CYBERSECURITY DDOS PROTECTION

NETSCOUT Tech Stops Outbound Cyberattacks at Device Source

TM
Techmediaglobal
| 4 min read
18 mos
SURGE TIMEFRAME
1 Tbps+
ATTACK THRESHOLD
100s/mo
FROM DOZENS/YEAR
~50%
GLOBAL TRAFFIC VISIBILITY

NETSCOUT has extended its Adaptive DDoS Protection (ADP) platform with a new capability designed to stop cyberattacks at the source, cutting off malicious traffic from hijacked devices before it ever leaves an internet service provider's (ISP) network. The move comes as the industry faces an explosion in large-scale distributed denial of service (DDoS) attacks, driven by increasingly powerful botnets built from everyday hijacked devices like smart TVs, routers and phones.

A Surge in Terabit-Scale Botnet Attacks

According to Darren Anstee, Chief Technology Officer for Security at NETSCOUT, the past year and a half has brought a dramatic escalation in both the scale and frequency of large DDoS attacks. Where NETSCOUT's ATLAS dataset once recorded only a handful of attacks exceeding one terabit per second annually, the company is now tracking hundreds of such attacks every month.

Anstee attributes the shift to two compounding factors: faster internet connectivity speeds and the rise of larger, more capable botnets. The result is a growing volume of outbound attack traffic originating from ISP subscriber networks, exposing providers to a new category of operational risk they must now actively manage.

"The attack traffic has to come from somewhere"

— Darren Anstee, Chief Technology Officer for Security, NETSCOUT

The Real Cost of Outbound Attack Traffic

Left unchecked, outbound DDoS traffic can trigger costly service outages, reputational damage and customer churn, while also straining peering relationships and driving up transit costs for providers. Anstee explains that large volumes of outbound attack traffic can congest the customer aggregation edge, affecting entire subscriber service markets and generating a wave of support calls from affected end-users.

Beyond the operational strain, ISPs also risk backlash from peering partners and attack targets, who can trace the malicious traffic back to its network of origin.

How the Adaptive Protection Engine Works

The expanded ADP solution combines dynamic detection, intelligent redirection and adaptive mitigation to identify and neutralise attacks automatically. By extending its monitoring to outbound network traffic, NETSCOUT pairs precision detection with threat intelligence tailored to each individual ISP, using proprietary AI and machine learning models to spot sophisticated attacks attempting to blend in with normal traffic patterns.

The system draws on a real-time global intelligence network that observes roughly half of all worldwide internet traffic, allowing it to swiftly pinpoint the exact hijacked devices generating malicious activity — stopping attacks before they leave the network and reducing wasted energy and capacity across the wider internet.

Industry Reaction and Broader Impact

Patrick Donegan, Founder and Principal Analyst at HardenStance, describes source-side mitigation, sometimes called attack suppression, as a critical part of tackling the DDoS problem. He notes that NETSCOUT's approach, backed by its ATLAS Intelligence Feed and its ASERT analyst team, gives providers the tools to detect and stop attacks before they cause impact — protecting both their own customers and the broader internet.

By applying its established inbound defence techniques to outbound and internal threats via its Arbor Sightline and Arbor TMS platforms, NETSCOUT aims to help providers strengthen infrastructure, reduce operational costs and protect revenue. Major organisations reported to use NETSCOUT's products include Amazon, British Airways, Intel, Nationwide Building Society and PTC.

Key Takeaways

  • NETSCOUT has extended its ADP platform to stop DDoS traffic at the hijacked device before it leaves the ISP network.
  • Attacks exceeding 1 terabit per second have jumped from dozens a year to hundreds a month over the past 18 months.
  • Faster connectivity and larger botnets are driving higher volumes of outbound attack traffic from ISP subscribers.
  • Unmitigated outbound traffic can cause outages, reputational harm, customer churn and strained peering relationships.
  • The new Outbound Detection feature uses AI-driven, ISP-tailored threat intelligence to identify and mitigate attacks automatically.
  • Industry analysts view source-side mitigation as essential to reducing large-scale DDoS impact across the internet.
Tags: DDoS Protection Cybersecurity NETSCOUT Botnets ISP Security Network Infrastructure AI Threat Detection