Skip to content
NeoProtect
NeoProtect

OOL Shield: detection pipelines for your network

The Out-of-Line Shield serves sFlow / sampling-capable networks reactively: it tracks, alerts and actions on irregularities found by fully customisable Detection Pipelines you build yourself, in an intuitive admin UI. No inline tap; it watches from the telemetry your routers already export.

Samples in
Filter statements
Algorithm
Result handlers

Filter statements

Sequentially ordered statements decide which samples this pipeline observes, so each pipeline watches exactly the traffic you care about.

Detection algorithms

Matching samples run through VAD for volume anomalies and carpet bombing, or GAD for L3/L4 header anomalies; both highly configurable.

Result handlers

Each handler filters the results it cares about, then acts: alert, log, enable On-Premise filtering, or announce BGP / FlowSpec.

Detection pipelines

We build around your network, not the other way around

Detection Pipelines are the pillars of OOL Shield. Each one defines a single way of handling incoming samples, and you can run as many as your node's hardware allows. They are where the product's modularity, depth and breadth come from.

Filter the samples

Samples first traverse one or more sequentially ordered filter statements, so only the traffic you want observed in this pipeline is passed on. Everything else is left alone.

Run an algorithm

Matching samples are handed to a highly configurable detection algorithm:

VADvolume attack detection

Reads per-second IP traffic from samples to catch volume anomalies across multiple prefix lengths, including carpet bombing spread over many IPs.

GADgeneric anomaly detection

Checks L3/L4 protocol headers autonomously for anomalies, for accuracy-based, generic attack detection.

Hand off to result handlers

Algorithm results flow to result handlers. Each one filters for the results it should handle, by IP or other algorithm attributes, and then performs a defined action on everything it accepts.

Result handler actions

What a pipeline can do once it finds something

The same result can drive several handlers at once: log it, alert on it, and mitigate it. Actions range from a quiet notification to precise FlowSpec at the router edge.

Alerting

Notify your alert contacts over webhook, mail and more the moment a result matches.

Logging

Record algorithm results internally to review behaviour and tune new pipeline configurations.

API filter enablement

Switch on On-Premise filtering for the affected destination IPs: integrated, automated, on-demand mitigation.

Simple BGP announcements

Announce the destinations from a result with a chosen community, MED and attributes to a set of peers. Mainly for blackholing.

Advanced BGP announcements

Use previously collected route information to dynamically announce DFZ-routeable prefixes to protected upstreams under attack.

FlowSpec announcements

Match anomalous traffic or destinations and DROP, POLICE (rate-limit) or REDIRECT it at the router level, or to a scrubbing appliance.

Steer traffic at the edge of your network

Turn a detection result into a route: peer with your routers to announce and withdraw BGP routes, push FlowSpec rules, and scope detection sensitivity per logical zone. Blackhole, redirect or rate-limit at the edge.

Upstreams
Your routers
samples ↓↑ bgp · flowspec
OOL Shield
bgp & flowspec

Announce routes & FlowSpec rules

Simple and advanced BGP announcements for blackholing and dynamic DFZ-prefix steering to protected upstreams, plus FlowSpec rules that DROP, POLICE (rate-limit) or REDIRECT matched traffic at the router edge.

zones

Scope detection per zone

Group prefixes to tune detection sensitivity per service, game, web or DNS, across multiple prefix lengths.

Example use cases

The same pipeline model, many outcomes

Because the pipeline is yours to compose, OOL Shield fits almost any flow-based observation need. These are simply the patterns we see most often.

Accurate, automated blackholing

VAD spots a volume anomaly and a result handler blackholes the right prefix, including traffic spread thin across many IPs.

On-demand On-Premise protection

Auto-enable in-line filtering for attacked IPs the instant they come under pressure, then relax when it passes.

Autonomous detect-and-mitigate

GAD identifies an anomaly and a FlowSpec handler mitigates it end to end, with no human in the loop.

Re-route under attack

Dynamically announce DFZ-routeable prefixes to protected upstreams while an attack is in progress.

Redirect to scrubbing

Use FlowSpec redirect actioning to steer suspect traffic into protection appliances on demand.

Got your own idea?

If your network needs something the listed building blocks don't cover yet, reach out; we're always happy to integrate new functions, often at no cost.

Your hardware, your instance

A managed rental, isolated to you

You provide the hardware OOL Shield runs on, plus a separate management node or VPS for your own instance of the On-Premise / OOL management suite: API, Panel, Grafana and more. Because every customer is fully isolated, you don't depend on a single shared platform's uptime; that independence is itself an uptime factor.

  • Sold as a managed software rental for business, enterprise, hosting & ISP networks
  • Your own isolated instance: API, Panel, Grafana and more
  • Stores samples short-term and analyses them per pipeline
typical node requirements
  • Bandwidth1–100G to your sFlow sources
  • Memory8–32 GB RAM
  • Processor4–6+ cores
  • ConnectivityInternet connection

Sizing depends on your network and sample rate; our team helps you pick the right hardware.

From the first “Hi!” to production

A guided path to going live

OOL Shield is priced on your 95th-percentile traffic and support plan. Setup is largely automated, with engineers checking every deployment before it carries production traffic.

  1. 01

    Reach out to sales

    Share your urgency, setup and questions. We clarify the basics and prepare a quote.

  2. 02

    Engineering implements with you

    After the quote is agreed, engineers ensure a smooth rollout over chat or scheduled calls. Setup is largely automated.

  3. 03

    Production-readiness review

    Engineering reviews the deployment one last time to confirm it is ready for production.

  4. 04

    Staged go-live

    Test on single prefixes or a slice of traffic, then move to full production when ready.

The reactive plane of the platform

OOL Shield is the optional, out-of-line companion to On-Premise Shield's in-line filtering. Together they cover proactive and reactive mitigation, managed from the same self-hosted suite on your own infrastructure.

  • Reactive detection from sFlow / sampling telemetry
  • Detection Pipelines you compose yourself, no code
  • Priced on your traffic, separately billed

Add the out-of-line plane

Tell us which devices export sFlow and how your edge peers, and we'll scope OOL Shield and the pipelines you need onto your deployment.

Get protected Talk to sales