SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Netscout adds CDN-bypassing DDoS protection features

Netscout adds CDN-bypassing DDoS protection features

Thu, 27th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

NETSCOUT has added new features to its Arbor Edge Defence product for distributed denial-of-service protection, targeting attacks that pass through or around content delivery networks.

The update is designed to help enterprises identify malicious traffic sources hidden behind shared CDN infrastructure and block those attacks without cutting off legitimate users on the same network path. It focuses on application-layer attacks that resemble normal customer activity and can still reach origin systems, APIs and authentication services.

Many organisations use CDNs to absorb large traffic spikes and shield internet-facing services from large-scale attacks. But that approach can leave gaps, with uncached requests, direct access to origin infrastructure and dynamic applications still exposed to more targeted traffic.

According to NETSCOUT, the revised approach restores source-level visibility closer to the protected application by decrypting and inspecting application traffic, identifying the original source from application headers and applying countermeasures to specific services rather than broadly blocking all traffic from a CDN proxy.

For security teams, the practical problem is that attackers can hide behind the same CDN infrastructure used by genuine customers. That leaves defenders with a blunt choice: allow harmful traffic through or block traffic in a way that also disrupts legitimate access.

Attack path

The updated product is meant to address both attacks that transit a CDN and those that bypass it to target origin infrastructure directly. It can also detect attempts to exhaust application, API, authentication and infrastructure resources.

Service-specific policies are a central part of the update. NETSCOUT said these can be tailored to the behaviour and requirements of each protected service, arguing that generic protections at the CDN layer may not reflect how an individual customer application normally behaves.

That issue has grown more pressing as online businesses and public services rely on a wider mix of applications, APIs and user authentication systems to generate revenue and maintain operations. Outages at those layers can have a direct commercial effect even when perimeter defences remain in place.

Christopher Rodriguez, Research Director, Security and Trust, IDC, said attacks are becoming more fluid across multiple layers of infrastructure.

"Cybercriminals launch DDoS attacks for many reasons, but the ultimate outcome is to drain the targeted organization's resources," said Christopher Rodriguez, Research Director, Security and Trust, IDC. "These attacks pose significant operational and financial risk because adversaries can target multiple layers of an organization's infrastructure and rapidly shift attack methods. Effective DDoS defense must be dynamic, highly performant, and broad enough to protect critical services across the attack surface."

Closer inspection

Arbor Edge Defence now includes a TLS transparent proxy so encrypted application traffic can be examined and linked back to its original source. NETSCOUT said this source identification is intended to let operators stop malicious traffic more precisely while avoiding broad disruption for legitimate users behind the same CDN service.

The update also reflects a broader market challenge for enterprises that have increased spending on cloud delivery and edge services while still retaining origin infrastructure in their own datacentres or in hybrid environments. In those setups, traffic may follow several routes before reaching the underlying application, complicating mitigation decisions during an attack.

Scott Iekel-Johnson, AVP, Product Management, NETSCOUT, said enterprises should not treat a CDN as complete protection for all routes into an application.

"Enterprises cannot assume that putting a CDN in front of an application protects every path attacker can use to reach it," said Scott Iekel-Johnson, AVP, Product Management, NETSCOUT. "Attackers increasingly look for ways around defenses, including targeting origin infrastructure directly or slipping through the CDN by mimicking legitimate traffic. AED closes those gaps by extending DDoS protection beyond the CDN, closer to the application itself, securing the paths attackers still exploit, enabling enterprises to protect critical applications precisely while keeping legitimate customers connected."

NETSCOUT positioned the changes as an additional layer alongside existing CDN arrangements rather than a replacement. That is likely to appeal to customers seeking tighter control over application availability without reworking established delivery infrastructure.

For NETSCOUT, the release extends its DDoS portfolio further into the space between shared cloud delivery platforms and the applications they front. The company said that connection point has become an increasingly important area of exposure for enterprises whose operations depend on uninterrupted digital services.