TelcoNews Canada - Telecommunications news for ICT decision-makers
Canada
NETSCOUT expands DDoS defence to stop attacks at source

NETSCOUT expands DDoS defence to stop attacks at source

Wed, 19th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

NETSCOUT has expanded its Adaptive DDoS Protection product to detect and mitigate outbound distributed denial-of-service traffic, targeting service providers dealing with attacks generated by compromised subscriber devices.

The extension shifts part of DDoS defence from protecting attack targets to stopping malicious traffic before it leaves an operator's network. The aim is to help internet service providers identify broadband routers, cameras and other connected devices hijacked by botnets and used to launch attacks elsewhere on the internet.

Outbound attack traffic is a growing concern for telecoms and broadband operators as more internet-connected household and small business devices are drawn into botnets. Newer Turbo-Mirai-class botnets can generate attacks measured in multiple terabits, increasing the risk of service disruption and the cost of carrying malicious traffic across provider networks.

For operators, the problem extends beyond the attack victim. Compromised devices within their subscriber base can consume network capacity, trigger abuse complaints, strain peering relationships and increase transit costs. Outages and poor service can also damage customer retention.

Source-side defence

The expanded product is being added to NETSCOUT's Arbor Sightline and Arbor Threat Mitigation System offerings. The system uses automated detection and mitigation to identify malicious outbound traffic and redirect it for suppression.

The updated service extends existing detection methods to outbound traffic flows and draws on threat intelligence tailored to individual internet service providers. It also analyses large volumes of internet traffic to find attacks designed to blend into legitimate traffic.

NETSCOUT said the product uses global intelligence on DDoS activity drawn from network traffic visibility covering about half of all internet traffic. That visibility helps identify attacks quickly and trace them back to compromised devices inside a provider's network.

The broader market backdrop is a rise in the number of consumer and business devices connected to broadband networks, often with weak security controls. Security vendors and telecoms operators have warned for years that poorly secured routers, cameras and other IoT hardware can be recruited into botnets and used at scale for denial-of-service attacks.

Patrick Donegan, Founder and Principal Analyst, HardenStance, said service providers need to tackle attacks closer to their source as botnets grow in size and output.

"The combination of higher-speed broadband connectivity and vulnerable IoT devices has been weaponized by a new class of massive DDoS botnets," said Patrick Donegan, Founder and Principal Analyst, HardenStance.

"Source-side mitigation, or attack suppression as it's sometimes known, is a critical part of the equation. NETSCOUT's approach, backed by its ATLAS Intelligence Feed (AIF) and ASERT analysts, gives service providers the tools they need to detect and stop attacks before they have an impact, protecting their customers and the broader internet from the large-scale DDoS attacks we have seen," said Donegan.

Operator pressures

The announcement reflects a broader shift in how network operators are approaching denial-of-service protection. Historically, many defences have focused on shielding the intended target of an attack, whether a website, application or network edge. NETSCOUT argues that providers also need tools to suppress malicious traffic generated by their own customers' infected devices before it reaches external destinations.

That position comes as operators face pressure to contain infrastructure spending while maintaining service quality. Stopping malicious traffic before it crosses peering and transit links could reduce the operational burden of large attack volumes and help avoid disputes with network partners affected by abusive traffic.

Darren Anstee, Chief Technology Officer, Security, NETSCOUT, described the change as an extension of existing DDoS workflows rather than a separate system.

"We are extending DDoS defense from the target to the source," said Darren Anstee, Chief Technology Officer, Security, NETSCOUT.

"By using our internet-scale visibility to derive localized threat intelligence for our customers, NETSCOUT can identify and precisely suppress attacks at their origin, before they cause problems locally or at their target. This capability gives our customers a new level of comprehensive defense across their peering, transit, cloud and customer edges," said Anstee.

The expanded protection is intended to help service providers reduce network disruption, limit infrastructure costs and lower internet-wide risk linked to botnet-driven DDoS attacks. The product extension builds on the company's established inbound mitigation workflow by applying similar processes to outbound and cross-bound traffic.