Back to Blog Search

    Guides

    How DDoS Protection Pricing Works: What You Are Actually Paying For

    Christopher Plunk

    Chief Technology Officer

    C
    August 16, 20267 min read

    Two quotes for the same DDoS protection can look nothing alike. One is a flat monthly figure. The next is a price per Mbps. A third will not give you a number until you say how much bandwidth you are willing to commit to. None of them is dishonest, but they are counting different things, and comparing only the headline price is how people end up with an invoice that behaves nothing like they expected.

    DDoS protection pricing gets much easier to judge once you know which quantity is being measured. This guide walks through the billing models you are likely to meet, explains what providers mean by clean traffic, shows how percentile billing works, and lists the questions that tend to expose a bad deal before you sign anything.

    Why DDoS protection pricing varies so much between quotes

    Stopping a flood of traffic requires having far more network capacity than the attacker can fill. That capacity has to exist and be paid for whether or not anyone attacks you this month, which makes DDoS mitigation a business with a large standing cost and a very uneven demand for it. Every pricing model is an attempt to split that standing cost between customers in a way that feels fair.

    Where the models diverge is in the proxy they choose for your share. Some use the size of the single service you are protecting. Some use how much legitimate traffic you actually move. Some use how much capacity you want held in reserve with your name on it. Work out which proxy a quote is built on and the comparison stops being guesswork.

    Timing matters too. Protection that runs continuously costs the provider more to operate than protection that only switches on once an attack is detected, and that difference usually shows up somewhere in the price. The trade-off between always-on and on-demand DDoS protection is worth understanding before you treat two quotes as equivalent.

    Clean traffic is the number that belongs on your bill

    While an attack is running, your protected address receives two very different things. There is the flood, which is junk sent purely to fill your connection, and there is the ordinary traffic from your users, players, or customers. Filtering separates the two and forwards only the second kind onward. The traffic that survives that process is what the industry calls clean traffic, and if the term is new to you, how traffic scrubbing works covers the mechanics in more detail.

    That distinction decides more about your invoice than any other clause in a contract.

    If a provider measures every packet that arrives at their edge, the attacker gets a vote on what you pay. A flood lasting an afternoon can produce a charge larger than the downtime it was meant to cause, which turns your protection into a second way of being hurt. If a provider measures only the clean traffic handed to your server, an attack costs you nothing extra, which is the point of buying protection at all.

    Some providers publish this as a rule rather than treating it case by case. The Sterile Networks pricing page states that blocked attack traffic is not counted, that only legitimate clean traffic delivered after mitigation is measured, and that customers never pay based on attack size. Whoever you are comparing, ask for the equivalent commitment in writing before you sign.

    The three billing models you will meet

    Almost every quote you receive will be a version of one of these.

    A fixed monthly plan covers one protected service. You choose a speed, an amount of outbound traffic, and how many protected addresses you need, and the price does not move with usage. It suits a single game server, website, or application where predictability matters more than fine-grained efficiency.

    Usage-based pricing charges a rate per Mbps of clean traffic, measured across the month. There is often no commitment, so your bill rises and falls with your actual traffic. It suits networks whose traffic genuinely varies, and it is usually the model on offer when you bring your own IP addresses.

    Committed capacity reserves a set amount of clean bandwidth for you at a lower price per Mbps, in exchange for agreeing to pay for it whether you use it or not. This is what hosting companies and larger gaming networks tend to buy, because the per-unit saving is real once your baseline is high enough.

    ModelWhat is measuredBest when
    Fixed monthlyA defined service, not your usageYou protect one server or service and want a predictable bill
    Usage-basedClean traffic across the monthYour traffic changes noticeably month to month
    Committed capacityA reserved amount you pay for regardlessYour baseline is consistently high and you want the lowest unit price

    Sterile Networks publishes all three, priced from $20 per month for a single protected service, $0.28 per Mbps on the clean 95th percentile with no commitment, and committed plans from 5 Gbps upward. The comparison of available protection plans sets out what each one includes.

    What 95th percentile billing actually means

    If you have never bought bandwidth before, this is the part that sounds like accounting trickery and is not.

    A provider billing on usage cannot simply charge for your highest moment, because one unusual minute would set the price for an entire month. The common approach is to sample your throughput at fixed intervals, typically every five minutes, then sort every sample taken that month from highest to lowest and discard the top five percent. Whatever sample is highest among the ones left becomes the number you are billed on. That is the 95th percentile.

    Five minute samples across a thirty day month produce roughly 8,600 measurements, so setting aside the top five percent forgives around thirty six hours of your busiest periods. A launch day, a single tournament, or one post that does unexpectedly well will not decide your invoice. A pattern that repeats every evening will, because it generates far more than thirty six hours of high samples.

    That behaviour is worth planning around. Percentile billing is forgiving of short spikes and unforgiving of a high, steady baseline, which is exactly the point at which committed capacity starts to look cheaper.

    The costs that sit outside the headline number

    The advertised price is rarely the whole price. Before comparing two providers, find out how each one treats the following.

    • Onboarding and setup. Some providers charge separately to configure a tunnel, onboard your address space, or set up filtering rules.
    • Support. Ask whether technical support is included or sold as a tier, and whether help during an active attack falls inside or outside it.
    • Per-address and per-service fees. Protecting a second service is sometimes a small addition and sometimes close to a second subscription.
    • Overage terms. Find out what happens when you exceed a committed amount, and at what rate.
    • Contract length and notice. A low monthly figure attached to a long minimum term is a different product from the same figure on a monthly rolling basis.
    • Whether reserved capacity is genuinely reserved. Capacity sold to several customers at once is only reserved until two of them need it.

    Sterile publishes its position on several of these: setup, onboarding, and support are included in every plan, committed bandwidth is described as reserved rather than oversold, and the pricing page states there are no hidden platform, setup, onboarding, or support fees. Treat that as a template for what to ask elsewhere rather than as an industry norm, because it is not one.

    Questions worth asking before you sign

    1. Is my bill based on clean traffic delivered, or on everything that arrives at your edge?
    2. What happens to my invoice during a large attack?
    3. Are you measuring an average, a peak, or a percentile, and over what interval?
    4. Is filtering running continuously, or does it start after an attack is detected?
    5. Which fees are excluded from the price you have quoted me?
    6. If I commit to capacity, is that capacity reserved for me alone?
    7. What is the shortest term you will sell this on?

    Answers that arrive quickly and in writing are a reasonable signal in themselves. Billing models are not commercially sensitive, and a provider who cannot explain theirs plainly is unlikely to become clearer once you are a customer.

    Matching the model to the traffic you actually have

    Start with your own numbers rather than the price list. Look at what your service moves on a normal evening, not on its best day, and decide whether that figure is stable or genuinely variable. A steady baseline points toward committed capacity. Real variation points toward usage-based pricing. One service that simply needs to stay online points toward a fixed plan, and the question of whether you need your own address space usually settles the rest.

    From there it is worth checking how the protection would actually be delivered, since that shapes what you can buy. Options for whole IP ranges and your own address space are described on the network and ASN protection page, and if you want a second opinion on which model fits the traffic you have, the pricing page has a direct route to asking.

    Related Posts