This white paper proposes a multi-tier architecture for protecting against distributed denial of service (DDoS) attacks. It recommends using a cloud-based DDoS protection service to mitigate volumetric attacks, while using on-premises network and application defense tiers to handle asymmetric and computational attacks. The network defense tier uses firewalls and load balancers to protect network layers, while the application defense tier uses web application firewalls and ADCs to inspect application traffic in depth. This hybrid cloud/on-premises architecture is designed to defend against all categories of DDoS attacks.