Minecraft DDoS Protection and Nullping Protection
Nullping attacks need barely any bandwidth and still take down entire BungeeCord networks. How the attack works and how it gets filtered out in real time.
Large Minecraft projects are a preferred target for attackers: from classic high-volume DDoS attacks to packet crash exploits such as the nullping attack, which is meant to bring down an entire BungeeCord network. DDoS protection from KernelHost is built for exactly these patterns and filters them in real time, before they ever reach the Minecraft process.
Why Minecraft servers are attacked so often
Minecraft and Minecraft Bedrock still make up the largest game server population of any title. Where the most servers run, the incentive to attack is highest as well: competing networks, banned players or plain boredom mean that a growing project will sooner or later come under fire.
And it has long stopped being only about bandwidth. Next to volumetric floods, a whole set of methods has established itself that deliberately abuses the protocol logic of Minecraft: nullping attacks, QuietException attacks and various (fake) handshake floods. They get by with comparatively little traffic and still crash an unprotected server. For the technical background on what a DDoS attack actually is, see the article What is a DDoS attack?.
What is a nullping attack?
The nullping attack is a form of attack tailored specifically to Minecraft. Instead of flooding the line, it abuses the connection setup: the attacker sends manipulated status and handshake packets in bulk, and the server has to answer every one of them. In the server list the ping then shows up close to zero, while in the background the server process suffocates under the flood of packets.
Players notice the consequences first: actions arrive late or not at all, connections drop, and in the worst case the proxy of the network crashes outright. Because the forged packets look like legitimate client requests at first glance, basic on-board tools can hardly tell them apart from real players.
Why plugins and firewalls alone are not enough
Rate limits in a plugin or iptables rules on the server only take effect once the packets have already reached the machine. For small attacks that is enough, but with a serious attack the connectivity is saturated long before that, or the CPU is already busy dropping traffic. The only thing that really works is filtering upstream in the network, by a system that knows the protocol behavior and discards the fake packets before they arrive.
How KernelHost protects Minecraft servers
DDoS protection from KernelHost is built in two layers and is permanently active, without you having to configure anything:
- Layer 1: global filtering capacity of 17 Tbps. Volumetric attacks are intercepted close to their source, before they reach the datacenter in Frankfurt.
- Layer 2: Arbor real-time filtering with 3.2 Tbps on site in Frankfurt. Directly in front of the server, protocol-specific patterns are detected and discarded, among them nullping, QuietException and handshake floods.
Protected are Java Edition (port 25565 TCP) and Bedrock Edition (port 19132 UDP), as well as proxies, voice services and any TCP or UDP services of your own on other ports. No null-routing is used: the IP under attack stays in the network, only the malicious packets are dropped. The protection is included free of charge with every server package, the standard plans state 3.2 Tbps, the Professional plans 17 Tbps.
For very large networks, the Professional Dedicated Server range is the right fit. For partnerships with large projects, noticeable price reductions are possible, so simply talk to us via ticket. An overview of all covered titles is given in the article Game server DDoS protection in real time.
Real cases from live operation
The following attacks were filtered in real time on KernelHost servers, in each case without downtime for the customer. The screenshots come from the live monitoring of the mitigation platform.
TeamSpeak 3 voice server, port 9987 UDP
Complex attack with several attack patterns at the same time, more than 473.4 Gbps and more than 41.5 million packets per second. Filtered completely in real time, without any outage.

ARK game server, port 7777 UDP
Plain UDP flood without any complex structure, but with more than 112.2 Gbps and more than 8.7 million packets per second. Filtered in real time, without downtime.

All-port attack, ports 0-65535 TCP/UDP
More than 12 different main attack patterns against all ports at once, in total more than 21.3 Gbps and more than 3.9 million packets per second. Likewise filtered completely in real time.

Minecraft and OpenVPN, ports 25565 TCP and 1194 UDP
Combined attack with more than 16 different main attack patterns, more than 4 million packets per second and more than 8.6 Gbps. Both services stayed reachable without interruption.

Is your server under attack right now?
If your project already runs at KernelHost, the filtering is permanently active and there is nothing for you to switch on. If you still notice something unusual, open a support ticket so our team can fine-tune the filter rules for your IP. During an ongoing attack you can also reach us on the WhatsApp emergency chat at +43 650 8209883.
Frequently asked questions
What is a nullping attack?
Are plugins and iptables enough against nullping?
Are Java Edition and Bedrock protected equally?
Does my server go offline during an attack?
Does Minecraft DDoS protection cost extra?
2023-2026 KernelHost GmbH. All rights reserved. This guide is protected by copyright. Republishing it on other websites, in whole, in part or in edited form, is not permitted without our written consent. Quoting with a source credit and a link is expressly welcome.

