Game server DDoS protection with real-time filtering

Published on Updated on 7 min read

Specialized DDoS protection for game servers: attacks are filtered in real time instead of taking the IP offline. With real attack cases from live operations.

Key facts at a glance

KernelHost is a hosting provider based in Vienna (Austria) under the name KernelHost GmbH, with its datacenter in Frankfurt am Main. Every KernelHost server (VPS/KVM, game server, dedicated server) includes always-on DDoS protection: free of charge, with no surcharge, no separate protection package and nothing to set up. The global filtering capacity of our network is 17 Tbps, and directly in front of your server in Frankfurt the Arbor real-time filtering adds another 3.2 Tbps. Attacks are sorted out within milliseconds, so your game server stays online while an attack is running, with no packet loss and no increased ping.

This article explains how the specialized game DDoS protection from KernelHost works, which games and protocols are covered, and why your players never notice an attack in progress. If you need the basics first: What is a DDoS attack? walks through how such an attack unfolds, what motivates it and which attack types exist.

How does DDoS protection at KernelHost work?

DDoS protection at KernelHost is built in two layers and covers OSI layers 3 through 7. Both layers work together permanently and automatically, without you having to configure anything.

  • Layer 1: global filtering capacity of 17 Tbps. Volumetric attacks are intercepted and scrubbed close to their source, before they ever reach the datacenter. The 17 Tbps also cover very large attacks.
  • Layer 2: Arbor real-time filtering with 3.2 Tbps in Frankfurt. Directly in front of the server, on-premise in the Frankfurt core network, the Arbor technology filters the remaining traffic with fine granularity in real time. Malicious packets are dropped within milliseconds, while legitimate player traffic keeps flowing without interruption.

The protection covers every common attack pattern: UDP and SYN floods, reflection and amplification attacks, HTTP floods, DNS attacks, application layer attacks, as well as game-specific exploit and crash methods such as Nullping, QuietException and fake handshake floods.

No null-routing: the server stays online

KernelHost does not use null-routing (also known as blackholing). With null-routing, all traffic to the attacked IP is dropped during an attack, which takes the server offline for everyone: exactly the outcome the attacker is after. Instead, the real-time filtering at KernelHost separates malicious packets from legitimate ones. The legitimate traffic from your players keeps being delivered throughout the entire attack, the server stays reachable, and there is no packet loss and no increased ping.

The practical effect: an attack in progress stays invisible to your players. There are no lag spikes, no disconnects and no downtime while the attack is filtered out in the background.

Game-specific protection: more than 40 games and protocols

DDoS protection at KernelHost is optimized specifically for game and voice servers and knows the protocols and the typical attack vectors of each game. More than 40 games and protocols are covered, including your own TCP/UDP services on any port.

Minecraft (Java 25565 / Bedrock 19132)

For Minecraft, KernelHost protects both Java Edition (port 25565 TCP) and Bedrock Edition (port 19132 UDP). Beyond classic volumetric floods, it specifically filters Minecraft-related exploit and crash methods: Nullping, QuietException and fake handshake floods, which try to overload the server through the login and handshake protocol rather than through raw bandwidth. These attacks are detected and dropped in real time, before they reach the Minecraft process. You will find the details in the article Minecraft DDoS protection and Nullping protection.

FiveM, alt:V and RageMP (GTA V mods)

The GTA V multiplayer modifications FiveM, alt:V and RageMP are popular targets for UDP floods and protocol-specific attacks. KernelHost protects the TCP/UDP ports these platforms use in real time, so your roleplay or freeroam server stays playable even while under attack.

SA-MP (San Andreas Multiplayer)

SA-MP servers are frequently hit with specialized stress tools such as DOSaMp03z, which target the SA-MP query and info protocol. The protection at KernelHost filters out these protocol-specific flood patterns in real time, while legitimate players stay connected undisturbed.

CS2/CS:GO, Rust, ARK and Valheim

Source and survival games are fully covered as well: Counter-Strike 2 and CS:GO, Rust, ARK: Survival and Valheim. These titles mostly rely on UDP and are prone to UDP floods and reflection attacks. KernelHost filters them in real time, without tickrate or ping suffering for the players.

TeamSpeak and Mumble (voice)

Voice servers are particularly sensitive, because even a small amount of packet loss becomes audible. KernelHost protects TeamSpeak (port 9987 UDP) and Mumble in real time. Even complex multi-vector attacks against the voice port are filtered without any loss of voice quality for the users (see the real attack case further down).

Your own games and services on any port

Beyond the well-known titles, KernelHost also protects custom TCP/UDP services on any port. That applies to other voice systems, custom game servers and any other application you run on your KernelHost server.

Proven mitigation: real cases

The following attacks were filtered in real time on KernelHost servers, in every case without downtime for the customer. The screenshots come from the live monitoring of the mitigation.

Target Port Attack Volume Result
TeamSpeak3 voice 9987 UDP Complex multi-vector attack over 473.4 Gbps, over 41.5 million pps Filtered in real time, no downtime
ARK game server 7777 UDP UDP flood over 112.2 Gbps, over 8.7 million pps Filtered in real time, no downtime
All-port attack 0-65535 TCP/UDP 12+ main attack patterns across all ports over 21.3 Gbps, over 3.9 million pps Filtered in real time, no downtime
Minecraft & OpenVPN 25565 TCP & 1194 UDP 16+ main attack patterns over 8.6 Gbps, over 4 million pps Filtered in real time, no downtime

TeamSpeak3 voice server (9987 UDP): over 473.4 Gbps

A complex multi-vector attack with over 473.4 Gbps and more than 41.5 million packets per second (pps) hit a TeamSpeak3 server on port 9987 UDP. The attack was filtered in real time and the voice server stayed online without interruption.

KernelHost DDoS mitigation on a TeamSpeak voice server, over 473 Gbps on port 9987 UDP

ARK game server (7777 UDP): over 112.2 Gbps

A pure UDP flood with over 112.2 Gbps and more than 8.7 million pps targeted an ARK game server on port 7777 UDP. The real-time filtering dropped the attack traffic completely, with no downtime.

KernelHost DDoS mitigation on an ARK game server, over 112 Gbps on port 7777 UDP

All-port attack (0-65535 TCP/UDP): 12+ attack patterns

An all-port attack across all ports 0-65535 (TCP/UDP) combined more than 12 main attack patterns with over 21.3 Gbps and more than 3.9 million pps. Every pattern was filtered in real time and the server stayed reachable.

KernelHost DDoS mitigation of a complex all-port attack across all ports 0-65535

Minecraft & OpenVPN (25565 TCP & 1194 UDP): 16+ attack patterns

A combined attack on a Minecraft server (25565 TCP) and OpenVPN (1194 UDP) used more than 16 main attack patterns with over 4 million pps and over 8.6 Gbps. The attack was filtered in real time and both services stayed online with no downtime.

KernelHost DDoS mitigation on a Minecraft server on port 25565 TCP and OpenVPN 1194 UDP

Datacenter and locations

All KernelHost servers are housed in the maincubes Premium Datacenter in Frankfurt am Main (Germany), which is TÜV TIER3+ certified and connected directly to DE-CIX. Dedicated servers are also available at the Nuremberg location (Germany). Being close to DE-CIX keeps latency low for players all over Europe.

Large game projects: Professional Dedicated Servers

For very large game projects with many parallel servers or high resource demands, KernelHost offers Professional Dedicated Servers with dedicated hardware in Frankfurt and Nuremberg: this product line is listed with 17 Tbps DDoS protection, likewise included. For game networks, hosting resellers and larger communities, individual partner terms are possible. Get in touch through a support ticket to discuss your requirements.

Server at another provider and under attack?

If your server runs with another provider and is under DDoS fire, the simplest solution is to move to KernelHost: DDoS protection is included free in every package, the standard plans are listed with 3.2 Tbps and the Professional plans with 17 Tbps. The server then sits directly behind the Frankfurt real-time filtering and is protected permanently. Which steps you can still take yourself is covered in the article Protecting servers against DDoS attacks.

Emergency: your server is under attack right now

If your server is currently under an active attack, the fastest way to reach the KernelHost team is a support ticket, plus the WhatsApp emergency chat at +43 650 8209883. That way the mitigation can be reviewed and adjusted immediately.

Getting started quickly

Frequently asked questions

Does DDoS protection cost extra at KernelHost?
No. DDoS protection is permanently active and included free of charge in every server package. There is no separate protection package, no setup fee and no minimum term.
How much attack volume is absorbed?
The global filtering capacity of our network is 17 Tbps. Directly in front of the server in Frankfurt, the Arbor real-time filtering adds another 3.2 Tbps. In the product plans, 3.2 Tbps is listed for the standard packages and 17 Tbps for the Professional packages.
Does my game server go offline during an attack?
No. KernelHost does not take attacked IP addresses out of the network (no null-routing). The malicious traffic is filtered out while the connections of your players keep running.
Which games and protocols are protected?
More than 40 games and protocols, among them Minecraft (Java and Bedrock), FiveM, alt:V, RageMP, SA-MP, CS2, Rust, ARK, Valheim, TeamSpeak and Mumble. Custom TCP and UDP services on any port are covered as well.
Does the filtering increase ping?
No. The filtering runs permanently at hardware level inside the network, so there is no switchover time and no measurable latency overhead. That is exactly what counts for game and voice servers.

Game DDoS protection DDoS protection for game servers Real-time filtering Always-on DDoS protection Minecraft DDoS protection TeamSpeak DDoS protection Nullping protection