İçeriğe geç
Siber Kale by Labris Networks

English

HARPP DDoS Mitigator: attack classes and placement

Labris Networks Mühendislik Ekibi · Last updated 13 August 2026

HARPP DDoS Mitigator is Labris Networks' DDoS detection and mitigation product family. It is a separate product from the firewall for a technical reason: the problem DDoS defence solves is not the problem a firewall solves, and the two are not solved well on the same hardware.

What it addresses

A firewall decides which traffic may pass, using identity, port, application and policy. DDoS defence asks a different question: what to do when the traffic itself looks legitimate but its volume or rate makes keeping the service up impossible.

That distinction has three practical faces.

  • Volumetric. Traffic that fills the access link creates the problem before reaching the firewall. No on-premise device can drop traffic that never arrives; this is a placement problem, and it is solved upstream.
  • State exhaustion. The attack targets the firewall's own session table. Each half-open connection holds a record, and once the table fills the device cannot accept legitimate traffic either.
  • Application layer. Apparently valid requests sent to tire the application or database behind it. They are legitimate at packet level, so they cannot be separated by policy — only by behaviour and rate.

Where it sits

An on-premise mitigation layer goes between the protected service and the internet connection, typically in front of the firewall. The reason for that order is that a stateless filter protects a stateful device: the fewer packets that reach the firewall, the more room its session table has.

The limit follows from the same position. If your access link is 10 Gbit, a 40 Gbit attack is not decided by how capable the device is — the traffic has already filled the link. Above that threshold mitigation has to happen upstream, at the operator or in a scrubbing centre. In practice enterprise architectures build both: volume upstream, fine discrimination on site.

What it does not solve

A mitigation layer does not make outage impossible. It raises the cost of an attack and lets you decide in advance which measure applies at which threshold. False positives are a real cost too: a defence that filters out legitimate users produces the outcome the attacker was aiming for. So an acceptance test measures not only whether the attack was stopped but who was lost while stopping it.

Evaluating capacity

Gigabits per second alone is misleading. In a small-packet attack the deciding figure is packets per second; in one targeting the session table it is new connections per second. The highest catalogue number is usually measured with large packets and does not represent the small-packet case. The full argument is on the DDoS protection page.

Version note

This page describes the product's place in an architecture and makes no claim about the behaviour of a specific release. The administrator documentation available to us is version 3.3.1; the product datasheet carries a more recent date. For a version-dependent question, the current official documentation is the source.

Siber Kale publishes in Turkish. This page is a summary for readers who do not read Turkish; the full material — questions, guides and a glossary — is on the Turkish side. The Turkish version of this page is /labris/harpp-ddos-mitigator/.