NetScout Systems. Inc. - Experts & Thought Leaders
Latest NetScout Systems. Inc. news & announcements
NETSCOUT®, a provider of observability, AIOps, cybersecurity, and DDoS attack protection solutions, expands its data platform to provide the trusted operational context required to build the foundation for enterprise AI. The NETSCOUT data platform observes digital interactions, converts packets into high-fidelity, compact, contextualised evidence in real time, and curates that evidence at scale for observability, service assurance, cybersecurity, and AI. This addresses a growing barrier to enterprise AI adoption: increasingly capable models still cannot deliver reliable operational decisions when the data supplied to them is incomplete, noisy, fragmented, or stripped of context. Traditional metrics, events, logs, and traces (MELT data) remain important, but often require AI systems to reconstruct what happened after telemetry has been sampled, aggregated, or separated across tools. That increases inference, compute requirements, token consumption, and the risk of an inaccurate recommendation. Semantic representations of data Gartner predicts that by 2027, organisations that prioritise semantics in AI-ready data will increase their agentic AI accuracy by up to 80 percent and reduce costs by up to 60 percent. Agentic AI outcomes depend on context, including semantic representations of data. The need for trusted context becomes even more consequential as AI agents progress from advising operators to taking autonomous action. "Unlocking the benefits of AI across the enterprise will not be achieved by adding another model. It will succeed through context engineering: giving AI the right operational context before reasoning begins,” said Sanjay Munshi, chief operating officer, NETSCOUT. AI-driven analysis “NETSCOUT turns observed digital interactions into grounded-truth evidence. Through our own internal testing we experienced more than a 25 percent reduction in AI token consumption compared with MELT only data, and more than a 75 percent reduction in MTTK. Compact, context-rich operational intelligence helps our customers improve decision confidence, lower the cost of AI-driven analysis, and establish the control required to move from AIOps recommendations toward safe, autonomous operations.” IDC expects 80 percent of agentic AI use cases will require real time, contextual, and widely accessible data and states that the goal is to create a trusted, real time data environment where AI can reason, decide, and act with the right context and guardrails. Improving decision confidence NETSCOUT produces Smart Data via a unique architectural approach, bringing together two complementary capabilities that improve context engineering: Early semantic extraction: NETSCOUT derives operational meaning from packets at the point of observation, preserving evidence that can disappear in conventional datasets. Context optimisation at source: NETSCOUT delivers higher-density, relevant context so AI systems can spend less of their context window and compute budget. AI-ready operational evidence Together, these capabilities deliver an AI-ready operational evidence layer that complements existing observability investments and can support human operators, analytics platforms, large language models, copilots, and AI agents. Smart Data is embedded across NETSCOUT solutions and can be integrated into enterprise data and AI workflows, enabling customers to use the operational intelligence within their chosen technology ecosystems. By meeting organisations wherever they are in their operational and AI transformation, NETSCOUT’s data platform helps customers: Operate more productively: Equip NetOps, SecOps, DevOps, SRE, and service teams with natural-language access to detailed operational evidence, accelerating investigation and helping resolve issues faster. Optimise token cost: Reduce the volume of low-value data AI must process by increasing signal density, helping organisations manage telemetry, storage, token, and compute costs without sacrificing the context required to understand service behaviour. Automate with greater confidence: Provide AI systems with independently observed, explainable evidence to support recommendations, governance, auditability, and the controlled progression from assisted operations to agentic action. Data centre transformation This common foundation provides AI systems with evidence-based operational context suitable for governed automation and agentic workflows, and supports observability, cybersecurity, service assurance, cloud and data centre transformation, and business-service resilience. It can help teams and agents expose hidden dependencies, distinguish infrastructure failures from application issues, identify protocol and security exposures, and understand the operational impact of an event across hybrid, multi-cloud, containerised, virtual, and physical environments. As access to AI models broadens and model capabilities converge, the quality, completeness, and token efficiency of the context supplied to those models becomes a more lasting source of differentiation. Trusted operational intelligence layer NETSCOUT extends the value of its core deep packet inspection-at-scale technology into a new growth arena: providing the trusted operational intelligence layer for enterprise AI and automation. For customers, this means a path to adopt AI without abandoning existing workflows or compromising visibility. For technology partners, it creates a source of curated, network-derived intelligence that can strengthen analytics and automation. For others, it demonstrates how NETSCOUT can apply its differentiated data foundation across observability, cybersecurity, AIOps, and AgenticOps.
NETSCOUT®, a provider of observability, AIOps, cybersecurity, and DDoS attack protection solutions, announces enhancements to its Arbor Edge Defense (AED) solution that helps enterprises maintain the availability of revenue-generating and mission-critical applications against sophisticated DDoS attacks that evade or bypass content delivery network (CDN) DDoS defences. The enhancements identify malicious sources concealed behind shared CDN infrastructure and apply precise, service-specific countermeasures to block attacks without denying access to legitimate customers using the same CDN. Accelerating digital experiences “Cybercriminals launch DDoS attacks for many reasons, but the ultimate outcome is to drain the targeted organisation’s resources,” said Christopher Rodriguez, research director, security and trust, IDC. “These attacks pose significant operational and financial risk because adversaries can target multiple layers of an organisation’s infrastructure and rapidly shift attack methods. Effective DDoS defence must be dynamic, highly performant, and broad enough to protect critical services across the attack surface.” Organisations rely on CDNs to accelerate digital experiences and absorb large-scale traffic surges, but CDN deployment alone does not eliminate DDoS risk. Dynamic applications, APIs, authentication services, uncached requests, and exposed origin infrastructure can remain vulnerable. Attackers exploit these gaps by sending DDoS attacks disguised as application-layer traffic that resembles legitimate user activity. CDN DDoS defences can miss this traffic because they focus on detecting volumetric DDoS attacks and rely on generic protections that are not customised to the individual customer applications being protected. Inspect application traffic These advanced application-layer DDoS attacks bypass CDN DDoS protections to the customer data centre, causing outages and impacting revenue. Defenders must either allow the attack through or block it, including the legitimate traffic along with it. NETSCOUT restores source-level visibility and enables precise mitigation of all CDN traffic closer to the protected service. The enhanced AED solution enables enterprises to: Reveal attack sources hidden by CDN proxies: AED integrates a high-performance TLS transparent proxy to decrypt and inspect application traffic, identify its true source from application headers, and apply precise application-layer DDoS countermeasures to block DDoS traffic that CDNs do not Stop application layer attacks: Detect traffic designed to exhaust application, API, authentication or infrastructure resources Protect applications with service-specific policies: Apply countermeasures tailored to the behaviour and requirements of each protected service Preserve legitimate customer access: Block malicious traffic precisely without denying service to broad ranges of users behind shared CDN infrastructure and without impacting other traffic arriving from the CDN proxy Defend direct and CDN-mediated traffic paths: Mitigate attacks that pass through the CDN as well as attacks that bypass it and target origin infrastructure directly Extend existing CDN investments: Add an independent layer of protection and visibility without requiring the enterprise to replace their CDN provider Mimicking legitimate traffic “Enterprises cannot assume that putting a CDN in front of an application protects every path attackers can use to reach it,” said Scott Iekel-Johnson, AVP, product management, NETSCOUT. “Attackers increasingly look for ways around defences, including targeting origin infrastructure directly or slipping through the CDN by mimicking legitimate traffic. AED closes those gaps by extending DDoS protection beyond the CDN, closer to the application itself, securing the paths attackers still exploit, enabling enterprises to protect critical applications precisely while keeping legitimate customers connected.” Business-critical applications The AED enhancements extend NETSCOUT’s established DDoS protection portfolio into an increasingly important point of enterprise exposure: the connection between shared cloud delivery infrastructure and business-critical applications. By complementing existing CDN investments rather than requiring organisations to replace them, AED helps customers address a significant area of exposure while extracting greater security value from current infrastructure investments. For enterprises whose revenue, operations and public services depend on application availability, this provides an additional layer of resilience at the point where an attack can have the greatest business impact.
NETSCOUT®, a provider of observability, AIOps, cybersecurity, and DDoS attack protection solutions, today announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent compromised subscriber devices from disrupting their own networks, consuming costly capacity and attacking customers and organisations across the internet. Multi-terabit attacks Consumer broadband routers, cameras and other IoT devices are increasingly being weaponised by Turbo-Mirai class botnets capable of generating multi-terabit attacks. These outbound attacks have already caused costly service outages, reputational damage and customer loss, and damage to peering relationships risking a large increase in transit costs at service providers around the world. By detecting and mitigating malicious traffic generated by compromised device populations before it leaves their networks, service providers can reduce abuse complaints and infrastructure costs while protecting their own networks and services and helping lower subscriber churn and regulatory risk. Vulnerable IoT devices “The combination of higher-speed broadband connectivity and vulnerable IoT devices has been weaponised by a new class of massive DDoS botnets,” said Patrick Donegan, founder and principal analyst, HardenStance. “Source-side mitigation, or attack suppression as it’s sometimes known, is a critical part of the equation. NETSCOUT’s approach, backed by its ATLAS Intelligence Feed (AIF) and ASERT analysts, gives service providers the tools they need to detect and stop attacks before they have an impact, protecting their customers and the broader internet from the large-scale DDoS attacks we have seen.” Comprehensive threat intelligence Using AI-powered threat intelligence and automated detection and mitigation, NETSCOUT’s ADP solution, an addition to its Arbor Sightline and Arbor Threat Mitigation System: Automatically detects and mitigates ever evolving attacks through dynamic detection, intelligent redirection and adaptive mitigation Extends these capabilities to outbound traffic, combining enhanced, customised detection with comprehensive threat intelligence tailored for each ISP Uses NETSCOUT’s proprietary AI/ML-powered DDoS detection to analyse massive volumes of outbound internet traffic to uncover attacks designed to hide within legitimate flows Draws on unique global real-time intelligence of DDoS activity covering approximately half of all internet traffic to rapidly detect and mitigate DDoS attacks and pinpoint the responsible, compromised devices Emerging service provider challenges “We are extending DDoS defence from the target to the source,” stated Darren Anstee, CTO for security, NETSCOUT. “By using our internet-scale visibility to derive localised threat intelligence for our customers, NETSCOUT can identify and precisely suppress attacks at their origin, before they cause problems locally or at their target. This capability gives our customers a new level of comprehensive defence across their peering, transit, cloud and customer edges.” This expansion of capabilities demonstrates how NETSCOUT is applying its global threat visibility and proven ADP solution to meet emerging service provider challenges. By extending an established inbound DDoS workflow to outbound and cross-bound threats, NETSCOUT enables operators to improve network-resilience, cost-controls and revenue protection through its proven Arbor Sightline and Arbor TMS solutions.
Technology's role in securing banks and financial institutions
DownloadSecurity technologies promote real-time awareness in K-12 schools
DownloadIntegrated systems enable critical and compliant security for transportation
DownloadModernising physical access control
DownloadAccess. Intrusion. One estate.
Download