NETSCOUT has upgraded its Arbor Edge Defense (AED) to identify attack sources hidden behind shared content-delivery-network infrastructure, targeting the application-layer DDoS traffic that CDN defences routinely wave through.
The design problem is a familiar one for anyone running production workloads behind a CDN. Volumetric attacks are the ones the CDN was built to soak up. Application-layer attacks — designed to exhaust APIs, authentication services or origin infrastructure directly — often look enough like legitimate traffic to slip past generic protections, and by the time they arrive at the customer data centre the defender is left choosing between letting the attack through or blocking legitimate customers alongside it.
AED's answer is to reveal what the CDN proxy obscures. A high-performance TLS transparent proxy decrypts and inspects application traffic, identifies the true source from application headers, and applies precise application-layer DDoS countermeasures. Service-specific policies replace generic ones; direct traffic to origin infrastructure is defended alongside CDN-mediated paths; and the existing CDN investment is complemented rather than replaced.
"Enterprises cannot assume that putting a CDN in front of an application protects every path attackers can use to reach it. Attackers increasingly look for ways around defences, including targeting origin infrastructure directly or slipping through the CDN by mimicking legitimate traffic. AED closes those gaps by extending DDoS protection beyond the CDN, closer to the application itself, securing the paths attackers still exploit, enabling enterprises to protect critical applications precisely while keeping legitimate customers connected."
Scott Iekel-Johnson, AVP, Product Management, NETSCOUT
Christopher Rodriguez, research director for security and trust at IDC, positions the shift as one about scope rather than intensity.
"Cybercriminals launch DDoS attacks for many reasons, but the ultimate outcome is to drain the targeted organisation's resources. These attacks pose significant operational and financial risk because adversaries can target multiple layers of an organisation's infrastructure and rapidly shift attack methods. Effective DDoS defence must be dynamic, highly performant, and broad enough to protect critical services across the attack surface."
Christopher Rodriguez, Research Director, Security and Trust, IDC
What matters commercially is where this puts the visibility line. CDNs remain necessary; NETSCOUT's argument is that CDN alone is not sufficient once revenue-generating applications are the target and attackers know how to look legitimate. AED's enhancements extend DDoS protection closer to the application itself — the point at which an attack has the most business impact.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter