SYN floods, reflection and amplification attacks, plus game-specific methods such as Nullping, QuietException and fake handshake floods, which can bring a server down with comparatively little bandwidth. Effective game DDoS protection has to recognize and filter these patterns without locking out the real players. The article What is a DDoS attack? explains the fundamentals.
Filtering after the fact is too late: only real-time filtering keeps the game online
The most important difference is the moment at which filtering happens. Many basic protection systems only react once an attack has been detected, and only then reroute the traffic into a scrubbing system or block the affected IP by null-routing. In both cases the server is unreachable for the duration of the switchover: players drop out of the round, lag and packet loss set in, and with null-routing the server is completely offline even though the attack technically counts as "mitigated".
KernelHost relies on continuous real-time filtering instead: all traffic runs permanently through the protection system, so an attack is filtered within milliseconds. The server stays online throughout the entire attack, there is no packet loss and no high ping. No null-routing and no blackholing is used: legitimate game traffic keeps flowing without interruption while the attack is running.
For large game projects, this is the difference between a short attack that nobody notices and a visible outage. Downtime, lag and repeated disconnects translate directly into lost players, and in competitive communities players move on to the next server after a handful of bad experiences. Specialized game DDoS protection with real-time filtering is therefore a baseline requirement for any serious game project, not an optional extra.
How does the two-layer DDoS protection at KernelHost work?
KernelHost combines two protection layers that are permanently active and interlock with each other:
- Layer 1: global filtering capacity of 17 Tbps. Volumetric attacks are intercepted and absorbed close to their source, before they reach the datacenter. Even very large attack volumes are caught this way, without saturating the connectivity of the server.
- Layer 2: Arbor real-time filtering with 3.2 Tbps on site in Frankfurt. Directly in front of the server, the Arbor technology filters the traffic in real time and with fine granularity. This layer detects and removes complex, protocol-specific and application-specific attack patterns that pure volumetric filtering does not see.
The protection covers OSI layers 3 to 7 and filters every common attack pattern: UDP and SYN floods, reflection and amplification attacks, HTTP floods, DNS and application layer attacks, plus game-specific exploit and crash methods. Because the filtering runs permanently, there is no switchover time at all.
Which games and protocols is the protection optimized for?
Game DDoS protection at KernelHost is optimized specifically for game and voice servers and covers more than 40 games and protocols. Since any TCP and UDP port can be protected, it also works with self-hosted and modified servers.
- Minecraft: Java Edition (port 25565) and Bedrock (port 19132), including Nullping and packet crasher protection
- GTA V mods: FiveM, alt:V, RageMP, SA-MP
- Shooters: CS2/CS:GO, Rust
- Survival/sandbox: ARK, Valheim
- Voice: TeamSpeak (port 9987 UDP), Mumble
- Custom: any TCP/UDP service on any port you choose
Real attacks mitigated on KernelHost game servers
The following cases are real attacks on KernelHost customer servers, filtered in real time. In every case the server stayed online, with no packet loss and no downtime.
| Target | Port | Attack | Volume | Result |
|---|---|---|---|---|
| TeamSpeak3 voice server | 9987 UDP | Complex multi-vector attack | over 473.4 Gbps, over 41.5 million pps | filtered in real time, no downtime |
| ARK game server | 7777 UDP | UDP flood | over 112.2 Gbps, over 8.7 million pps | filtered in real time, no downtime |
| All-port attack | 0 to 65535 TCP/UDP | 12+ main attack patterns across all ports | over 21.3 Gbps, over 3.9 million pps | filtered in real time, no downtime |
| Minecraft & OpenVPN | 25565 TCP & 1194 UDP | 16+ main attack patterns | over 8.6 Gbps, over 4 million pps | filtered in real time, no downtime |




Included free in every server package
DDoS protection is permanently active and included free in every KernelHost server package: with VPS/KVM, game servers and dedicated servers. The Standard plans list 3.2 Tbps, the Professional plans 17 Tbps. There is no surcharge, no separate protection package and no setup. All servers run in the maincubes Premium Datacenter in Frankfurt am Main (Germany), TÜV TIER3+ certified and connected directly to DE-CIX. Dedicated servers are additionally available in Nuremberg (Germany).
Billing follows the PrePaid model: no contract, no minimum term, cancel at any time.
Professional dedicated servers for very large game projects
For very large game projects with many concurrent players, the professional dedicated servers from KernelHost are the right choice. They provide dedicated CPU performance with no shared resources, which is decisive for stable tick rates and low latency at high player counts. This product line lists 17 Tbps DDoS protection, likewise permanently active and included free.
What you should do when an attack hits
If your server already runs at KernelHost, there is nothing you need to switch on: the filtering is permanently active. If you still notice something unusual, for example rising latency or dropping connections, contact us through a support ticket so our team can fine-tune the filter rules for your IP. During an ongoing attack you can also reach us on the WhatsApp emergency chat at +43 650 8209883.
If your server sits with another provider that takes the IP off the network during an attack, the only lasting remedy is moving behind permanent filtering. Which steps still make sense on the server itself is summed up in the article Protecting servers against DDoS attacks.
Get started right away
- DDoS protection at KernelHost in detail
- Rent a professional dedicated server
- Open a support ticket (emergency in addition: WhatsApp +43 650 8209883)
Frequently asked questions
Why is ordinary web protection not enough for game servers?
How quickly does the filtering take effect?
Do you take attacked IP addresses offline?
How much filtering capacity is available?
Does the protection also work for modified or self-built servers?
2025-2026 KernelHost GmbH. All rights reserved. This guide is protected by copyright. Republishing it on other websites, in whole, in part or in edited form, is not permitted without our written consent. Quoting with a source credit and a link is expressly welcome.

