NETSCOUT®, a company known for its solutions in observability, artificial intelligence for IT operations (AIOps), cybersecurity, and distributed denial-of-service (DDoS) attack protection, has announced significant improvements to its Arbor Edge Defense (AED) solution. These enhancements aim to bolster the security of enterprises' revenue-generating and mission-critical applications against complex DDoS attacks that can slip past content delivery network (CDN) defences.
The upgraded AED solution is designed to detect malicious activities masked behind shared CDN infrastructure. It employs precise, service-specific strategies to thwart these attacks without inadvertently blocking legitimate users who also utilise the same CDN. By revealing hidden sources, AED integrates a transparent proxy for decrypting and scrutinising application traffic, enabling the identification and mitigation of attacks at the application layer, which often go undetected by traditional CDN defences.
Insights on cyber risks
Christopher Rodriguez, a research director at IDC, noted that DDoS attacks aim to deplete an organisation's resources and pose substantial operational and financial risks. "These attacks pose significant operational and financial risk because adversaries can target multiple layers of an organisation’s infrastructure and rapidly shift attack methods," said Rodriguez. Effective DDoS protection requires a dynamic, high-performance approach capable of safeguarding essential services across the attack spectrum.
While CDNs are instrumental in enhancing digital experiences and managing the surge in traffic volumes, they do not entirely eliminate the threat of DDoS attacks. Dynamic applications, along with APIs and authentication services, remain exposed. Attackers can exploit these vulnerabilities by launching DDoS traffic that mimics legitimate user activity, thereby circumventing CDN defences which mainly target large-scale volumetric attacks.
Enhanced visibility and protection
The AED enhancements align with NETSCOUT’s broader portfolio of DDoS protection solutions
The additional capabilities provided by AED allow it to effectively defend against application-layer DDoS attacks that aim to drain resources at application, API, authentication, or infrastructure levels. AED restores visibility at the source level and facilitates accurate mitigation of CDN traffic, ensuring that only malicious traffic is blocked while preserving access for legitimate customers.
Scott Iekel-Johnson, AVP of Product Management at NETSCOUT, emphasises the necessity of extending protection beyond the CDN. "Attackers increasingly look for ways around defences, including targeting origin infrastructure directly or slipping through the CDN by mimicking legitimate traffic. AED closes those gaps by extending DDoS protection beyond the CDN, closer to the application itself," he stated, highlighting AED's role in securing critical applications while maintaining connectivity for genuine users.
Integration with existing infrastructure
The AED enhancements align with NETSCOUT’s broader portfolio of DDoS protection solutions, addressing the crucial juncture between shared cloud delivery systems and business-critical applications.
By providing an independent layer of security, AED complements existing CDN investments, allowing enterprises to enhance their security posture without the need for replacing their CDN provider. This integration secures critical operations and supports applications crucial to enterprises' revenue and service availability, providing resilience where potential attacks can have significant business consequences.
NETSCOUT®, a provider of observability, AIOps, cybersecurity, and DDoS attack protection solutions, announces enhancements to its Arbor Edge Defense (AED) solution that helps enterprises maintain the availability of revenue-generating and mission-critical applications against sophisticated DDoS attacks that evade or bypass content delivery network (CDN) DDoS defences.
The enhancements identify malicious sources concealed behind shared CDN infrastructure and apply precise, service-specific countermeasures to block attacks without denying access to legitimate customers using the same CDN.
Accelerating digital experiences
“Cybercriminals launch DDoS attacks for many reasons, but the ultimate outcome is to drain the targeted organisation’s resources,” said Christopher Rodriguez, research director, security and trust, IDC. “These attacks pose significant operational and financial risk because adversaries can target multiple layers of an organisation’s infrastructure and rapidly shift attack methods. Effective DDoS defence must be dynamic, highly performant, and broad enough to protect critical services across the attack surface.”
Organisations rely on CDNs to accelerate digital experiences and absorb large-scale traffic surges, but CDN deployment alone does not eliminate DDoS risk. Dynamic applications, APIs, authentication services, uncached requests, and exposed origin infrastructure can remain vulnerable. Attackers exploit these gaps by sending DDoS attacks disguised as application-layer traffic that resembles legitimate user activity. CDN DDoS defences can miss this traffic because they focus on detecting volumetric DDoS attacks and rely on generic protections that are not customised to the individual customer applications being protected.
Inspect application traffic
These advanced application-layer DDoS attacks bypass CDN DDoS protections to the customer data centre, causing outages and impacting revenue. Defenders must either allow the attack through or block it, including the legitimate traffic along with it. NETSCOUT restores source-level visibility and enables precise mitigation of all CDN traffic closer to the protected service.
The enhanced AED solution enables enterprises to:
- Reveal attack sources hidden by CDN proxies: AED integrates a high-performance TLS transparent proxy to decrypt and inspect application traffic, identify its true source from application headers, and apply precise application-layer DDoS countermeasures to block DDoS traffic that CDNs do not
- Stop application layer attacks: Detect traffic designed to exhaust application, API, authentication or infrastructure resources
- Protect applications with service-specific policies: Apply countermeasures tailored to the behaviour and requirements of each protected service
- Preserve legitimate customer access: Block malicious traffic precisely without denying service to broad ranges of users behind shared CDN infrastructure and without impacting other traffic arriving from the CDN proxy
- Defend direct and CDN-mediated traffic paths: Mitigate attacks that pass through the CDN as well as attacks that bypass it and target origin infrastructure directly
- Extend existing CDN investments: Add an independent layer of protection and visibility without requiring the enterprise to replace their CDN provider
Mimicking legitimate traffic
“Enterprises cannot assume that putting a CDN in front of an application protects every path attackers can use to reach it,” said Scott Iekel-Johnson, AVP, product management, NETSCOUT.
“Attackers increasingly look for ways around defences, including targeting origin infrastructure directly or slipping through the CDN by mimicking legitimate traffic. AED closes those gaps by extending DDoS protection beyond the CDN, closer to the application itself, securing the paths attackers still exploit, enabling enterprises to protect critical applications precisely while keeping legitimate customers connected.”
Business-critical applications
The AED enhancements extend NETSCOUT’s established DDoS protection portfolio into an increasingly important point of enterprise exposure: the connection between shared cloud delivery infrastructure and business-critical applications.
By complementing existing CDN investments rather than requiring organisations to replace them, AED helps customers address a significant area of exposure while extracting greater security value from current infrastructure investments. For enterprises whose revenue, operations and public services depend on application availability, this provides an additional layer of resilience at the point where an attack can have the greatest business impact.