Notebookcheck Cloudflare Launches Programmable Flow Protection for Custom DDoS Mitigation
Article Content
- •Programmable Flow Protection allows custom DDoS mitigation for proprietary UDP protocols.
- •The feature is currently in closed beta and requires an additional cost for Magic Transit customers.
- •Customers can upload C-based programs to define packet handling logic for enhanced security.
Cloudflare has introduced Programmable Flow Protection, a new feature for Magic Transit customers aimed at enhancing DDoS mitigation for custom UDP protocols. This feature allows customers to upload their own stateful packet-processing programs written in C, which are then deployed as eBPF programs across Cloudflare's global network. The system is designed to address challenges in mitigating DDoS attacks targeting specialized UDP traffic used in gaming, VoIP, and streaming services. Currently, the feature is in closed beta and available as an add-on for Magic Transit deployments. It supports both asymmetric and symmetric topologies but only inspects ingress traffic. Configuration is managed through Cloudflare's API, facilitating the creation and management of custom mitigation rules. The introduction of this feature reflects Cloudflare's commitment to providing tailored security solutions for diverse network environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…