Md. Mahabubur Rahman
DDoS mitigation when the customer is an ISP

Security · 28 Jul 2026 · 5 min read

DDoS mitigation when the customer is an ISP

Volumetric attacks on downstream ISPs are infrastructure problems. How WanGuard, FastNetMon, and custom automation sit on a multi-gigabit IIG core.

A volumetric DDoS against a downstream ISP is not a "security ticket." It is a capacity, peering, and customer-SLA problem at the same time.

On a national IIG backbone the blast radius is not one enterprise prefix. It is every subscriber behind that ISP. Mitigation has to be fast enough that the core stays healthy, and precise enough that you do not blackhole a paying customer.

The stack we run

  • FastNetMon for early anomaly detection on flow telemetry
  • WanGuard for mitigation policy and scrubbing decisions
  • Custom firewall automation for repeatable, auditable response
  • NetFlow / sFlow / IPFIX so the same data feeds both engineering and forensics

What "self-developed automation" actually means

Playbooks fail when they live in a wiki. Ours live in scripts the NOC can run with a named incident ID: identify the target prefix, classify volumetric vs application, apply a temporary filter, notify the downstream ISP, and expire the control.

That last part matters. Permanent filters accumulate into a second, undocumented routing policy.

For clients and hiring managers

If you operate IP Transit, DDoS is a product feature whether you sell it or not. The question is whether your backbone team can mitigate without taking the rest of the table down.