Smarter, automated DDoS attack blocking

Innovative intelligence-based approach uses unique global visibility and automated AI analytics engine to speed DDoS attack response and reduce operational overhead.

  • 2 years ago Posted in

NETSCOUT SYSTEMS has launched a new, innovative AI-based solution enabling its customers to automatically and instantaneously block a large proportion of DDoS attacks thus simplifying operations and minimising risk to their businesses.

The solution leverages NETSCOUT's ATLASÒ network, an unmatched source of visibility into DDoS attack activity on the Internet. Multiple ATLAS datasets are analysed, curated, and correlated using artificial intelligence. This automated intelligent pipeline is developed using NETSCOUT's ATLAS Security Engineering and Response Team (ASERT) expertise to identify botnet members and other network infrastructure that is actively participating in DDoS attacks.

This intelligence is continuously updated and shared in real-time with NETSCOUT's industry-leading Arbor Threat Mitigation System (TMS) and OmnisÒ AED Smart DDoS attack protection solutions via the Omnis ATLAS Intelligence Feed (AIF). This new Omnis AIF content enables TMS and AED to know, in advance, the IP addresses of devices across the Internet that are being used to launch DDoS attacks, resulting in the ability to instantly block up to 90 per cent of attack traffic, without further analysis, during an attack.

This data provides TMS and AED with the intelligence needed to automatically stop botnet-generated DDoS attacks, including reflection/amplification, direct-path TCP state exhaustion, application-layer, and encrypted attacks. The analysis behind Omnis AIF is based on NETSCOUT's unique, global DDoS attack visibility extending to more than one-third of all Internet traffic and millions of DDoS attacks. This global intelligence can then be applied automatically for local protection.

"This is an innovative way to block DDoS attacks," stated Darren Anstee, chief technology officer for security at NETSCOUT. "Omnis AIF, which incorporates the new DDoS reputation feed, takes an intelligence-based approach providing customers with faster, more comprehensive, and more automated solutions. Our approach is different because we leverage global observations in DDoS attack activity to drive local automation and response. As a result, we can dramatically lower the risk of business impact due to DDoS attack for our customers."

Acquisition of leading DSPM company will bolster Proofpoint’s human-centric security platform...
NTT DATA’s new Managed Detection & Response service powered by Palo Alto Networks Cortex XSIAM...
SPG is enhancing its cybersecurity capabilities in a new partnership with Saviynt, a leading...
Graylog has unveiled significant security advancements to drive smarter, faster, and more...
Datadog has published its new report, the State of Cloud Security 2024. The report found that...
ISACA research shows automating threat detection/response and endpoint security are the most...
Strategic partnership unifies AI-native endpoint security and next-generation firewall protection...
Advanced forms of social engineering are on the rise, though obvious gaps like weak passwords are...