Under attack?
Protection for VoIP and telecom operators

Voice degrades before it disconnects, which is why scrubbing centres are the wrong tool

A web page survives a hundred milliseconds of extra latency and a little loss. A call does not - it becomes unusable long before it drops, and the customer blames you rather than the attacker. Anything that reroutes media or adds jitter has already failed, whatever its capacity figure says.

What attacks voice infrastructure

SIP floods and registration abuse

INVITE and REGISTER floods against signalling, and scanners that walk extension ranges looking for weak credentials. Both look like signalling because they are signalling.

UDP floods against media ranges

RTP lives on wide UDP port ranges with no handshake to validate, which makes it both easy to flood and easy for a clumsy filter to break.

Jitter as the real damage

Loss and delay variation destroy call quality at levels far below what would be considered an outage anywhere else. A mitigation that 'only' adds 30 ms of variance has taken the service down.

Why in-path filtering suits voice

No diversion, no path change

Traffic is filtered where it already flows. Media does not get rerouted when an attack starts, so there is no re-convergence, no path change and no jitter event caused by the protection itself.

Filtering in the driver, measured in nanoseconds

A dropped packet costs a handful of instructions in the NIC receive path. There is no queueing stage added to the traffic that passes, which is what keeps delay variation flat under load.

SIP and IPsec vectors handled explicitly

SIP attack patterns and IPsec-targeted floods are filtered as their own classes, and IKE and NAT-T are recognised so tunnels carrying voice between sites are never caught by a generic UDP rule.

Per-destination budgets for wide port ranges

Media ranges cannot be protected by port rules. Budgets are per destination and per prefix, so a flood across an entire RTP range is caught by volume rather than by guessing ports.

Tier 2 European backbone · European DDoS protected network Built, filtered and operated inside the EU · human NOC 24/7, no AI agents
ISO 9001ISO 27001PCI-DSSGDPRNIS2

Carrier plumbing for voice operators

The mitigation is one layer. The same network sells the layers around it - and a stack bought from one operator has nobody in it to blame somebody else.

IP transit

Transit where jitter is the metric

Committed capacity reserved end to end, so delay variation stays flat on the busy evening - the property a voice operator is actually buying, stated as a figure per route rather than a slogan. The transit page →

Transport

Interconnects between switch sites

E-Line between softswitch and SBC locations, or a wavelength for TDM-replacement backhaul - transparent to your signalling and media, protected where the route is diverse. EVPN-MPLS transport →

Consulting

QoS, and the boxes that honour it

Equipment selection and configuration for voice: queuing, marking, session border placement and the measurements to prove it works - then support after the handover. Consulting & build →

How it is delivered

Protected IP transit for signalling and media ranges
Tunnelled delivery where the softswitch stays where it is
Thresholds set against your measured call traffic, not a default
Captures from every incident for post-mortem analysis

Protection for other sectors