NETSCOUT®, a company specializing in observability, AIOps, cybersecurity, and DDoS attack protection, has unveiled an enhancement to its Adaptive DDoS Protection (ADP) solution.
This latest extension enables service providers to automatically detect and control outbound DDoS attack traffic, providing more comprehensive protection from the attack's origin.
Multi-terabit Attacks
The protection strategies now include measures to stop compromised subscriber devices from disrupting networks, conserving bandwidth, and preventing attacks on other entities on the internet. The threat primarily comes from consumer devices, such as routers and cameras, that are increasingly being exploited by Turbo-Mirai class botnets.
These botnets can launch multi-terabit attacks that may lead to significant service disruptions
These botnets can launch multi-terabit attacks that may lead to significant service disruptions, reputational harm, and increased transit costs for service providers. By identifying and neutralizing this malicious traffic at its origin, service providers can mitigate service outages, reduce complaints and costs, and improve network security, effectively reducing subscriber churn and regulatory risk.
Vulnerable IoT Devices
Patrick Donegan, founder and principal analyst at HardenStance, highlighted the risks associated with high-speed broadband connectivity and susceptible IoT devices.
"The combination has been weaponized by a new class of massive DDoS botnets," he said, emphasizing source-side mitigation as a critical aspect of defense. NETSCOUT's approach, supported by its ATLAS Intelligence Feed (AIF) and ASERT analysts, provides service providers with necessary tools to detect and prevent DDoS attacks, thereby safeguarding their customers and the internet at large.
Comprehensive Threat Intelligence
By employing AI-powered threat intelligence and leveraging automated detection and mitigation, NETSCOUT's ADP solution, an integral component of its Arbor Sightline and Arbor Threat Mitigation System, effectively:
- Identifies and mitigates evolving attacks through dynamic detection and adaptive measures.
- Enhances its capabilities by focusing on outbound traffic, utilizing customized detection and comprehensive threat intelligence specific to each ISP.
- Analyses large volumes of outbound traffic with proprietary AI/ML-powered DDoS detection methods to spot attacks concealed within legitimate data flows.
- Utilizes global real-time intelligence on DDoS activity, monitoring roughly half of all internet traffic, to rapidly detect and nullify DDoS threats and identify compromised devices.
Emerging Service Provider Challenges
Darren Anstee, NETSCOUT's CTO for security, noted, "We are extending DDoS defense from the target to the source." With enhanced internet-scale visibility, NETSCOUT can develop localized threat intelligence for its customers, detecting and suppressing attacks at their origin before they cause local or targeted issues. This advancement provides service providers with a robust defense strategy across various networks, including peering, transit, cloud, and customer edges.
This capability expansion reflects how NETSCOUT utilizes its global threat insights and established ADP solutions to tackle emerging challenges faced by service providers. By evolving from handling inbound DDoS attacks to addressing outbound and cross-bound threats, NETSCOUT enables operators to improve network resilience, manage costs, and protect revenue through solutions like Arbor Sightline and Arbor TMS.
NETSCOUT®, a provider of observability, AIOps, cybersecurity, and DDoS attack protection solutions, today announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic.
By extending protection from the attack target towards its source, NETSCOUT helps operators prevent compromised subscriber devices from disrupting their own networks, consuming costly capacity and attacking customers and organizations across the internet.
Multi-terabit attacks
Consumer broadband routers, cameras and other IoT devices are increasingly being weaponised by Turbo-Mirai class botnets capable of generating multi-terabit attacks.
These outbound attacks have already caused costly service outages, reputational damage and customer loss, and damage to peering relationships risking a large increase in transit costs at service providers around the world. By detecting and mitigating malicious traffic generated by compromised device populations before it leaves their networks, service providers can reduce abuse complaints and infrastructure costs while protecting their own networks and services and helping lower subscriber churn and regulatory risk.
Vulnerable IoT devices
“The combination of higher-speed broadband connectivity and vulnerable IoT devices has been weaponised by a new class of massive DDoS botnets,” said Patrick Donegan, founder and principal analyst, HardenStance.
“Source-side mitigation, or attack suppression as it’s sometimes known, is a critical part of the equation. NETSCOUT’s approach, backed by its ATLAS Intelligence Feed (AIF) and ASERT analysts, gives service providers the tools they need to detect and stop attacks before they have an impact, protecting their customers and the broader internet from the large-scale DDoS attacks we have seen.”
Comprehensive threat intelligence
Using AI-powered threat intelligence and automated detection and mitigation, NETSCOUT’s ADP solution, an addition to its Arbor Sightline and Arbor Threat Mitigation System:
- Automatically detects and mitigates ever evolving attacks through dynamic detection, intelligent redirection and adaptive mitigation
- Extends these capabilities to outbound traffic, combining enhanced, customized detection with comprehensive threat intelligence tailored for each ISP
- Uses NETSCOUT’s proprietary AI/ML-powered DDoS detection to analyze massive volumes of outbound internet traffic to uncover attacks designed to hide within legitimate flows
- Draws on unique global real-time intelligence of DDoS activity covering approximately half of all internet traffic to rapidly detect and mitigate DDoS attacks and pinpoint the responsible, compromised devices
Emerging service provider challenges
“We are extending DDoS defense from the target to the source,” stated Darren Anstee, CTO for security, NETSCOUT. “By using our internet-scale visibility to derive localised threat intelligence for our customers, NETSCOUT can identify and precisely suppress attacks at their origin, before they cause problems locally or at their target. This capability gives our customers a new level of comprehensive defense across their peering, transit, cloud and customer edges.”
This expansion of capabilities demonstrates how NETSCOUT is applying its global threat visibility and proven ADP solution to meet emerging service provider challenges. By extending an established inbound DDoS workflow to outbound and cross-bound threats, NETSCOUT enables operators to improve network-resilience, cost-controls and revenue protection through its proven Arbor Sightline and Arbor TMS solutions.