Cluster nominal
Legit user Botnet source Server replica Dropped packet
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

DDoS Mitigation: Traffic Filtering & Load Balancing

This simulation models a distributed denial-of-service attack against a small server cluster and the three defenses used to survive it: per-source rate limiting, anomaly-based traffic filtering, and horizontal load balancing across replicas. A botnet of attacking sources and a handful of legitimate users both send requests toward the cluster; you control how aggressive the attack is and how the defenses respond, and watch — via real packet flow in 3D and live numeric readouts — how much legitimate traffic actually gets through versus how much gets starved when the queue overflows. The underlying capacity, rate-limit and filter math is worked out explicitly in the "How it works" panel so the trade-offs (over-filtering blocks real users, under-provisioning starves them during a flood) are visible, not just asserted.