One License for the Entire Network. How We Calculate the Cost of Anti-DDoS Protection in LiveShield

One License for the Entire Network. How We Calculate the Cost of Anti-DDoS Protection in LiveShield

One License for the Entire Network. How We Calculate the Cost of Anti-DDoS Protection in LiveShield

Choosing a system for protection against DDoS attacks usually starts with technical questions. But there comes a moment when you have to work out how much it will all cost. At LiveShield, we make that easier.

A price list that needs a spreadsheet

The typical licensing model of anti-DDoS systems on the market looks roughly like this: a separate license for the component responsible for detection, and a separate one for the filtering component. If the network has several edge routers exporting traffic data, each of them may require its own detection license. Filtering is sometimes billed per network interface. Want to process packets efficiently, bypassing the operating system stack? DPDK support is often yet another separately paid item on the invoice.

The list does not end there. There are one-time activation fees. A web panel for viewing traffic is sometimes an add-on billed per user: every person in the NOC who is supposed to see the charts is another item on the monthly bill. Technical support can be limited to a number of tickets per month, depending on the package purchased.

The result is that the answer to the simple question "how much will protecting our network cost" requires building a model: how many routers do we have, how many interfaces, how many locations, how many administrators will use the panel, do we need DPDK. And as the network grows, with a new node, a new router or a new server room, the license cost jumps, even though traffic may have changed only slightly.

There is one more detail worth attention: the way traffic is counted. Some solutions on the market license the sum of incoming and outgoing traffic. For an ISP with natural traffic asymmetry, this means paying for bandwidth that does not matter from the anti-DDoS protection perspective, because volumetric attacks come from outside.

How we solved this in LiveShield

When designing the LiveShield licensing model, we made one assumption: an operator should not have to wonder how much security will cost them. We make the license price depend on a single factor: the volume of traffic incoming to the network, expressed in Gbps. That is all.

What follows in practice:

It does not matter how many servers you run. The LiveShield modules (Manager, Analyser, Worker) can be placed on one machine or split across several; the license does not distinguish. A Worker can sit at every location where you have traffic, or a single Worker can serve everything.

It does not matter how many locations you have. A network spread across two, three or five server rooms is still one license. For pricing purposes we sum the incoming traffic from all locations, and that is the only number we care about.

It does not matter how many edge routers or interfaces you have. We add another BGP interconnect point, another port, and the license cost does not change.

We count only incoming traffic. We do not sum in + out. Traffic leaving your network does not raise the license price.

LiveShield licensing

Full functionality in every license

The second pillar of this model is the absence of functional variants. There is no "basic" and "enterprise" version, no modules to buy separately. Every LiveShield license, regardless of traffic volume, includes the full set:

  • attack detection based on analysis of a full copy of traffic (mirror), with a first reaction in even under a second
  • packet processing using DPDK as standard, with no additional license
  • mitigation via BGP FlowSpec, with automatic generation and distribution of rules to edge routers
  • BGP blackholing (RTBH), including selective blackholing
  • advanced filtering with dynamic learning of the attack pattern for TCP and UDP traffic
  • detection of distributed carpet bombing attacks, with per-subnet aggregation
  • event pipelines: e-mail notifications and webhooks, configurable separately for different prefixes or customer groups
  • reporting supporting the reporting obligations arising from KSC/NIS2
  • a management panel with no user limit
  • full IPv4 and IPv6 support
On top of that, software updates during the license period.

Hardware does not complicate the bill either

LiveShield runs on-premise, on standard x86 servers with DPDK-compatible network cards. It does not require dedicated appliances or closed hardware. This means the infrastructure cost is predictable and remains fully under the operator's control, and the LiveShield license is completely independent of it. You can replace a server, add a second one, move a Worker to another location: the volume of incoming traffic is still the only variable in the price.

What is all this for?

The "one license, one parameter, full functionality" model is not a marketing trick but a consequence of how we think about the product. Anti-DDoS protection is supposed to work across the operator's entire network, and not only where the budget stretched to yet another component license. Artificially splitting functionality into variants leads to a situation in which the operator has detection but has to buy mitigation separately, and the attack will not wait for the purchasing process to close.

If you want to check how this model would translate to your network, one piece of information is enough: peak incoming traffic. Write to us at office@liveshield.net or use the form at liveshield.net. You can also view the panel yourself in the demo version: https://demo.liveshield.net

Don't wait for the next DDoS attack.
Contact us today!

Please check filled in fields for errors. If problem persists, contact us directly at office@liveshield.net

Thank you for reaching out to us!

Your message has been successfully sent.
We will get back to you as soon as possible.

Or call us directly

(+48) 880 779 307