NETSCOUT uses machine learning to stop DDoS attacks

Machine Learning


NETSCOUT Systems revealed this week that it dynamically applies machine learning algorithms to combat distributed denial of service (DDoS) attacks.

Tom Bienkowski, director of product marketing at NETSCOUT, said the latest version of the Arbor Edge Defense (AED) platform is being installed in enterprises alongside firewalls and other cybersecurity infrastructure that monitor for signs of DDoS attacks. said. These attacks are becoming more sophisticated as cybercriminals adjust to look for weaknesses in defenses.

Historically, cybercriminals launched DDoS attacks and hoped for the best. Now they are monitoring the effectiveness of these attacks so they can adjust their tactics and techniques based on the strength of the defenses they encounter, he said. Many of these attacks were launched after extensive reconnaissance operations identified specific weaknesses, Bienkowski added.

NETSCOUT adds machine learning algorithms that analyze inbound and outbound network packets, detect changes in them, and surface mitigation recommendations in real time. Armed with these insights, cybersecurity teams can remediate exploited vulnerabilities and strengthen other elements of cybersecurity defenses.

NETSCOUT already maintains a network of Atlas cybersecurity sensors across over 500 Internet Service Providers (ISPs), capable of analyzing 400 Tbps of network traffic originating from 93 countries. ASERT analytics application tracks 50% of all internet traffic and real-time DDoS attack activity and updates AED instances via intelligence feeds.

There are now more than 10 million DDoS attacks launched on a regular basis, many of which cripple internet services for whole countries or single organizations they perceive to be on the wrong side of the problem. It is set up by activists trying to advance the cause.

Additionally, some of the organizations conducting these types of attacks now rent out their services to interested parties, allowing cybercriminals to use DDoS attacks to prevent cybersecurity teams from detecting more targeted attacks. It is becoming more common to

DDoS attacks are a fairly blunt vehicle, but as attacks become easier, organizations are realizing that they need to devote significant resources to defending against them. Doing so separates limited resources from other attack vectors that need to be defended. In fact, defending against DDoS attacks, like any other kind of cyberattack, is a cat-and-mouse game of one machine competing with another. The challenge is that cybercriminals seem to have access to virtually unlimited resources compared to enterprise IT organizations that are constantly making economic trade-offs between cybersecurity defense tactics.

I hope the day will come when ISPs and carriers will be able to do more to prevent DDoS attacks. Meanwhile, machine learning algorithms and other forms of artificial intelligence (AI) are at least beginning to level today’s highly unequal playing field.

Recent articles by author



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *