Hosting providers
Protect dedicated servers, VPS infrastructure, game hosting, web hosting, colocation, and customer networks—without hand-maintained profiles.
Explore solutions ↗An always-on, inline DDoS mitigation appliance for hosting providers, ISPs, datacenters, and network operators.
Every packet is filtered all the time. There is no mitigation mode to activate.
DON'T DETECT, THEN DEFEND
Most DDoS systems detect an attack, decide how to respond, and then activate mitigation. Covariant Edge doesn't. Protected traffic continuously passes through the filtering engine.
ZERO MITIGATION ACTIVATION DELAY
There is no race between an attacker and the detection system because mitigation doesn't need to be activated. Detection provides useful telemetry—but detection is not what protects the service.
THE PROTECTION CONFIGURES ITSELF
Large service-provider networks are constantly changing. Covariant automatically develops an understanding of what is running and how that service normally behaves. No mitigation profile needs to be created.
Protocols, ports, connection behavior, packet rates, and client patterns.
Legitimate behavior becomes the reference point for the protected workload.
Traffic that fits is forwarded. Traffic outside policy is filtered.
POLICY BASED ON WHAT ACTUALLY BELONGS
Covariant doesn't define an attack simply as “a lot of traffic.” The filtering system continuously asks a more useful question:
Does this traffic make sense for the service receiving it?
Exposed services and connection behavior
Normal traffic volume and packet rates
How real clients interact with the service
WHAT HAPPENS WHEN AN ATTACK STARTS?
That's the point. Covariant keeps doing exactly what it was doing before: forward traffic that belongs and filter traffic that doesn't.
Same filtering state before, during, and after an attack.
BUILT FOR THE FORWARDING PATH
Buy Covariant software and build appliances with our recommended hardware, or deploy certified appliances. Either way, filtering stays under your control—with <5µs of added latency.
Explore the architecture↗NETWORK INTERFACES
ADDED LATENCY
TRAFFIC TELEMETRY
SCALABLE NODES
BUILT FOR NETWORKS WHERE EVERY CUSTOMER IS DIFFERENT
Protect dedicated servers, VPS infrastructure, game hosting, web hosting, colocation, and customer networks—without hand-maintained profiles.
Explore solutions ↗Add always-on filtering across heterogeneous customer traffic while your network continues operating normally during attacks.
Explore solutions ↗Build protection directly into the forwarding path, then expand capacity with commodity mitigation nodes as the network grows.
Explore solutions ↗WHAT HAPPENS WHEN A NEW SERVICE COMES ONLINE?
A new service starts receiving legitimate traffic.
The platform observes the service and determines how traffic behaves.
Within seconds or minutes, filtering develops an understanding of what belongs.
No attack is required. Traffic is continuously evaluated.
There is nothing to activate. Traffic outside policy is rejected.
PUT COVARIANT EDGE IN YOUR LAB
Evaluate Covariant against your own traffic, applications, hardware, and testing methodology. Don't take our word for it.
Attack it.