Skip to content
Cloudflare Launches Programmable Flow Protection for Custom DDoS Mitigation

Cloudflare Launches Programmable Flow Protection for Custom DDoS Mitigation

First seen 1 Apr 2026, 14:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 2, 2026 at 14:02 UTC
  • •Programmable Flow Protection allows custom DDoS mitigation for proprietary UDP protocols.
  • •The feature is currently in closed beta and requires an additional cost for Magic Transit customers.
  • •Customers can upload C-based programs to define packet handling logic for enhanced security.

Cloudflare has introduced Programmable Flow Protection, a new feature for Magic Transit customers aimed at enhancing DDoS mitigation for custom UDP protocols. This feature allows customers to upload their own stateful packet-processing programs written in C, which are then deployed as eBPF programs across Cloudflare's global network. The system is designed to address challenges in mitigating DDoS attacks targeting specialized UDP traffic used in gaming, VoIP, and streaming services. Currently, the feature is in closed beta and available as an add-on for Magic Transit deployments. It supports both asymmetric and symmetric topologies but only inspects ingress traffic. Configuration is managed through Cloudflare's API, facilitating the creation and management of custom mitigation rules. The introduction of this feature reflects Cloudflare's commitment to providing tailored security solutions for diverse network environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 191d ago How this analysis works

Timeline

2026-03-31
Cloudflare announces Programmable Flow Protection feature
2026-04-01
Feature details published by Notebookcheck

More articles in this cluster (2)