ddos protection

overview

Check Point WAF SaaS provides integrated Distributed Denial-of-Service (DDoS) protection designed to maintain the availability, resiliency, and stability of customer-facing applications and APIs during malicious traffic events and large-scale denial-of-service attacks.

The service combines globally distributed traffic mitigation capabilities with application-layer security controls to automatically detect and mitigate a broad range of network and application-level attack vectors. DDoS protections are integrated directly into the Check Point WAF SaaS platform and operate continuously as part of the managed security service.

The platform is designed to minimize operational overhead for customers by automatically handling traffic analysis, attack detection, mitigation activation, and protection enforcement without requiring customer-side infrastructure changes or dedicated DDoS management expertise.

DDoS protection capabilities described in this document apply to Check Point WAF SaaS deployments only.

Disclaimer

DDoS mitigation uses adaptive detection and automated protections designed to block large-scale abusive traffic while minimizing impact on legitimate users.

During certain large-scale or highly distributed attacks, some requests may still reach the protected application until additional mitigations or manual tuning are applied. Requests containing malicious payloads continue to be inspected and enforced by the WAF security engine.

Additional controls such as geo-restrictions, rate limiting, or custom mitigation policies may be required in some attack scenarios.

This protection engine is available for CloudGuard WAF SaaS. It is not available with local editions of the product such as Gateway & Agent.

DDoS Protection Capabilities

Operational Visibility

Check Point WAF SaaS provides operational visibility into active DDoS events through the DDoS dashboard.

The dashboard is populated during attack events and provides visibility into attack timelines, mitigation activities, and attack-related operational details.

Check Point maintains 24x7 operational monitoring and DDoS response processes to support mitigation and service continuity during significant attack events.

Shared Responsibility & SLA Considerations

Check Point WAF SaaS is designed to provide automated DDoS detection and mitigation capabilities as part of the managed security service.

Check Point uses commercially reasonable efforts to detect, mitigate, and minimize the impact of denial-of-service attacks affecting protected customer applications and APIs.

The service does not provide a guaranteed mitigation-time SLA for all attack scenarios. However, DDoS protections are continuously monitored, maintained, and enhanced as part of ongoing platform operations and security engineering processes.

Check Point WAF SaaS is backed by Check Point enterprise-grade 24x7 operational support and monitoring processes to help maintain service availability and operational responsiveness during security events.

Summary

Check Point WAF SaaS delivers integrated enterprise-grade DDoS protection designed to help organizations maintain application availability during denial-of-service attacks while minimizing operational complexity.

The platform combines continuous traffic monitoring, automated attack detection, infrastructure and application-layer mitigation, AI-driven behavioral analysis, integrated bot protections, global resiliency architecture, and managed operational simplicity.

The DDoS Dashboard

The DDoS dashboard is populated when an attack happens and gives security teams live visibility and control of attack details. As needed, upon attack, you will also be contacted by our DRT team.

Example Scenario

An attacker launches a sophisticated HTTP/2 flood on your login API.