한국어English日本語简体中文繁體中文DeutschไทยTiếng ViệtРусскийPortuguês (Brasil)EspañolBahasa Indonesia

Game Lag White Paper › L4 Internet path

Shared links saturated by DDoS DDoS saturating shared links

Cause ID isp-ddos-path · Primary owner Infra team (Network infrastructure) · Also External (External)

Open the interactive card with figures and simulations →

Massive attacks aimed at the game company, or at someone else on the same network, fill up shared links.

Why A flood of attack traffic → Effect Legitimate traffic on the same links gets delayed and dropped too → On screen Many players teleport, disconnect, or can’t connect at the same time

Symptoms
Teleporting, Disconnect, Can’t connect / infinite loading
Factors
Packet loss, Latency
Who’s affected
Whole server, Specific region/ISP
When
Randomly, When crowds gather
Owner
Primary owner Infra team (Network infrastructure) · Also External (External)
Infra team action items
Use a DDoS protection service, reroute traffic during attacks, hide server addresses (keep servers behind protection equipment and don’t expose their real addresses).
External action items
If the attack targets someone else on the same network, ask the ISP to block it upstream.
On the graph
Hits a ceiling · Link inbound traffic (bps/pps), interface drops
Where to look
Inbound traffic and dropped packet counts on our links and equipment, plus the DDoS protection service’s attack detection log, lined up with the times when disconnects cluster
Confirmed if
Inbound traffic flattens out at link capacity and drops rise, while players across many regions and ISPs teleport or disconnect at the same moment
Ruled out if
Links have headroom but only some ISPs are bad: congestion or routing problems in the ISP segment
Check with
Infra tools (no game code needed)

Sources

  1. Infrastructure layer attacks AWS
    Volumetric attacks such as UDP reflection and SYN floods overwhelm network capacity or tie up firewall and load balancer resources
  2. Obfuscating AWS resources (BP1, BP4, BP5) AWS
    Put edge services such as CloudFront or a load balancer in front of origin servers to reduce direct exposure
  3. RFC 7999: BLACKHOLE Community IETF
    The BLACKHOLE community, announced over BGP to ask neighboring networks to drop traffic headed to a specific address

See also

Same layer: L4 Internet path

Same symptom (Teleporting), other layers

View the interactive card with figures and simulations