--- title: "DDoS Defense" slug: "ddos-defense" description: "Automate DDoS detection and mitigation with Kentik's comprehensive defense solutions, featuring customizable policies and real-time attack insights." updated: 2026-07-17T16:11:24Z published: 2026-07-17T16:11:24Z canonical: "kb.kentik.com/ddos-defense" stale: true --- > ## Documentation Index > Fetch the complete documentation index at: https://kb.kentik.com/llms.txt > Use this file to discover all available pages before exploring further. # DDoS Defense This article discusses the **DDoS Defense** page in the Kentik portal. ![](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/image(261).png) *Automate DDoS detection, investigation, and mitigation with Kentik.* | **Purpose:** | Streamline the protection of your network from DDoS attacks with easily customizable Kentik-provided preset alert policies for the most common attack profiles. | | --- | --- | | **Benefits:** | - Eliminate false positives/negatives and decrease response time with automatic machine learning-based traffic profiling. - Visualize attack characteristics and network impact. - Trigger automatic mitigation actions including RTBH, Flowspec, and external mitigation hardware or services. | | **Use Cases:** | DDoS detection, mitigation, and administration | | **Relevant Roles:** | Network Engineers/Architects, Network Security Engineers, NOC Engineers, Carrier Product Managers | ## About DDoS Defense DDoS attacks employ various attack vectors, including volumetric, invalid protocols, UDP, TCP, ICMP, amplification and reflection, and DNS. Effective detection and alerting require a comprehensive understanding of these possibilities. Kentik's DDoS Defense workflow (**Protect »** **DDoS Defense**) is part of our overall Alerting system (see [**Protect**](/v1/docs/protect-overview)) focused on DDoS policies that require minimal customization to protect against common attacks. ### Access DDoS Defense The DDoS protection features have two portal locations: - **DDoS Defense Page**: Go to **Protect »** **DDoS Defense** to quickly view ongoing and historical attacks and mitigations. - **Policy Templates**: Go to **Settings »** **Alerting** and click **Alert Policy Templates** for Kentik-created alert policies to help you quickly deploy protection (see [**Alert Policy Templates**](/v1/docs/alert-policy-templates)). - Use the **Filters** pane to narrow the templates to DDoS-targeted ones, then clone a template to add it to your [**Alert Policies Page**](/v1/docs/alert-policies#alert-policies-page-ui). - The template remains unchanged and the resulting policy is fully editable to meet the needs of your organization. To access the Alert Policy Templates page from the DDoS Defense page: 1. Click **Manage Alert Policies** to go the Policies page 2. Click **Alert Policy Templates** to go to the Policy Templates page. > [!NOTE] > **Note:** For attack profiles not covered by DDoS templates, create a custom alert policy in **Protect »** **Alerting** (see [**Alert Policies**](/v1/docs/alert-policies)). ## DDoS Defense Page The **DDoS Defense** page provides a high-level view of DDoS attack activity that has generated alarms from DDoS-related [**Alert Policies**](/v1/docs/alert-policies). ### DDoS Defense Page UI The DDoS Defense page includes: - **Manage Alert Policies** (button): Click to go to the [**Alert Policies**](/v1/docs/alert-policies) page, filtered by Protect policy type. - **DDoS Defense Breakdowns**: Bar charts showing alerts categorized by status, severity, and policy (see [**DDoS Defense Breakdowns**](/v1/docs/ddos-defense#ddos-defense-breakdowns)). Breakdowns cover the last 24 hours. Hover over a bar to open a popup with additional information about its alerts. - **Last 24 Hour Attack Activity**: A chart showing attack activity in the last 24 hours (see [**Attack Activity Chart**](/v1/docs/ddos-defense#attack-activity-chart)). - **Last 24 Hour Top Dest IPs**: Chart showing the top destination IP addresses in the last 24 hours as measured in different metrics (see [**Top Dest IPs**](/v1/docs/ddos-defense#top-dest-ips)). - **Attacks Within the Last 24 Hours**: A table listing attacks within the last 24 hours along with details on those attacks (see [**Attack Table**](/v1/docs/ddos-defense#attack-table)). ### DDoS Defense Breakdowns The DDoS Defense breakdowns are bar charts at the top of the page representing different breakdowns of alerts. The charts are similar to the [**Alerting Breakdowns**](/v1/docs/alerting-page#alerting-breakdowns) and contain the following UI elements: - **Status**: The bars represent alerts by their state. - **Severity**: The bars represent alerts by the severity level of their policy thresholds. - **Policies**: The bars represent individual policies triggered in the last 24 hours, in descending order by alert count. Hover on a bar to see the name, type, ID, description, and alert count for the policy. ![](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/image(262).png) *The bar charts show breakdowns of alerts over the last 24 hours.* ### Attack Activity Chart The **Last 24 Hour Attack Activity** chart shows attack activity over the last 24 hours. The blue bar indicates new alarms, while the red line shows active alarms. Hovering over the chart reveals a popup with counts of new and active alarms. ![](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/image(263).png) *The timeline shows the number and times of attacks in the last 24 hours.* ### Attack Table The **Attacks Active Within Last 24 Hours** table shows alarms in the last day from Protect alert policies. Each row provides summary information about an alarm (see [**Alerts List**](/v1/docs/alerting-page#alerts-list)). Click a row for more details (see [**Attack Details Drawer**](/v1/docs/ddos-defense#attack-details-drawer)). The **View More Attacks** button at the top right takes you to the [**Alerting**](/v1/docs/alerting-page) page, filtering the [**Alerts List**](/v1/docs/alerting-page#alerts-list) to show only DDoS attacks (not limited to the last 24 hours). ![](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/image(265).png) *The table lists the alarms generated by alert policies over the last 24 hours.* #### Attack Details Drawer Click the row for an attack to open a Details drawer identical to the [**Alert Summary Drawer**](/v1/docs/alerting-page#alert-summary-drawer).