
How to Stop Outbound DDoS in ISP Networks
Detection is the easy part. The hard part is tracing a DDoS from a border IP all the way to the specific subscriber flooding a Chinese ASN — and containing it without killing upload speeds for every paying customer. Here's what we deployed across ISP customer networks in March 2026: automated tracing chains, per-subscriber nftables rate limits (including the ones that broke QUIC on day one), and the Quarantine BNG architecture.










