Video game gamer consoles
– Getty Images

Cloudflare has concocted a solution to tackle distributed denial-of-service (DDoS) attacks based around a backbone protocol for online games, voice calls, and other apps reliant on real-time communication between clients and servers.

Designed for its Magic Transit DDoS protection service, Programmable Flow Protection is a system designed to let users implement their own custom DDoS mitigation logic using custom and proprietary protocols built on user datagram protocol (UDP).

Unlike transmission control protocol (TCP), UDP is set up to send data packets quickly without the need for handshakes confirming safe arrival. But as packets can get lost, duplicated, or reordered, apps using UDP must handle errors themselves. Hackers exploit this weakness for DDoS floods, spoofing junk UDP traffic to overwhelm servers.

Traditionally, if Cloudflare doesn’t understand the protocol inside a UDP packet’s payload, its DDoS mitigation systems either completely block or apply a rate limit to the destination IP and port combination, in effect causing the same lags or outages as intended by the hackers.

With Programmable Flow Protection, users can write their own extended Berkeley packet filter (eBPF) program to define legitimate packets and how to deal with “bad” ones, by either dropping or challenging them before they reach the end destination.

“A customer can upload the program to Cloudflare, and Cloudflare will execute it on every packet destined to their network," the vendor explained. "Programs are executed in userspace, not kernel space, which allows Cloudflare the flexibility to support a variety of customers and use cases on the platform without compromising security."

The solution also tackles replay attacks, where a bad actor repeatedly sends packets that were once valid, and thus conform to expected patterns of the traffic, but still remain invalid in the application’s current context.

With Programmable Flow Protection, a user can deploy a program that challenges suspicious clients and drops scripted traffic, tracks the source IP addresses it has seen, and emits a packet with a cryptographic challenge back to unknown clients.

In a UDP-heavy example such as gaming, a legitimate client running a valid gaming client is able to correctly solve the challenge and respond with proof. Meanwhile, the attacker’s script is blocked, with subsequent packets dropped.

Programmable Flow Protection is currently in beta and available to Magic Transit Enterprise customers for an additional cost.