Decoding the world of cybersecurity

NETSCOUT pushes DDoS defence to source

NETSCOUT is extending DDoS mitigation into service-provider networks so compromised subscriber devices can be suppressed closer to the source before attack traffic reaches wider internet infrastructure.

NETSCOUT pushes DDoS defence to source
Summary
  • NETSCOUT has extended Adaptive DDoS Protection to detect and mitigate outbound attack traffic inside service-provider networks.
  • The approach is designed to suppress malicious traffic from compromised subscriber and IoT devices before it consumes wider network capacity.
  • Source-side mitigation complements rather than replaces destination-side DDoS protection, while shifting more resilience responsibility towards access providers.

NETSCOUT is extending its Adaptive DDoS Protection platform to help internet service providers detect and suppress outbound attack traffic generated by compromised subscriber devices before it leaves their networks.

The change moves part of distributed denial-of-service defence away from the conventional model of protecting only the intended target. Instead, operators can identify malicious traffic at or near the source and intervene before it consumes upstream capacity or reaches organisations elsewhere on the internet.

NETSCOUT says the capability uses its ATLAS Intelligence Feed and Arbor security tooling to identify suspicious outbound traffic from broadband and internet-of-things devices connected through service-provider infrastructure.

That addresses a persistent feature of modern DDoS campaigns: attackers frequently assemble botnets from compromised routers, cameras, consumer devices, and other internet-connected systems that belong to legitimate subscribers. The owner may have no indication that the device is generating attack traffic until the provider detects it or the equipment is blocked.

Source-side suppression can reduce the amount of malicious traffic traversing an operator’s own network, limiting both external harm and internal congestion. NETSCOUT also argues that it can reduce the cost of carrying attack traffic and help providers protect other customers sharing the same infrastructure.

Mitigation is moving deeper into the network

DDoS defence has traditionally concentrated on destination-side controls: on-premises mitigation appliances, cloud scrubbing services, or a combination of the two. Those systems remain important because they protect organisations against attack traffic arriving from many networks at once.

They do not, however, prevent an ISP from transporting attack traffic generated inside its own subscriber base. A sufficiently large botnet can consume network capacity before the traffic reaches the destination’s defences, leaving the access provider to carry traffic that has no legitimate business purpose.

Moving detection closer to the source creates a different set of operational requirements. Providers need enough visibility to distinguish an actual DDoS flow from legitimate high-volume behaviour, and automated suppression has to be accurate enough to avoid interrupting ordinary customer traffic.

Those decisions also have governance implications. A provider intervening in outbound traffic needs clear thresholds, auditability, and operational controls around how subscribers are restricted or notified when compromised equipment is identified.

The direction reflects the growth of weaponised broadband and IoT infrastructure. Consumer and small-business devices can remain online for years, often with uneven patching and limited monitoring, making them attractive raw material for botnets. The result is that a security failure at the edge can become a capacity and resilience problem for networks far beyond the compromised household or business.

Source-side mitigation will not replace protection at the target. Attack traffic can originate across many autonomous systems, cloud services, and compromised networks, and no single access provider has enough visibility or authority to suppress all of it.

It can nevertheless change the economics of carrying malicious traffic. If more providers stop attack flows before they leave the originating network, less capacity is wasted transporting them through upstream infrastructure and fewer packets need to be absorbed by the eventual victim.

For telecoms operators, that makes DDoS defence part of broader network-resilience engineering rather than a service activated only when a customer is under attack. The more compromised subscriber devices are used as offensive infrastructure, the more pressure there is for providers to address abuse on both sides of the connection.

×