NETSCOUT Systems has expanded its Adaptive DDoS Protection solution to help service providers detect and automatically block malicious traffic leaving their networks.
The company said the new outbound protection is designed to address the growing threat posed by compromised broadband routers, security cameras and other internet-connected devices being recruited into large botnets.
By moving protection closer to the source of an attack, NETSCOUT said operators can limit network disruption, reduce infrastructure expenses and prevent compromised subscriber devices from being used to attack organizations elsewhere on the internet.
IoT Botnets Drive Growing DDoS Threat
The company said faster broadband connections combined with vulnerable Internet of Things devices have created an environment in which attackers can generate increasingly powerful distributed denial-of-service attacks.
Turbo-Mirai-class botnets, in particular, are capable of producing multi-terabit attacks by coordinating large numbers of compromised devices.
For internet service providers, outbound attacks can create problems even when the provider is not the intended target. Malicious traffic can consume network capacity, trigger abuse complaints, damage relationships with peering partners and increase transit costs.
NETSCOUT said the resulting disruption can also contribute to customer dissatisfaction, reputational damage and subscriber losses.
Automated Detection Moves Toward the Source
The expanded Adaptive DDoS Protection capability is intended to identify malicious traffic generated by compromised devices before that traffic leaves an operator’s network.
The solution has been added to NETSCOUT’s Arbor Sightline and Arbor Threat Mitigation System platforms.
According to the company, the system can automatically identify changing attack patterns and respond through dynamic detection, intelligent traffic redirection and adaptive mitigation.
The outbound capability combines customized detection with threat intelligence tailored to individual internet service providers.
AI and Global Threat Intelligence Power the System
NETSCOUT said its artificial intelligence and machine-learning-based technology analyzes large volumes of outbound internet traffic to identify attacks that may otherwise be hidden within legitimate network activity.
The system also draws on the company’s global real-time view of DDoS activity.
NETSCOUT said its intelligence covers approximately half of all internet traffic, allowing the company to identify emerging attack patterns and help operators locate compromised devices responsible for malicious activity.
Industry Analyst Highlights Source-Side Defence
Patrick Donegan, founder and principal analyst at HardenStance, said the combination of high-speed connectivity and vulnerable IoT equipment has created a new generation of powerful DDoS botnets.
He described source-side mitigation, sometimes referred to as attack suppression, as an important component of modern DDoS defence.
Donegan said NETSCOUT’s approach combines its ATLAS Intelligence Feed and ASERT security research capabilities to give service providers greater ability to identify and stop attacks before they cause wider damage.
NETSCOUT Says Defence Can Extend Across the Network
Darren Anstee, NETSCOUT’s chief technology officer for security, said the company is effectively extending DDoS protection from the traditional target of an attack toward its point of origin.
“We are extending DDoS defence from the target to the source,” Anstee said.
He said NETSCOUT’s internet-scale visibility can be converted into localized intelligence for service providers, allowing attacks to be identified and suppressed at their origin.
The company said this approach can provide protection across peering connections, transit networks, cloud environments and customer-facing infrastructure.
Focus on Cost and Network Resilience
NETSCOUT said the expansion reflects the changing challenges faced by service providers as attacks increasingly originate from compromised customer equipment.
Rather than responding only after malicious traffic has reached its intended target, operators can use outbound detection to intervene earlier and prevent compromised devices from generating disruptive traffic.
The company said the approach can help service providers strengthen network resilience, control operational costs, protect revenue and reduce the risk of subscriber churn and regulatory exposure.
NETSCOUT Promotes New Security Resources
The company is directing customers and security professionals to its expanded Arbor Sightline and Arbor Threat Mitigation System offerings for more information about the new capabilities.
NETSCOUT also highlighted its latest DDoS Threat Intelligence Report, which examines evolving tactics used by botnet operators and provides additional insight into the changing threat landscape.
The company said its broader objective is to give service providers greater visibility and control over DDoS attacks at both the destination and source of malicious traffic.