DDoS protection · always on

DDoS protection built through reverse engineering. You see it working, in real time.

Unlike most, ours doesn't search for known attacks. It blocks everything by default and only releases legitimate traffic. New attacks don't get through, false positives are nearly zero, and you watch it all on the live panel.

Permanent mitigation· Proprietary L7 filters· Live panel· Zero added latency· Continuous updates
tcpdump · protection · live rec
in
0.0 Gbps
pass
0.0 Gbps
drop
0.0 Gbps
02 · Why DDoS matters

Every online server will be attacked. It's only a matter of when.

Servers exposed to the internet receive attack attempts all the time — automated probes hunting for vulnerabilities, or targeted attacks against an e-commerce on Black Friday, against a growing SaaS, against an API that moves money. But it's the gaming sector where the problem is most visible: for those running a serious server, DDoS isn't "if it happens", it's "when it happens".

Game servers are daily targets

Attacks come at critical moments: decisive rounds, playoffs, league finals, streamer broadcasts. Without protection that actually works, the result is downtime exactly when it matters.

Web applications suffer sophisticated L7 attacks

SaaS, e-commerce, APIs and public portals suffer application-layer attacks that go unnoticed by generic, volume-based protections.

Small and mid-sized businesses are growing targets

Today, any server with a public IP is a potential target — and attack tools are more accessible than ever. The myth that DDoS is only a big-company problem has fallen apart.

03 · Predominant model

How most protections work.

Traditional DDoS protection runs on the blacklist model: it knows the patterns of attacks that have already happened in the world, and blocks traffic when it recognizes those patterns. Anything that isn't a "known attacker" is considered legitimate traffic and passes through.

INTERNET SERVER BLACKLIST FILTER if known → block CATALOGED PATTERNS known attack (blocked) new attack (passes!) legitimate traffic

How it fails

New attacks pass unnoticed

Since the filter has to know the attack in order to block it, new vectors reach the server before they're identified.

It needs constant updates

Every time a new technique appears, the signature catalog has to be updated. If the update is slow, your protection is vulnerable in the meantime.

False positives are frequent

Because the filter analyzes patterns, it eventually identifies legitimate players or users as attacks — and blocks them. Server protected, but nobody can connect.

On-demand activation means a window of exposure

Some protections 'turn on' when they detect an attack, and take seconds to minutes to start filtering. Those seconds are enough to take the server down.

04 · Hostini model

Ours works the other way around.

Instead of blocking "known attacks", we block everything by default. We build the filters by reverse-engineering the protocols we protect — studying the real traffic of each application and mapping exactly what the connection of a legitimate user or player looks like. When the protection recognizes the legitimate traffic pattern, it lets it through. Everything else stays blocked.

INTERNET SERVER WHITELIST FILTER match → pass rest → block LEGITIMATE PATTERN any attack (all blocked) legitimate traffic (passes)

Why this changes everything

New attacks don't pass

Since we block anything that isn't legitimate traffic, new attack vectors (even ones not yet cataloged by the market) are blocked automatically. We don't need to discover the attack to start blocking it.

Almost zero false positives

The traffic pattern of a legitimate user is stable and well-mapped. Real users get through. Anything that isn't, doesn't. None of that drama where protection blocks real customers by mistake.

Permanent mitigation, always on

It's not protection that turns on when it detects an attack. It's protection that's always on, filtering 100% of the traffic 100% of the time. No exposure window.

Zero added latency

Filtering doesn't impact response time. Unlike protections that add hops to the route, ours is invisible to the end user.

Continuous updates

As new attack vectors emerge or new protocols need to be supported, we update the filters. The protection is monitored and continuously improved.

05 · Specialization

Filters built for your type of application.

Filter design varies depending on the type of traffic that needs to be protected. Each application has its own patterns, and generic protection doesn't work for all of them.

GAMES

Game servers

Filters built by reverse-engineering the protocols of FiveM, MTA, SAMP, Tibia and CS2. Each protocol has unique packet patterns, and the filter precisely distinguishes a legitimate player's traffic from attack traffic. Works from casual servers to the largest networks in Brazil.

FiveMMTASAMPTibiaCS2
WEB · API

Web applications and APIs

Protection against L7 attacks that compromise web applications — slow loris, HTTP flood, attacks against specific API endpoints, form abuse. The filter analyzes the behavior of a legitimate session and blocks anomalous patterns.

HTTPWSSGraphQLREST
COMBINED

Combined servers and portals

For cases like Tibia/OTServ — where the attack can come simultaneously against the game server (ports 7171/7172) and the web portal (voting, downloads, status) — we apply the same protection on both fronts. No need to hire Cloudflare separately for the website.

L4 gameL7 webBundled
06 · Evidence

You don't have to take our word for it.
You see it.

Every Hostini customer has access to the real-time traffic monitoring panel. Every packet that comes in, every attack that gets filtered, every action the protection takes — all visible, at any moment. It's not a report that arrives by email once a week. It's live.

panel.hostini.com.br / protection / brasil-roleplay live · t-32s

Inbound traffic · L3/L7 protection

brasil-roleplay.hostini · ip 200.96.xxx.xxx · 60s window
60s 15m 1h 24h
total traffic
0.0 Gbps
60s average
filtered
0.0 Gbps
75.9% of total
passing ✓
0.0 Gbps
+0.4ms latency
players online
0
+ 32 / min
Real-time throughput
L3/L4 + L7 · 60s window
Filtered attack Legitimate traffic

Panel features

Real-time traffic

Full view of the traffic reaching your server in this exact second.

Attack history

Every attack your infrastructure has suffered, with type, volume and duration. Visible for auditing, analysis and peace of mind.

Detailed technical metrics

Packets per second, bandwidth consumed, open connections, unique IPs — every metric a technical team needs.

Configurable alerts

Set up alerts via email or WhatsApp for events: attacks above a certain volume, anomalous spikes, and so on.

07 · Cases

Operations that trust our protection.

Servers that can't go down. Protection that doesn't fail when it matters.

FiveM · 2019 →
3.000 peak concurrent players

Brasil Roleplay

One of the biggest references in Brazilian roleplay. A customer since 2019, in an industry where DDoS is constant.

FiveM · Launch
6.000 at the beta launch

Reduto

Reached 6,000 concurrent players with Hostini. Infrastructure tested at real scale, at a moment of maximum exposure to attacks.

MTA · 2024 →
1.000 peak MTA players

Nova Capital

The largest MTA server in Brazil. Migrated to Hostini in 2024 looking for stability — including against DDoS attacks.

08 · How to get this protection

Protection comes included in all of our plans.

Unlike the market, where DDoS protection is sold as an expensive add-on, here it's included in every plan — VPS, dedicated and game servers. No extra cost, no separate activation, no fine print.

VPS

VPS Servers

Dedicated resources, Ryzen hardware, always-on DDoS protection.

from R$ 42,90/month
See VPS plans
DEDICATED

Dedicated Servers

Exclusive physical machine, DDoS protection with live panel, 24h support.

from R$ 950/month
See dedicated
GAMES

Game Servers

Specific filters for FiveM, MTA, SAMP, Tibia, CS2 and more. From casual to 6,000-player operations.

from R$ 32,90/month
See game plans
09 · Frequently asked questions

DDoS protection questions.

Distributed denial-of-service attack. It's when thousands (or millions) of compromised machines send traffic to a server at the same time, aiming to take it down. Unlike other types of attacks, DDoS doesn't break in — it overloads.
It's the model where everything is blocked by default and only traffic that matches a legitimate user's pattern is released. It's the opposite of the traditional model ('blacklist'), where everything is considered legitimate until proven to be an attack. Whitelist is safer because new attacks are blocked automatically, without having to be cataloged first.
No. It's included in all Hostini plans — VPS, dedicated and game servers. No additional charge, no separate activation.
No. Filtering happens without adding noticeable hops to the route. Your users or players won't feel any ping difference compared to running without the protection.
The mitigation infrastructure runs on world-class technology and has the capacity to block attacks of any scale. The live panel lets you watch each attack being neutralized in real time.
For each game (FiveM, MTA, SAMP, Tibia, CS2) we reverse-engineered the protocol: we studied how the game communicates and mapped exactly what a legitimate player's traffic looks like. The filters were built from that knowledge.
At the moment, the protection is offered only as part of our server plans. For specific cases where you need standalone protection for a server hosted elsewhere, talk to the team and we'll evaluate it together.
It's active from the first second. There's no 'learning' or activation period. The server is delivered with protection already filtering 100% of the traffic.

Protection you don't have to take on faith. You see it.

Included in every Hostini plan, at no extra cost. Up to 30 days to test.

Chat on WhatsApp