Back to PGHost
Security Architecture: Zero-Trust Anycast
Infrastructure Security

Security & DDoS Safeguards

How PGHost shields your Minecraft world, player databases, and network ports against attacks and corruption.

1. Multi-Layered 100 Gbps Anti-DDoS Mitigation

Every server IP is protected by our edge scrubbing matrix:

  • Layer 3 & 4: Automated filtering for SYN Floods, UDP Amplification, ICMP Floods, and fragmented packet streams.
  • Layer 7 (Minecraft Specific): Deep packet inspection for Handshake/Ping botnets, query flooder exploits, and invalid login spam.
  • No Blackholing: Legitimate player traffic continues uninterrupted while attack packets are silently dropped at the BGP edge.

2. Kernel-Space WireGuard Isolation

Node daemon communication uses private cryptographic WireGuard tunnels. Containers cannot communicate horizontally across the private subnet, eliminating cross-server vulnerabilities.

3. Automated Snapshot Redundancy

World data is safeguarded with daily snapshots copied to encrypted off-site S3 storage buckets. In the event of catastrophic player griefing or plugin corruption, admins can revert to a clean checkpoint in seconds.