Hytale server: DDoS protection and help during attacks

Published on Updated on 3 min read

Hytale communicates over QUIC and UDP, not over TCP like Minecraft. What that means for DDoS mitigation and how to proceed when an attack hits.

Do you run a Hytale server and want it to stay reachable even while it is under fire? DDoS protection has top priority at KernelHost and is permanently active in every server package, at no extra cost and with nothing to set up.

Why Hytale needs its own filtering logic

Hytale uses a different network protocol than Minecraft. While Minecraft Java Edition communicates primarily over TCP, Hytale relies heavily on the QUIC protocol over UDP (usually on port 5520). That delivers fast connections and smooth gameplay, but it asks something different of DDoS mitigation.

QUIC encrypts large parts of the connection setup. That is good for privacy, but it makes telling real players apart from forged connection attempts far more demanding: a filter cannot simply read the plaintext of the handshake. On top of that, UDP is connectionless, so source addresses are easy to spoof. Taken together, both properties turn Hytale servers into an attractive target for UDP floods and connection flood attacks. The basics are covered in the article What is a DDoS attack?.

How KernelHost protects your Hytale server

DDoS protection at KernelHost is built in two layers and is active around the clock:

  • Layer 1: 17 Tbps of global filtering capacity. Volumetric attacks are absorbed close to their source, before they ever reach the datacenter in Frankfurt am Main.
  • Layer 2: 3.2 Tbps of Arbor real-time filtering on site in Frankfurt. Directly in front of the server, protocol-specific patterns are identified and packets are dropped one by one.

Attacked IP addresses are never taken off the network: no null-routing means your players can keep playing while the attack is filtered in the background. Depending on the intensity and the type of attack, fine-tuning the filter profiles can be worthwhile so that not a single real player gets blocked. That is exactly what our network team is here for.

To see how filtering works for other game titles, read the article Real-time DDoS protection for game servers.

What to do when you are under attack right now

If you notice dropped connections, high ping or timeouts on your Hytale server that point to a DDoS attack, please get in touch with us straight away. We will then activate and tune the Hytale-specific filter profiles for your IP address.

  1. Log in to the customer panel.
  2. Open "Support" and then "Tickets".
  3. Create a new ticket with the subject "Hytale DDoS attack".
  4. State the IP address of the affected server, along with the port and the time you first noticed something unusual.

Our network engineers analyze the traffic and adjust the protection rules so that the attack is filtered and your server stays reachable for players. While an attack is running, you can also reach us through the WhatsApp emergency chat at +43 650 8209883.

Open a support ticket

Frequently asked questions

Why is DDoS mitigation different for Hytale than for Minecraft?
Hytale uses QUIC over UDP, usually on port 5520. The connection setup is encrypted and UDP allows spoofed source addresses, so the filtering needs profiles of its own.
Is protection for Hytale servers included in the price?
Yes. DDoS protection is permanently active in every server package and included at no cost, with no separate protection package and no setup fee.
What do I do during an ongoing attack?
Open a ticket in the customer panel with the subject Hytale DDoS attack and state the IP, the port and the time. In urgent cases you can also reach us through the WhatsApp emergency chat at +43 650 8209883.
Do real players get blocked during an attack?
The goal is exactly the opposite. That is why we tune the filter profiles per IP whenever needed, so that only the malicious traffic is dropped.

Hytale server Hytale DDoS protection QUIC UDP flood DDoS protection game server protection real-time filtering