Detection, Mitigation & Response

Detect and mitigate DDoS attacks in under 1 second, respond automatically, and keep your users informed.

All features →
Docs
Documentation Quick Start API Reference Agent Setup Integrations 18
Learn
Free Tools 37 Free Certifications State of DDoS 2026 REPORT DDoS Protection Landscape Buyer's Guide PDF Hackathon Sponsorships DDoS Protection Facts
Company
About Us Become a Consultant 30% Partners White Label Managed Protection Contact Us System Status
Open Source
ftagent-lite MIT NetHawk MIT
Legal
Security Trust Center Terms & Privacy
Who Uses Flowtriq

From indie hosts to ISPs, see how teams like yours use Flowtriq to detect and stop DDoS attacks.

All use cases →

Carpet Bombing Detection

Carpet Bombing and
Cross-Node Correlation

Carpet bombing attacks distribute traffic across many destination IPs to stay below individual per-node thresholds. Flowtriq detects these distributed attacks by analyzing aggregate fleet-wide traffic, cross-referencing source IPs and timing across all nodes, and auto-grouping related incidents into unified attack groups.

Auto
Correlation Engine
5 min
Correlation Window
Unified
Group Visibility

How It Works

Cross-node detection catches what per-node thresholds miss

Carpet bombing works by spreading attack traffic across dozens or hundreds of destination IPs. Each individual node sees traffic below its detection threshold, so traditional per-node monitoring stays silent. The attacker exploits the gap between per-server detection and fleet-wide visibility.

Flowtriq solves this with cross-node correlation. When a new incident is detected, the engine checks all active incidents across your workspace for matching attack families, overlapping source IPs, and timing within a 5-minute window. Matches are grouped into a unified incident group with aggregate threshold detection, so distributed attacks that stay under per-node limits are caught at the fleet level.

Automatic Grouping

No manual tagging required. When a UDP flood hits Node A and the same attack type appears on Node B within 5 minutes, they are automatically linked into a multi-node group.

Unified Dashboard View

Incident groups appear above your incidents list with expandable member details. See all affected nodes, combined peak PPS, and group status at a glance.

Auto-Resolve

When all member incidents in a group are resolved, the group automatically closes. No manual cleanup required.

Cross-Reference

Each incident detail page shows a banner linking to its group and all sibling incidents. Jump between related attacks instantly.

Correlation Flow

From detection to grouping

Attack Hits Node A

Incident created with attack family, source IPs, and timing data.

Engine Checks Window

Same family + overlapping source IPs + within 5 minutes = correlated.

Group Created

Both incidents linked. Alerts fire once for the group, not per-node.

Why It Matters

See the full campaign

Multi-node attacks are increasingly common. Attackers target entire infrastructure, not just individual servers. Without correlation, your team investigates each incident separately, missing the bigger picture.

With incident correlation, you see the full campaign: which nodes were hit, in what order, and with what combined volume. This enables faster escalation decisions and more accurate impact assessment for post-incident reports.

Multi-Node Visibility

See every node affected by a coordinated attack in one view. Know instantly whether the attacker is targeting a single server or sweeping your entire fleet.

Alert Deduplication

Get one alert per attack campaign, not one per node. When 10 servers are hit simultaneously, your Slack channel sees one grouped notification with the full blast radius.

Combined Metrics

Aggregate peak PPS, total bandwidth, and source IP overlap across all group members. Understand the true scale of coordinated attacks.

Post-Incident Reports

Generate reports that capture the full multi-node campaign. Timeline, affected nodes, combined impact, shared source IPs, all in one document.

Cross-Layer

L7 Cross-Layer Correlation

When an L7 HTTP flood is detected from the access log, Flowtriq cross-references the attacking source IPs against recent L3/L4 incidents from the same workspace. If the same IPs appear in both network-layer and application-layer attacks, the incidents are linked for unified analysis.

This reveals multi-layer campaigns where attackers combine volumetric floods with targeted HTTP requests, giving you the complete attack picture across protocol layers.

FAQ

Common questions about correlation

What is DDoS incident correlation?

Correlation automatically groups related attacks across multiple nodes into a single incident when they share timing windows, source IP overlap, or attack signatures. This gives a unified view of distributed attacks instead of hundreds of separate single-node alerts.

How does correlation detect carpet bombing?

Carpet bombing spreads traffic across many destination IPs to stay under per-node thresholds. Correlation detects the aggregate pattern by cross-referencing source IPs and timing across all nodes, triggering even when no individual node crosses its own threshold.

Does correlation work across different data centers?

Yes. Correlation works across any nodes in your workspace regardless of physical location, network, or cloud provider.

How does correlation handle multi-vector attacks?

When an attacker combines multiple attack types (e.g., UDP flood + SYN flood + HTTP flood) against the same infrastructure, correlation groups all related incidents by timing window and source IP overlap regardless of attack family. You see the full multi-vector campaign as one coordinated event.

Does correlation work across different cloud providers?

Yes. Correlation operates at the workspace level and is provider-agnostic. Nodes on AWS, bare metal, DigitalOcean, and on-prem infrastructure all participate in the same correlation engine as long as they belong to the same workspace.

How does alert deduplication work with correlated incidents?

When incidents are grouped, alerts fire once for the group instead of once per node. Your Slack, email, or webhook channel receives a single notification listing all affected nodes and combined metrics, rather than separate alerts for each server.

Is there a minimum number of nodes required for correlation?

Correlation activates with as few as two nodes. If only one node is attacked, it is treated as a standalone incident. The moment a second node reports the same attack family within the 5-minute window, both are grouped automatically.

Get Started

See the Full Picture

Detect multi-node campaigns automatically. Start your free trial and deploy across your infrastructure.

FAQ

Frequently Asked Questions

What is DDoS incident correlation?

Correlation automatically groups related attacks across multiple nodes into a single incident when they share timing windows, source IP overlap, or attack signatures. This gives a unified view of distributed attacks instead of hundreds of separate single-node alerts.

How does correlation detect carpet bombing?

Carpet bombing spreads traffic across many destination IPs to stay under per-node thresholds. Correlation detects the aggregate pattern by cross-referencing source IPs and timing across all nodes — triggering even when no individual node crosses its own threshold.

Does correlation work across different data centers?

Yes — correlation works across any nodes in your workspace regardless of physical location, network, or cloud provider.

How does correlation handle multi-vector attacks?

When an attacker combines multiple attack types (e.g., UDP flood + SYN flood + HTTP flood) against the same infrastructure, correlation groups all related incidents by timing window and source IP overlap regardless of attack family. You see the full multi-vector campaign as one coordinated event.

Does correlation work across different cloud providers?

Yes. Correlation operates at the workspace level and is provider-agnostic. Nodes on AWS, bare metal, DigitalOcean, and on-prem infrastructure all participate in the same correlation engine as long as they belong to the same workspace.

How does alert deduplication work with correlated incidents?

When incidents are grouped, alerts fire once for the group instead of once per node. Your Slack, email, or webhook channel receives a single notification listing all affected nodes and combined metrics, rather than separate alerts for each server.

Is there a minimum number of nodes required for correlation?

Correlation activates with as few as two nodes. If only one node is attacked, it is treated as a standalone incident. The moment a second node reports the same attack family within the 5-minute window, both are grouped automatically.

Does Flowtriq provide cross-network threat intelligence?

Yes. Each incident includes anonymized cross-tenant correlation data showing how many other networks are experiencing the same attack family, same source ASN, or same attack subtype. This collective defense intelligence helps you understand whether you are the only target or part of a broader campaign, and provides platform-wide trend data for your attack types.

What is IP reputation intelligence?

Flowtriq maintains a shared IP reputation database across all customers. When you view an incident, the dashboard shows whether the source IPs have attacked other networks, their risk scores, attack frequency, and known attack families. This proprietary threat intelligence is powered by the platform install base and grows more accurate as more operators deploy Flowtriq.