NETSCOUT has extended its Adaptive DDoS Protection (ADP) platform with a new capability designed to stop cyberattacks at the source, cutting off malicious traffic from hijacked devices before it ever leaves an internet service provider's (ISP) network. The move comes as the industry faces an explosion in large-scale distributed denial of service (DDoS) attacks, driven by increasingly powerful botnets built from everyday hijacked devices like smart TVs, routers and phones.
A Surge in Terabit-Scale Botnet Attacks
According to Darren Anstee, Chief Technology Officer for Security at NETSCOUT, the past year and a half has brought a dramatic escalation in both the scale and frequency of large DDoS attacks. Where NETSCOUT's ATLAS dataset once recorded only a handful of attacks exceeding one terabit per second annually, the company is now tracking hundreds of such attacks every month.
Anstee attributes the shift to two compounding factors: faster internet connectivity speeds and the rise of larger, more capable botnets. The result is a growing volume of outbound attack traffic originating from ISP subscriber networks, exposing providers to a new category of operational risk they must now actively manage.
"The attack traffic has to come from somewhere"— Darren Anstee, Chief Technology Officer for Security, NETSCOUT
The Real Cost of Outbound Attack Traffic
Left unchecked, outbound DDoS traffic can trigger costly service outages, reputational damage and customer churn, while also straining peering relationships and driving up transit costs for providers. Anstee explains that large volumes of outbound attack traffic can congest the customer aggregation edge, affecting entire subscriber service markets and generating a wave of support calls from affected end-users.
Beyond the operational strain, ISPs also risk backlash from peering partners and attack targets, who can trace the malicious traffic back to its network of origin.
Industry Reaction and Broader Impact
Patrick Donegan, Founder and Principal Analyst at HardenStance, describes source-side mitigation, sometimes called attack suppression, as a critical part of tackling the DDoS problem. He notes that NETSCOUT's approach, backed by its ATLAS Intelligence Feed and its ASERT analyst team, gives providers the tools to detect and stop attacks before they cause impact — protecting both their own customers and the broader internet.
By applying its established inbound defence techniques to outbound and internal threats via its Arbor Sightline and Arbor TMS platforms, NETSCOUT aims to help providers strengthen infrastructure, reduce operational costs and protect revenue. Major organisations reported to use NETSCOUT's products include Amazon, British Airways, Intel, Nationwide Building Society and PTC.
