When purchasing high-defense DDoS services, almost everyone encounters the terms "guaranteed protection" and "elastic protection" on the pricing page. Two figures representing bandwidth (in Gbps) are displayed side-by-side, yet the prices differ vastly. Many people are confused: exactly which level of protection am I buying? How much traffic can it actually withstand during an attack? The answer to this question determines a critical factor: whether your chosen plan can actually safeguard your business during a real-world attack.
Let’s first clear up a common misconception. Many people see "50G guaranteed + 200G elastic" and instinctively assume the total protection capacity is 250G. This is incorrect.
The protection capacity is defined by the higher of the two values—guaranteed protection bandwidth or elastic protection bandwidth. Elastic protection bandwidth is not an increment added *on top* of the guaranteed amount; rather, it represents the absolute upper limit of the instance's defense capability against attacks.
Here is an example: 30G guaranteed and 100G elastic. An 80G attack occurs. The actual protection capacity is 100G, not 130G. The excess 50G (the 80G attack minus the 30G guaranteed capacity) is handled via the elastic protection channel, incurring a daily post-paid charge. If the attack exceeds 100G, the instance triggers "blackhole routing," cutting off all traffic.
Therefore, when selecting a plan, the elastic protection bandwidth represents the actual upper limit of the attack volume you can withstand. The guaranteed capacity determines the threshold below which you incur no extra costs, while the elastic capacity determines the point at which your business operations would fail.
Guaranteed Protection: The Pre-paid "Baseline Defense"
Guaranteed protection bandwidth is the specification selected at the time of purchase, utilizing a pre-paid model (billed monthly or annually). It provides continuous, baseline protection; this defense capability remains active regardless of whether an attack is occurring.
Its primary function is to handle routine, day-to-day attacks. If your business occasionally faces small-scale DDoS attacks where the peak attack volume consistently stays within your baseline protection bandwidth, you simply pay a fixed monthly or annual fee without incurring any additional charges.
Baseline protection specifications typically start at 5 Gbps or 10 Gbps, with mainstream plans ranging from 30 Gbps to 100 Gbps. Pricing is relatively transparent.
Baseline protection has a feature that is easily overlooked: it can be upgraded but not downgraded. If you purchase a 30 Gbps plan and find it insufficient, you can pay extra to upgrade to 60 Gbps or 100 Gbps. However, if you later decide 30 Gbps is more than you need and want to downgrade to 10 Gbps, you cannot do so. Therefore, when selecting a baseline specification, it is better to choose a tier slightly above your historical average attack volume rather than cutting it too close to save money.
Elastic Protection: A Pay-As-You-Go "Burst Buffer"
Elastic protection bandwidth represents an extended upper limit beyond the baseline, utilizing a daily pay-as-you-go model. The trigger condition is clear: elastic protection activates and incurs charges only when the peak attack volume exceeds the baseline bandwidth but remains below the elastic bandwidth limit.
There is a key detail to understand here: elastic protection is not a service you "automatically purchase," but rather an "upper threshold" you actively configure. You can set the elastic bandwidth to match the baseline in the console; this effectively disables elastic protection, meaning no pay-as-you-go charges will be incurred. If you set it to 200 Gbps, you are authorizing the service provider to handle attacks up to 200 Gbps when they exceed the baseline, with the excess portion billed on a daily basis.
Billing rules are often where confusion arises. The system calculates the difference between the day's peak attack volume and the baseline bandwidth; the billing rate is then determined by the specific tier into which that difference falls.
For example, suppose the baseline is 30 Gbps and the peak attack volume for the day is 80 Gbps. The difference is 80 - 30 = 50 Gbps. If your system is attacked three times in a single day with peak volumes of 40 Gbps, 60 Gbps, and 80 Gbps, you are billed for only one instance based on the highest peak (80 Gbps); the charges do not stack.
There is a "black hole trap" here that is easily overlooked: if the attack peak exceeds the upper limit of your elastic protection—for instance, if you set the elastic limit to 100 Gbps but an attack hits at 120 Gbps—the entire instance is immediately sent to a "black hole," and all traffic is blocked. Furthermore, no elastic protection fee is incurred in this scenario, because the service provider did not actually defend against the attack; they simply blocked the IP address.
A concept easily confused with the above: Elastic Service Bandwidth.
You will frequently encounter the term "Elastic Service Bandwidth" in search results. It is distinct from "Elastic Protection Bandwidth," though the names are similar enough to cause confusion.
Elastic Protection Bandwidth deals with DDoS attack traffic. When an attack exceeds your baseline capacity, elastic protection kicks in, and you are billed based on the attack's peak volume.
Elastic Service Bandwidth deals with normal business traffic. For example, if your website's usual traffic is 100 Mbps but spikes to 300 Mbps during the evening peak—exceeding your purchased baseline service bandwidth—Elastic Service Bandwidth allows for a "temporary capacity expansion." You are charged for the excess traffic, preventing your normal traffic from being throttled.
The billing logic differs for each as well. Elastic protection is priced based on the range into which the difference between the attack peak and the baseline falls. Elastic Service Bandwidth is typically calculated using the "daily 6th-highest peak" or "monthly 95th-percentile peak," aligning more closely with standard bandwidth billing models.
A simple way to remember: Elastic Protection handles "being attacked," while Elastic Service Bandwidth handles "normal user traffic."
How to choose: Work backward from your attack profile.
Once you understand the distinction between baseline capacity and elastic capacity, the logic for selecting the right option becomes clear. If your business has never been hit by a DDoS attack, or only faces occasional low-volume harassment (under 10 Gbps): Select a baseline protection tier that matches the peak attack volume you anticipate, and set the elastic limit to match that baseline (effectively disabling elasticity). This way, you pay only a fixed monthly fee and avoid unexpected pay-as-you-go charges.
If you occasionally face attacks exceeding your baseline, but not frequently: Set your baseline based on the historical average peak attack volume, and set the elastic limit to 1.2–1.5 times the historical maximum peak. This allows you to pay the baseline fee most of the time while incurring a daily elastic charge only when hit by a larger attack—a more cost-effective approach than purchasing a high-baseline package upfront.
If you are under constant attack or your business is extremely sensitive to service interruptions: Select the highest baseline tier you can afford and set the elastic limit significantly higher than the baseline. This is crucial because if an attack exceeds the elastic limit and triggers "blackholing" (traffic dropping), your service will go offline. For sectors like e-commerce, gaming, and finance—where even a one-second outage means financial loss—the cost of blackholing far outweighs the expense of pay-as-you-go elastic protection.
Reminder: Bills for elastic protection are generated early the following morning. If your account balance is insufficient to cover the charges, elastic protection will be suspended, though baseline protection remains unaffected. Therefore, if you enable elastic protection, ensure you maintain an adequate account balance or set up low-balance alerts.