The expanded Adaptive DDoS Protection solution enables service providers to detect and mitigate malicious outbound traffic from compromised subscriber devices, helping protect networks, reduce infrastructure costs and limit large-scale attacks.
NETSCOUT has expanded its Adaptive DDoS Protection (ADP) solution to enable service providers to automatically detect and mitigate outbound DDoS attack traffic generated by compromised subscriber devices.
The company said the enhancement extends DDoS protection beyond the intended target of an attack to its source. This approach is designed to prevent compromised devices from disrupting service provider networks, consuming network capacity or being used to launch attacks against customers and organisations across the internet.
The expanded capability forms part of NETSCOUT's broader observability, AIOps and cybersecurity portfolio, with the company targeting the growing challenge posed by compromised consumer broadband and IoT devices.
IoT botnets raise outbound attack risks
Consumer broadband routers, cameras and other connected devices are increasingly being targeted by Turbo-Mirai-class botnets, which can generate multi-terabit DDoS attacks. Such compromised device populations can turn subscriber networks into launch points for attacks against external targets.
For service providers, outbound DDoS traffic can result in service disruptions, reputational damage and customer losses. It can also affect peering relationships and potentially increase transit costs.
NETSCOUT said detecting and mitigating malicious traffic before it leaves an operator's network can help reduce abuse complaints and infrastructure expenses while protecting network services. The approach can also help operators address subscriber churn and regulatory risks associated with compromised devices being used in attacks.
Source-side mitigation gains importance
“The combination of higher-speed broadband connectivity and vulnerable IoT devices has been weaponized by a new class of massive DDoS botnets,” said Patrick Donegan, founder and principal analyst, HardenStance. “Source-side mitigation, or attack suppression as it’s sometimes known, is a critical part of the equation. NETSCOUT’s approach, backed by its ATLAS Intelligence Feed (AIF) and ASERT analysts, gives service providers the tools they need to detect and stop attacks before they have an impact, protecting their customers and the broader internet from the large-scale DDoS attacks we have seen.”
AI and global threat intelligence drive detection
NETSCOUT's ADP combines AI-powered threat intelligence with automated detection and mitigation capabilities. The solution is available as an addition to its Arbor Sightline and Arbor Threat Mitigation System (Arbor TMS) platforms.
The expanded capability uses dynamic detection, intelligent traffic redirection and adaptive mitigation to identify and respond to evolving attacks. For outbound traffic, it combines customised detection with threat intelligence tailored to individual internet service providers.
NETSCOUT's proprietary AI/ML-powered DDoS detection technology analyses large volumes of outbound internet traffic to identify malicious activity that may be concealed within legitimate traffic flows.
The company also draws on its global real-time intelligence on DDoS activity, which it says covers approximately half of all internet traffic. This intelligence is used to identify attacks and help pinpoint compromised devices responsible for generating malicious traffic.
DDoS defence moves from target to source
“We are extending DDoS defense from the target to the source,” stated Darren Anstee, CTO, Security, NETSCOUT. “By using our internet-scale visibility to derive localized threat intelligence for our customers, NETSCOUT can identify and precisely suppress attacks at their origin, before they cause problems locally or at their target. This capability gives our customers a new level of comprehensive defense across their peering, transit, cloud and customer edges.”
NETSCOUT said the expansion builds on its existing inbound DDoS protection workflow by adding capabilities for outbound and cross-bound attacks. The company is positioning the approach as a way for service providers to strengthen network resilience, control costs and protect revenue through the Arbor Sightline and Arbor TMS platforms.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




