DDoS Detection for Network Operators at NANOG 97 | Flowtriq
Detection, Mitigation & Response

Detect and mitigate DDoS attacks in under 1 second, respond automatically, and keep your users informed.

All features →
Learn
Documentation Quick Start API Reference Agent Setup DDoS Protection Landscape State of DDoS 2026 REPORT Free Certifications NEW
Research & Guides
Mirai Botnet Kill Switch Research memcached Amplification Dynamic Baselines PCAP Forensics PagerDuty Setup
Company
About Us Partners Whitelabel / Reseller Affiliate Program Pay with Crypto System Status
Legal & Support
Contact Us Security Trust Center Terms Privacy SLA
Who Uses Flowtriq

From indie hosts to ISPs, see how teams like yours use Flowtriq to detect and stop DDoS attacks.

Talk to Us →
Infrastructure
Hosting Providers ISPs MSPs/MSSPs Small Operators Routers Edge Node Defense
Gaming
Game Server Hosting Game Studios
Business
SaaS Platforms E-Commerce Financial Services Compliance
NANOG 97 · Bellevue, WA · June 1–3, 2026

The DDoS detection tool
NANOG operators are switching to.

NANOG 97 brings together North America's top ISPs, carriers, and network engineers. If automated BGP FlowSpec and sub-second detection are on your shortlist, Flowtriq is $9.99/node/month — no dedicated server, no NetFlow infrastructure, no enterprise sales process.

No credit card pip install ftagent BGP FlowSpec included 60-second setup

Built for the NANOG community

The same operators who debate BGP policy at NANOG are using Flowtriq to automate their DDoS response.

ISPs
Sub-second detection without flow taps or dedicated hardware — agent runs on existing hosts.
Tier-1 Carriers
Automated BGP blackhole and FlowSpec at transit scale. ExaBGP, GoBGP, BIRD 2, FRRouting.
IXP Members
Confidence-gated FlowSpec rules that protect peering without blunt blackholing.
Hosting Providers
Per-server detection across bare metal, VPS, and cloud. No scrubbing appliance needed.

The pricing reality

What FastNetMon actually costs in 2026

FastNetMon's LiveView dashboard ($70/user/month) launched April 2026 — on top of their $115+/month Advanced license. Here's the real total for a NOC team.

FastNetMon Advanced + LiveView for a 3-person NOC

Advanced license (10G): $115/month. LiveView dashboard: $70 × 3 users. Dedicated server: ~$100/month.

$115 + ($70 × 3) + ~$100 = ~$425/month
FastNetMon Advanced + LiveView

FastNetMon

  • $115/mo base + $70/user/mo dashboard
  • Dedicated server required (~$60–150/mo)
  • 30–60s latency via NetFlow
  • No PCAP forensics
  • Automated FlowSpec unreliable
  • Trial by application — gated
Flowtriq

Flowtriq — $9.99/node/month

  • $9.99/node/month — unlimited users, dashboard included
  • No dedicated server — runs on existing Linux hosts
  • <1s detection — kernel-level, unsampled
  • PCAP with pre-attack ring buffer
  • Confidence-gated FlowSpec + auto-rollback
  • 7-day free trial — no card, no application

Feature comparison

FastNetMon Advanced vs Flowtriq

The full technical breakdown for network engineers who need specifics.

CapabilityFastNetMon Advanced + LiveViewFlowtriq
Detection
Detection methodNetFlow / sFlow / IPFIX (sampled)  Kernel-level per-packet, unsampled
Detection latency  30–60s  <1 second
Attack classification  Flood type only  7 families + confidence score
L7 HTTP flood detection  L3/L4 only  Access log parsing
Botnet source flagging  No  300+ known botnet sources
BGP & Mitigation
BGP RTBH blackhole  Yes  Yes
BGP FlowSpec  Advanced only  Included at $9.99/node
Automated FlowSpec  Manual (false positives block automation)  Confidence-gated + auto-rollback
BGP speaker supportExaBGP, GoBGP  ExaBGP, GoBGP, BIRD 2, FRRouting
Detection → BGP in <2s  No  Yes
iptables / nftables / XDP  Script-based  46 automated rule types
Forensics & Evidence
PCAP capture  Not available  Pre-attack ring buffer + analyzer
AI incident summaries  No  Yes
Hash-chained audit log  No  SHA-256
Operations
Web dashboard  +$70/user/mo  Included, unlimited users
REST API + Terraform  API Advanced only; no Terraform  Both included
Prometheus metrics  Advanced only  15+ metric families
Dedicated server required  Yes (~$60–150/mo)  No
Setup time  Hours  60s: pip install ftagent

Technical architecture

How Flowtriq works

For network engineers who need to understand the stack before trusting it with production traffic.

Kernel-level capture

AF_PACKET + BPF — every packet header, unsampled, at line rate. No NetFlow infrastructure. No router changes required.

EWMA dynamic baselines

Per-node baselines via EWMA. Auto-learns in ~5 minutes. No manual thresholds. Handles diurnal patterns and traffic growth without false positives.

Confidence-gated FlowSpec

FlowSpec fires only above a confidence threshold. Auto-rollback on confidence drop. Supports ExaBGP, GoBGP, BIRD 2, FRRouting.

PCAP ring buffer

Rolling pre-attack buffer. At incident declaration, the buffer is flushed and attached — packet-level evidence from before the attack peaked.

Lightweight agent

<30 MB RAM, <0.1% CPU idle. systemd service. Any Linux kernel ≥ 3.10. No DPDK, no PF_RING, no kernel module.

Multi-tenancy

Workspace-based RBAC (Owner, Admin, Analyst, Readonly). ISPs manage customer nodes under separate workspaces with isolated alerting and reporting.

Deploy before NANOG 97 — no application required

7 days full access. No credit card. No bandwidth questionnaire. Ship on any Linux server you already operate in 60 seconds.

Get Started Free → Full FastNetMon Comparison
pip install ftagent  ·  Linux kernel ≥ 3.10  ·  BGP FlowSpec included

More resources