Massive attacks aimed at the game company, or at someone else on the same network, fill up shared links.
Why A flood of attack traffic → Effect Legitimate traffic on the same links gets delayed and dropped too → On screen Many players teleport, disconnect, or can’t connect at the same time
Primary owner Infra team (Network infrastructure) · Also External (External)
Infra team action items
Use a DDoS protection service, reroute traffic during attacks, hide server addresses (keep servers behind protection equipment and don’t expose their real addresses).
External action items
If the attack targets someone else on the same network, ask the ISP to block it upstream.
On the graph
Hits a ceiling · Link inbound traffic (bps/pps), interface drops
Where to look
Inbound traffic and dropped packet counts on our links and equipment, plus the DDoS protection service’s attack detection log, lined up with the times when disconnects cluster
Confirmed if
Inbound traffic flattens out at link capacity and drops rise, while players across many regions and ISPs teleport or disconnect at the same moment
Ruled out if
Links have headroom but only some ISPs are bad: congestion or routing problems in the ISP segment
Check with
Infra tools (no game code needed)
Sources
Infrastructure layer attacksAWS Volumetric attacks such as UDP reflection and SYN floods overwhelm network capacity or tie up firewall and load balancer resources