Home InternationalIntroducing Programmable Flow Protection: custom D...
International⭐ Featured

Introducing Programmable Flow Protection: custom DDoS mitigation logic for Magic Transit customers

Magic Transit customers can now program their own DDoS mitigation logic and deploy it across Cloudflare’s global network. This enables precise, stateful mitigation for custom and proprietary UDP protocols.

6 April 2026 at 07:18 pm
1 views
Introducing Programmable Flow Protection: custom DDoS mitigation logic for Magic Transit customers

Cloudflare has announced the launch of Programmable Flow Protection, a new feature designed to empower Magic Transit customers with the ability to create their own custom DDoS mitigation logic. This innovative system allows users to deploy their own protocol-specific rules across Cloudflare's global network, providing precise, stateful mitigation for custom and proprietary UDP-based protocols.

Programmable Flow Protection is a response to the long-standing challenge of protecting custom or proprietary UDP protocols, which have traditionally been difficult for Cloudflare's DDoS mitigation systems to handle effectively. Unlike well-known protocols like TCP, UDP lacks a handshake or stateful connections, making it challenging for existing systems to identify and mitigate attacks.

Cloudflare's existing DDoS mitigation solutions, such as Advanced TCP Protection and Advanced DNS Protection, are built on the understanding of specific protocol characteristics. For instance, Advanced TCP Protection uses known characteristics of the TCP protocol to challenge and verify the legitimacy of incoming traffic. Similarly, Advanced DNS Protection builds a per-customer profile of DNS queries to identify and mitigate DNS attacks. However, these systems struggle with custom or proprietary UDP protocols due to the lack of relevant protocol knowledge.

Programmable Flow Protection addresses this gap by allowing customers to write their own eBPF programs that define what constitutes "good" and "bad" packets and how to handle them. These programs are then executed across Cloudflare's entire global network, enabling the system to drop or challenge "bad" packets before they reach the customer's origin. This level of customization and flexibility ensures that DDoS attacks of any scale can be effectively mitigated.

The feature is currently in beta and available to all Magic Transit Enterprise customers for an additional cost. Customers interested in joining the beta can contact their account team or sign up on the designated page.

The introduction of Programmable Flow Protection underscores Cloudflare's commitment to providing tailored solutions for its customers' unique needs. By empowering users with the ability to create custom DDoS mitigation logic, Cloudflare is further solidifying its position as a leader in cybersecurity and network protection.

In the ever-evolving landscape of cyber threats, the ability to adapt and respond to new challenges is crucial. With Programmable Flow Protection, Magic Transit customers can now take control of their DDoS mitigation strategies, ensuring that their custom and proprietary UDP protocols are protected against sophisticated attacks. This innovative feature not only enhances security but also fosters a more resilient and adaptable ecosystem for businesses and organizations reliant on custom network protocols.

📰 Related News
Ollama 0.2.6 Released with Native Gemma 4 Support and Enhanced Performance
Ollama 0.2.6 Released with Native Gemma 4 Support and Enhanced Performance
Ollama 0.2.6 is now live, featuring native support for Google's Gemma 4 models and improved local inference performance for Windows, macOS, and Linux.
14 Apr
Weekly news roundup: Shortages spread to MLCCs; SK Hynix reportedly in talks with Microsoft and Google
Weekly news roundup: Shortages spread to MLCCs; SK Hynix reportedly in talks with Microsoft and Google
Below are the most-read DIGITIMES Asia stories from the week of April 6-April 13, 2026:
14 Apr
cutile-stencil 0.2.0
cutile-stencil 0.2.0
An xDSL-based stencil compiler that generates optimized GPU kernels via NVIDIA cuTile
14 Apr
merlin-llm added to PyPI
merlin-llm added to PyPI
Merlin — a fast local LLM for agentic coding on Apple Silicon
14 Apr
Fluent Cut - Craft and compose videos programmatically in PHP with an elegant fluent API
Fluent Cut - Craft and compose videos programmatically in PHP with an elegant fluent API
Craft and compose videos programmatically in PHP with an elegant fluent API - b7s/fluentcut
14 Apr
Crypto Investor at Center of Trump Corruption Allegations Now Sees Himself as ‘Victim’
Crypto Investor at Center of Trump Corruption Allegations Now Sees Himself as ‘Victim’
Justin Sun has accused Trump-affiliated World Liberty Financial of misconduct and a general lack of transparency.
14 Apr
nvidia-nat-weave 1.7.0a20260413
nvidia-nat-weave 1.7.0a20260413
Subpackage for Weave integration in NeMo Agent Toolkit
14 Apr
nvidia-nat-s3 1.7.0a20260413
nvidia-nat-s3 1.7.0a20260413
Subpackage for S3-compatible integration in NeMo Agent Toolkit
14 Apr
Social Security Trust Fund to Run Dry in 2032: Just 6 Years From Now
Social Security Trust Fund to Run Dry in 2032: Just 6 Years From Now
Six years. That is how much time separates retirees from a Social Security system that, by its own projections, runs out of money. If you are 56 years old...
14 Apr
cane-gpu-perf added to PyPI
cane-gpu-perf added to PyPI
GPU inference benchmarking with opinionated diagnostics
13 Apr