Site icon TechArena

NETSCOUT Enhances DDoS Protection to Defend Applications Against CDN-Burning Attacks

Netscout DDOS protection

NETSCOUT has announced enhancements to its Arbor Edge Defense (AED) solution that helps enterprises maintain the availability of revenue-generating and mission-critical applications against sophisticated DDoS attacks that evade or bypass content delivery network (CDN) DDoS defences. The enhancements identify malicious sources concealed behind shared CDN infrastructure and apply precise, service-specific countermeasures to block attacks without denying access to legitimate customers using the same CDN.

“Cybercriminals launch DDoS attacks for many reasons, but the ultimate outcome is to drain the targeted organisation’s resources,” said Christopher Rodriguez, research director, security and trust, IDC. “These attacks pose significant operational and financial risk because adversaries can target multiple layers of an organisation’s infrastructure and rapidly shift attack methods. Effective DDoS defence must be dynamic, highly performant, and broad enough to protect critical services across the attack surface.”

Organisations rely on CDNs to accelerate digital experiences and absorb large-scale traffic surges, but CDN deployment alone does not eliminate DDoS risk. Dynamic applications, APIs, authentication services, uncached requests, and exposed origin infrastructure can remain vulnerable. Attackers exploit these gaps by sending DDoS attacks disguised as application-layer traffic that resembles legitimate user activity. CDN DDoS defences can miss this traffic because they focus on detecting volumetric DDoS attacks and rely on generic protections that are not customized to the individual customer applications being protected. These advanced application-layer DDoS attacks bypass CDN DDoS protections to the customer datacentre, causing outages and impacting revenue. Defenders must either allow the attack through or block it, including the legitimate traffic along with it. NETSCOUT restores source-level visibility and enables precise mitigation of all CDN traffic closer to the protected service.

The enhanced AED solution enables enterprises to:

“Enterprises cannot assume that putting a CDN in front of an application protects every path attackers can use to reach it,” said Scott Iekel-Johnson, AVP, product management, NETSCOUT. “Attackers increasingly look for ways around defences, including targeting origin infrastructure directly or slipping through the CDN by mimicking legitimate traffic. AED closes those gaps by extending DDoS protection beyond the CDN, closer to the application itself, securing the paths attackers still exploit, enabling enterprises to protect critical applications precisely while keeping legitimate customers connected.”

The AED enhancements extend NETSCOUT’s established DDoS protection portfolio into an increasingly important point of enterprise exposure: the connection between shared cloud delivery infrastructure and business-critical applications. By complementing existing CDN investments rather than requiring organisations to replace them, AED helps customers address a significant area of exposure while extracting greater security value from current infrastructure investments. For enterprises whose revenue, operations and public services depend on application availability, this provides an additional layer of resilience at the point where an attack can have the greatest business impact.

For these and more stories, follow us on X (Formerly Twitter)FacebookLinkedIn and Telegram. You can also send us tips or reach out at info@techarena.co.ke.

Also Read: NETSCOUT Expands DDoS Protection to Help Service Providers Stop Attacks at the Source

Exit mobile version