Distributed denial of service (DDoS) attacks are changing shape. Attackers now use AI throughout the attack lifecycle, from reconnaissance to exploitation to hardening compromised devices against takeover by rival botnet operators. The result is larger, more coordinated botnets capable of direct, stateful attacks rather than the reflection and amplification techniques that dominated a few years ago.
To keep up, defenders need more intelligence and more bandwidth. That’s what Netscout is targeting with the expansion of its Arbor Cloud DDoS mitigation capacity to 33 Tbps across 16 global scrubbing centers, up from a previous peak of 15 Tbps. The new capacity and capabilities come in part from the acquisition of DigiCert’s DDoS and WAF services, which occurred in May of this year.
“AI is used on the forefront by attackers to carry out social social attacks, carry out infiltrations, look for vulnerabilities, find them quickly and exploit them,” Carlos Morales, senior vice president and general manager of Arbor Cloud at Netscout, told Network World. “The net of that is you get these bigger botnets that what you had before.”
Morales pointed to three specific ways AI is reshaping these attacks.
More than amplification. Smaller botnets used to depend on reflection and amplification to punch above their real size, spoofing a target’s address so that third-party DNS or NTP servers would fire oversized replies at the victim instead of the botnet doing the work directly. That dependency also gave attackers a side benefit, since the traffic appeared to originate from those third-party servers rather than from the botnet itself. Morales said today’s larger, AI-expanded botnets do not need that trick anymore. They generate volume directly from the compromised devices under their control. “So prior, the botnets weren’t quite as big,” he said.
AI takes over coordination. Reconnaissance, vector switching, and target selection used to require a human actively managing the attack. “Now AI can do a lot of that and automate those attacks for you,” he said.
Stateful vs. stateless. Reflection and amplification floods are stateless. Spoofed packets get fired at a target with no handshake to complete and no session to hold open, so a defender can filter much of that traffic right at the network border without tracking individual connections.
AI-coordinated botnets can sustain real, stateful sessions instead, using large numbers of actual compromised devices rather than spoofed packets. That traffic often lands on a legitimate destination port where a simple access control list cannot block it without also blocking real users. Mitigating it means processing that traffic at scale while still telling attack sessions apart from legitimate ones.
Reaching 33 Tbps required upgrades across three layers: bandwidth, hardware, and software.
Bandwidth: The buildout required carrier capacity to absorb attack traffic coming into the network, matched by clean capacity to return legitimate traffic on the way out.
Hardware: Terminating that volume at the network edge requires 100 gig ports, along with the routing and switching capacity behind them.
Software: Netscout inspects incoming traffic and makes pass or drop decisions rather than compressing or otherwise modifying it, an approach Morales distinguished from CDN providers that terminate connections. That capacity is applied at different levels depending on the attack. Simple volumetric traffic is blocked at scale with blunt filtering rules, while more complex or targeted traffic requires layered, intelligent mitigation built on Arbor technology, what Morales called scrubbing.
“We have 33 terabits per second of capacity,” Morales said. “That’s dedicated to DDoS and application security. That’s what we do.”
Asked what comes after 33 Tbps, Morales said the buildout is not a one-time event and there will likely be more bandwidth upgrades in the future.
Netscout’s near-term focus is on automation and speed of detection and mitigation, along with making the experience consistent for customers regardless of whether they use on-premises equipment, the cloud service, or both. Arbor Cloud is also backed by a 24×7 security operations center. Morales drew a line between where technology and people are both needed.
“What we’re focused on is continuous automation and speed of defenses,” Morales said. “Ultimately you don’t want to rely on humans for speed. You want to rely on humans for intelligence and common sense. You want to roll technology for speed and response.”