NETSCOUT® has announced an extension to its Adaptive DDoS Protection (ADP) solution, which now allows service providers to automatically identify and mitigate outbound DDoS attack traffic.
This advancement aims to enhance the security framework by focusing on the source of attacks, thus preventing compromised subscriber devices from disrupting networks, conserving capacity, and attacking entities across the internet.
Challenges posed by multi-terabit attacks
Increasingly, consumer broadband routers, cameras, and other IoT devices are being exploited by Turbo-Mirai class botnets, which are capable of launching multi-terabit attacks.
These outbound attacks have resulted in significant service outages, reputational harm
These outbound attacks have resulted in significant service outages, reputational harm, customer attrition, and impaired peering relationships, potentially escalating transit costs for service providers globally. By identifying and managing malicious traffic before it exits their networks, service providers can alleviate abuse complaints and infrastructure expenses, while safeguarding their own networks and services and reducing subscriber turnover and regulatory risk.
The threat of vulnerable IoT devices
Patrick Donegan, founder and principal analyst at HardenStance, stated, “The combination of higher-speed broadband connectivity and vulnerable IoT devices has been weaponised by a new class of massive DDoS botnets."
"Source-side mitigation, or attack suppression as it’s sometimes known, is a critical part of the equation. NETSCOUT’s approach, backed by its ATLAS Intelligence Feed (AIF) and ASERT analysts, gives service providers the tools they need to detect and stop attacks before they have an impact, protecting their customers and the broader internet from the large-scale DDoS attacks we have seen.”
Leveraging comprehensive threat intelligence
NETSCOUT's proprietary AI/ML-powered DDoS detection analyses vast amounts of outbound internet traffic
NETSCOUT employs AI-driven threat intelligence alongside automated detection and mitigation for its ADP solution, integrated into its Arbor Sightline and Arbor Threat Mitigation System. The system automatically detects and mitigates evolving attacks via dynamic detection, intelligent redirection, and adaptive mitigation.
It provides these capabilities for outbound traffic by merging enhanced detection with tailored threat intelligence for individual ISPs. Additionally, NETSCOUT's proprietary AI/ML-powered DDoS detection analyses vast amounts of outbound internet traffic to identify malicious activities concealed within legitimate flows, using unique global real-time threat intelligence to swiftly detect and mitigate DDoS attacks and identify the compromised devices responsible.
Addressing emerging provider challenges
Darren Anstee, CTO for security at NETSCOUT, explained, “We are extending DDoS defence from the target to the source. By using our internet-scale visibility to derive localised threat intelligence for our customers, NETSCOUT can identify and precisely suppress attacks at their origin, before they cause problems locally or at their target. This capability gives our customers a new level of comprehensive defence across their peering, transit, cloud and customer edges.”
This enhancement of capabilities illustrates NETSCOUT's commitment to applying its global threat visibility and established ADP solution to address new challenges faced by service providers. By extending the existing inbound DDoS workflow to encompass outbound and cross-bound threats, NETSCOUT assists operators in bolstering network resilience, controlling costs, and safeguarding revenue through its tried and tested Arbor Sightline and Arbor TMS solutions.
