Interserver
Defending Against a 1.2Tbps DDoS Attack: A Case Study with Interserver
How Path Network protected long-time customer Interserver from a 1.2 Tbps DDoS attack, without a single moment of service disruption.
1.2 Tbps
Peak attack size
360 Mp/s
Peak packet rate
5 hrs
Attack duration
0
Downtime


client
Interserver is a web hosting provider offering shared, cloud, dedicated, and colocation hosting since 1999.
Service
Location
USA
industry
Web Hosting
Web Hosting Since 1999
Client background for Interserver
Who They Are
Interserver has been a reliable web hosting provider since 1999. They offer various services, including shared hosting, cloud hosting, dedicated servers, and colocation. Known for their commitment to security and customer support, Interserver serves a wide range of clients, from freelancers to Fortune 500 companies.
DDoS-protected floating IPs
Since 2021, Interserver has partnered with Path Network to enhance its DDoS protection capabilities. Path's service protects their infrastructure and enables them to offer DDoS-protected "floating IPs" to their end customers. These floating IPs provide flexible and dynamic protection, ensuring uninterrupted service for their clients' servers.
The Incident
A sustained UDP reflection/amplification attack flooded Plains Internet's network. With no DDoS mitigation in place, there was nothing to stop it.


UDP DDoS being blocked
Attack Profile
Five IPs, One Target
On July 31st, Interserver was targeted in a severe DDoS attack aimed at five specific IP addresses, all belonging to the same end-user. The attack was characterized by multiple spikes surpassing 500 Gbps, peaking at 1.2 Tbps and roughly 360 Mp/s (million packets per second) during five hours of intense activity.

Timeline
This attack began shortly after 8:00 PM PST and continued until around 1 PM, with the highest peak occurring towards the end of this period. The largest of these attacks combined UDP and GRE-based DDoS vectors, predominantly utilizing UDP. The attacker gave up shortly after noticing there was no impact, not even after using its resources at full capacity.

Mitigation Strategy
This wasn't emergency response, it was a system already built for this
When Interserver was hit with a 1.2 Tbps multi-vector attack, Path Network's layered defense system handled it automatically, filtering malicious traffic before it ever reached their network.
Threshold, exceeding 1 Tbps
Layer 01
Auto-Filtering
Path's Orchestrator auto-filtering technology immediately identified and blocked the majority of the malicious traffic. This layer is designed to handle large-scale volumetric attacks, including those exceeding 1 Tbps.
Configured by, end-user
Layer 02
Stateful Firewall Rules
For any residual threats that bypassed the first layer, smaller but more complex DDoS vectors, stateful firewall rules were activated. These were configured by Interserver's end-user directly in the customer dashboard, adapted to the specific applications they wanted protected.
Basis, RFC-defined
Layer 03
Custom-Built DDoS Filters
The final layer applies custom-built DDoS filters, selected from a predefined list in the customer dashboard and built from the unique RFC documents for the applications they're meant to protect.
The Outcome
Thanks to our comprehensive mitigation strategy, the attack was fully neutralized without any disruption to Interserver or their end-users. The effectiveness of our approach was highlighted by the seamless continuity of Interserver's services.
The end-user of Interserver did not feel any impact from the attack, and the Interserver team noticed no disruptions to their network. Their own feedback said it best: "Overall, we did not have any issues or notice anything."
Debrief
Lessons learned & best practices
It's a matter of when, not if
DDoS attacks aren't rare, and they don't only target large enterprises. This incident is a reminder that any business handling internet traffic needs the right partner and defenses in place before an attack happens, not after.
Layered defense adapts to real threats
Volumetric filtering alone isn't enough. Interserver's mitigation held because auto-filtering absorbed the bulk of the attack while stateful rules and custom, RFC-based filters adapted to the specific applications under threat, catching the more complex vectors that slipped past the first layer.




