Minecraft DDoS Protection and Nullping Protection

Published on Updated on 5 min read

Nullping attacks need barely any bandwidth and still take down entire BungeeCord networks. How the attack works and how it gets filtered out in real time.

Large Minecraft projects are a preferred target for attackers: from classic high-volume DDoS attacks to packet crash exploits such as the nullping attack, which is meant to bring down an entire BungeeCord network. DDoS protection from KernelHost is built for exactly these patterns and filters them in real time, before they ever reach the Minecraft process.

Why Minecraft servers are attacked so often

Minecraft and Minecraft Bedrock still make up the largest game server population of any title. Where the most servers run, the incentive to attack is highest as well: competing networks, banned players or plain boredom mean that a growing project will sooner or later come under fire.

And it has long stopped being only about bandwidth. Next to volumetric floods, a whole set of methods has established itself that deliberately abuses the protocol logic of Minecraft: nullping attacks, QuietException attacks and various (fake) handshake floods. They get by with comparatively little traffic and still crash an unprotected server. For the technical background on what a DDoS attack actually is, see the article What is a DDoS attack?.

What is a nullping attack?

The nullping attack is a form of attack tailored specifically to Minecraft. Instead of flooding the line, it abuses the connection setup: the attacker sends manipulated status and handshake packets in bulk, and the server has to answer every one of them. In the server list the ping then shows up close to zero, while in the background the server process suffocates under the flood of packets.

Players notice the consequences first: actions arrive late or not at all, connections drop, and in the worst case the proxy of the network crashes outright. Because the forged packets look like legitimate client requests at first glance, basic on-board tools can hardly tell them apart from real players.

Why plugins and firewalls alone are not enough

Rate limits in a plugin or iptables rules on the server only take effect once the packets have already reached the machine. For small attacks that is enough, but with a serious attack the connectivity is saturated long before that, or the CPU is already busy dropping traffic. The only thing that really works is filtering upstream in the network, by a system that knows the protocol behavior and discards the fake packets before they arrive.

How KernelHost protects Minecraft servers

DDoS protection from KernelHost is built in two layers and is permanently active, without you having to configure anything:

  • Layer 1: global filtering capacity of 17 Tbps. Volumetric attacks are intercepted close to their source, before they reach the datacenter in Frankfurt.
  • Layer 2: Arbor real-time filtering with 3.2 Tbps on site in Frankfurt. Directly in front of the server, protocol-specific patterns are detected and discarded, among them nullping, QuietException and handshake floods.

Protected are Java Edition (port 25565 TCP) and Bedrock Edition (port 19132 UDP), as well as proxies, voice services and any TCP or UDP services of your own on other ports. No null-routing is used: the IP under attack stays in the network, only the malicious packets are dropped. The protection is included free of charge with every server package, the standard plans state 3.2 Tbps, the Professional plans 17 Tbps.

For very large networks, the Professional Dedicated Server range is the right fit. For partnerships with large projects, noticeable price reductions are possible, so simply talk to us via ticket. An overview of all covered titles is given in the article Game server DDoS protection in real time.

Real cases from live operation

The following attacks were filtered in real time on KernelHost servers, in each case without downtime for the customer. The screenshots come from the live monitoring of the mitigation platform.

TeamSpeak 3 voice server, port 9987 UDP

Complex attack with several attack patterns at the same time, more than 473.4 Gbps and more than 41.5 million packets per second. Filtered completely in real time, without any outage.

KernelHost DDoS mitigation: TeamSpeak voice server on port 9987 UDP, more than 473 Gbps filtered in real time

ARK game server, port 7777 UDP

Plain UDP flood without any complex structure, but with more than 112.2 Gbps and more than 8.7 million packets per second. Filtered in real time, without downtime.

KernelHost DDoS mitigation: ARK game server on port 7777 UDP, more than 112 Gbps UDP flood filtered in real time

All-port attack, ports 0-65535 TCP/UDP

More than 12 different main attack patterns against all ports at once, in total more than 21.3 Gbps and more than 3.9 million packets per second. Likewise filtered completely in real time.

KernelHost DDoS mitigation: complex all-port attack across all ports 0-65535 filtered in real time

Minecraft and OpenVPN, ports 25565 TCP and 1194 UDP

Combined attack with more than 16 different main attack patterns, more than 4 million packets per second and more than 8.6 Gbps. Both services stayed reachable without interruption.

KernelHost DDoS mitigation: Minecraft server on port 25565 TCP and OpenVPN on 1194 UDP filtered in real time

Is your server under attack right now?

If your project already runs at KernelHost, the filtering is permanently active and there is nothing for you to switch on. If you still notice something unusual, open a support ticket so our team can fine-tune the filter rules for your IP. During an ongoing attack you can also reach us on the WhatsApp emergency chat at +43 650 8209883.

Frequently asked questions

What is a nullping attack?
An attack tailored to Minecraft that sends manipulated status and handshake packets in bulk. In the server list the ping appears close to zero, while the server process suffocates under the flood of packets.
Are plugins and iptables enough against nullping?
For small attacks yes, for serious ones no. Both only take effect once the packets have already reached the server. What works is filtering upstream in the network, by a system that knows the protocol behavior.
Are Java Edition and Bedrock protected equally?
Yes. Java Edition on port 25565 TCP and Bedrock Edition on port 19132 UDP are protected, as are proxies such as BungeeCord and any services of your own on other ports.
Does my server go offline during an attack?
No. KernelHost does not take attacked IP addresses out of the network. Only the malicious packets are discarded, and the connections of real players keep running.
Does Minecraft DDoS protection cost extra?
No, it is included with every server package and permanently active. The standard plans state 3.2 Tbps, the Professional plans 17 Tbps.

Minecraft DDoS protection Nullping protection Packet crasher BungeeCord protection Minecraft server Bedrock Edition Real-time filtering