On-premises DDoS
mitigation that doesn't wait for an attack.

An always-on, inline DDoS mitigation appliance for hosting providers, ISPs, datacenters, and network operators.

Every packet is filtered all the time. There is no mitigation mode to activate.

01 / THE DIFFERENCE

DON'T DETECT, THEN DEFEND

Filtering is the
normal state.

Most DDoS systems detect an attack, decide how to respond, and then activate mitigation. Covariant Edge doesn't. Protected traffic continuously passes through the filtering engine.

TRADITIONAL
Attack Detection Classification 10–60s to mitigation
COVARIANT EDGE
Filtering is already active 0s to mitigation

ZERO MITIGATION ACTIVATION DELAY

Protection without an
activation delay.

There is no race between an attacker and the detection system because mitigation doesn't need to be activated. Detection provides useful telemetry—but detection is not what protects the service.

FILTERING DOES
01No detection threshold before protection begins+
02No mitigation rule waiting to be deployed+
03No diversion delay+
04No temporary exposure while an attack is classified+
05No operator required to activate protection+
06No transition into or out of mitigation mode+

THE PROTECTION CONFIGURES ITSELF

The workload
defines the policy.

Large service-provider networks are constantly changing. Covariant automatically develops an understanding of what is running and how that service normally behaves. No mitigation profile needs to be created.

01Observe the service

Protocols, ports, connection behavior, packet rates, and client patterns.

02Build an understanding

Legitimate behavior becomes the reference point for the protected workload.

03Continuously enforce

Traffic that fits is forwarded. Traffic outside policy is filtered.

POLICY BASED ON WHAT ACTUALLY BELONGS

Learn the good traffic.
Filter the rest.

Covariant doesn't define an attack simply as “a lot of traffic.” The filtering system continuously asks a more useful question:

Does this traffic make sense for the service receiving it?
01

Protocols in use

Exposed services and connection behavior

02

Packet behavior

Normal traffic volume and packet rates

03

Traffic distribution

How real clients interact with the service

WHAT HAPPENS WHEN AN ATTACK STARTS?

Nothing special.

That's the point. Covariant keeps doing exactly what it was doing before: forward traffic that belongs and filter traffic that doesn't.

LEGITIMATE TRAFFICFORWARDED
ATTACK TRAFFICFILTERED×

Same filtering state before, during, and after an attack.

BUILT FOR THE FORWARDING PATH

100G+ on-premises protection on
commodity hardware.

Buy Covariant software and build appliances with our recommended hardware, or deploy certified appliances. Either way, filtering stays under your control—with <5µs of added latency.

Explore the architecture
100G+

NETWORK INTERFACES

<5µs

ADDED LATENCY

REAL-
TIME

TRAFFIC TELEMETRY

SCALABLE NODES

BUILT FOR NETWORKS WHERE EVERY CUSTOMER IS DIFFERENT

Protection that
follows the workload.

01

Hosting providers

Protect dedicated servers, VPS infrastructure, game hosting, web hosting, colocation, and customer networks—without hand-maintained profiles.

Explore solutions
02

ISPs & network operators

Add always-on filtering across heterogeneous customer traffic while your network continues operating normally during attacks.

Explore solutions
03

Infrastructure teams

Build protection directly into the forwarding path, then expand capacity with commodity mitigation nodes as the network grows.

Explore solutions

WHAT HAPPENS WHEN A NEW SERVICE COMES ONLINE?

Adaptation without
intervention.

  1. 01

    Traffic begins

    A new service starts receiving legitimate traffic.

  2. 02

    Covariant learns

    The platform observes the service and determines how traffic behaves.

  3. 03

    Policy adapts

    Within seconds or minutes, filtering develops an understanding of what belongs.

  4. 04

    Filtering continues

    No attack is required. Traffic is continuously evaluated.

  5. 05

    An attack arrives

    There is nothing to activate. Traffic outside policy is rejected.

PUT COVARIANT EDGE IN YOUR LAB

Protection should be
boring.

Evaluate Covariant against your own traffic, applications, hardware, and testing methodology. Don't take our word for it.

Attack it.