NVIDIA B200 GPUs available now!
Cluster Edition

High Defense IP

  • Massive Scrubbing Capacity
  • Full Business Support
  • Accurate Detection & Second-Level Response
  • Integrated DDoS & CC Attack Defense
Get Started

Product Overview

Our High Defense IP is a premium value-added protection service designed to safeguard businesses such as gaming, finance, and websites from large-scale DDoS attacks that could cause service disruptions. High Defense IP provides DDoS protection for registered domain names or origin IP addresses (including non-OneSource Cloud elastic public IPs).

By configuring High Defense IP, when facing large-scale DDoS attacks, malicious traffic is diverted to the High Defense IP for scrubbing, ensuring the stability and availability of the origin business services.

The service offers massive scrubbing capacity, supporting multiple defense lines such as multi-line BGP and static three-line BGP. It is compatible with TCP, HTTP, and HTTPS protocols, delivering rapid response and meeting the business needs of industries like finance, gaming, and e-commerce.

High Defense IP is closely tied to enterprise business operations. Customers interested in activating the service can contact the sales team for assistance.

Supported Regions: 

High Defense IP can protect public network servers, including but not limited to IDC data centers, OneSource cloud servers, and other cloud environments. The regions where High Defense IP is currently available include:
Mainland China: North China (Beijing)East China (Shanghai and Wuxi)South China (Guangzhou)

The DDoS protection capabilities offered by High Defense IP in different regions are summarized in the following table:

Product Architecture

After purchasing the High Defense IP, you need to update your domain to resolve to the High Defense IP.For Web services, point the domain name to the High Defense IP.For non-Web services, replace the original service IP with the High Defense IP.At the same time, you will need to configure forwarding rules on the DDoS High Defense IP.All public traffic will first pass through the High Defense data center. The system forwards incoming traffic to the origin IP based on port and protocol rules. Malicious attack traffic is filtered and scrubbed at the High Defense IP, while clean traffic is forwarded to the origin IP, ensuring stable and protected access to your services.

Key Features

  • Comprehensive DDoS Protection
    Safeguards against a wide range of DDoS attacks, including TCP flood, UDP flood, HTTP slow attacks, and CC attacks, ensuring smooth business operations for both web and non-web services.
  • Detailed Protection Reports
    Provides real-time and historical traffic reports along with attack details, offering transparent insight into service status with complete attack logs and traffic analysis.
  • Versatile Protection Capabilities
    Supports forwarding rules for HTTP, HTTPS, and TCP protocols. Users can easily add, delete, or modify forwarding rules, configure multiple forwarding strategies, and enable traffic load balancing for even distribution of business traffic.
  • Automatic Blackhole Recovery
    For sudden traffic surges or insufficient elastic bandwidth leading to blackhole routing, the system regularly checks and automatically lifts the blackhole. It's recommended to increase the protection bandwidth when recovering to minimize future downtime.
  • Elastic Bandwidth Protection
    Offers flexible bandwidth protection ranging from 20G to 1000G on top of the guaranteed base bandwidth, allowing users to scale protection as needed.

Product

Massive Traffic Scrubbing Capacity

Offers multiple high-performance protection line options—including China Telecom, Unicom, Mobile, multi-line BGP, and static multi-line—with single-node defense capacity of up to 2.3 Tbps.

Comprehensive Business Support

Supports both web and non-web applications, ideal for industries with high security demands such as finance, gaming, e-commerce, and government—whether hosted in the cloud or on-premises.

Accurate Detection & Fast Mitigation

The advanced DDoS mitigation engine applies multi-layer, multi-module filtering at the network (L4) and application layers. It intelligently identifies and blocks malicious traffic—such as TCP, UDP, ICMP, IGMP, HTTP, DNS, video streaming, and gaming data—while ensuring legitimate traffic passes through safely.

Integrated DDoS/CC Defense System

Backed by robust DDoS mitigation resources, mature cloud security technology, and a dedicated security operations team, OneSource Cloud delivers a unified three-in-one defense system to guard against all forms of DDoS and CC attacks.

Fast & Reliable Performance

With security nodes distributed across Northern, Eastern, and Southern China and all three major carriers, protection is delivered close to the user for optimal access speed and effective high-volume DDoS defense—ensuring seamless user experiences.

Source IP Protection

High-Defense IP services mask and replace the user’s origin server IP, preventing direct attacks on the source and significantly enhancing security.

Secure & Hassle-Free Access

Deeply integrated with the management console, the service offers one-stop HTTPS encryption and fast onboarding. Simply purchase a High-Defense IP, configure forwarding rules, and your protection is live.

Flexible Pricing & Cost Optimization

Combines “guaranteed bandwidth” with “elastic protection” to reduce routine security costs. Users only pay for additional protection during actual attack events, ensuring uninterrupted service without overpaying.

Application Scenarios