NETSCOUT strengthens DDoS protection to close security gaps left by CDN infrastructure
NETSCOUT has enhanced Arbor Edge Defense to identify attack sources hidden behind CDN proxies and block sophisticated application-layer DDoS attacks without disrupting legitimate users.
NETSCOUT announced the enhancements in India on August 27, describing them as an additional layer of protection for revenue-generating and mission-critical applications against attacks that can evade or bypass conventional CDN-based DDoS defences.

NEW DELHI: NETSCOUT has enhanced its Arbor Edge Defense (AED) solution to address a critical security gap that can emerge when enterprises rely on content delivery networks (CDNs) to protect applications from distributed denial-of-service (DDoS) attacks.
The enhancements are designed to identify malicious traffic sources concealed behind shared CDN infrastructure and apply service-specific countermeasures, allowing enterprises to block sophisticated application-layer DDoS attacks without cutting off legitimate customers using the same CDN.
NETSCOUT announced the enhancements in India on August 27, describing them as an additional layer of protection for revenue-generating and mission-critical applications against attacks that can evade or bypass conventional CDN-based DDoS defences.
CDNs are widely used to accelerate digital experiences and absorb large traffic surges, but their deployment does not eliminate every DDoS risk. Dynamic applications, APIs, authentication services, uncached requests and exposed origin infrastructure can remain vulnerable to attacks.
According to NETSCOUT, attackers are increasingly disguising DDoS traffic as legitimate application-layer activity. Such attacks can evade CDN protections that primarily focus on volumetric attacks and generic mitigation techniques. When the malicious traffic reaches the customer’s infrastructure, organisations may have to choose between allowing the attack to continue or blocking traffic that could also include legitimate users.
The enhanced AED solution uses a high-performance TLS transparent proxy to decrypt and inspect application traffic and identify its actual source from application headers. It can then apply application-layer countermeasures to traffic that existing CDN protections fail to stop.
The system is designed to detect attacks aimed at exhausting application, API, authentication and infrastructure resources while applying policies tailored to individual protected services.
A key feature is the ability to distinguish malicious traffic from legitimate users sharing the same CDN infrastructure. This allows enterprises to block attack traffic without broadly denying access to genuine customers or disrupting other traffic arriving through the CDN proxy.
AED can also defend both CDN-mediated and direct traffic paths, covering attacks that pass through a CDN as well as those that bypass it and target origin infrastructure directly.
NETSCOUT said the enhanced solution is intended to complement existing CDN investments rather than require organisations to replace their CDN provider. It adds an independent layer of visibility and protection closer to the application itself.
“Enterprises cannot assume that putting a CDN in front of an application protects every path attackers can use to reach it,” said Scott Iekel-Johnson, AVP, product management, NETSCOUT. He said attackers were increasingly targeting origin infrastructure directly or attempting to pass through CDNs by mimicking legitimate traffic.
Christopher Rodriguez, research director, security and trust at IDC, said DDoS attacks can create significant operational and financial risks because attackers can target multiple layers of an organisation’s infrastructure and rapidly change their methods. He said effective DDoS protection needs to be dynamic, high-performance and broad enough to cover critical services across the attack surface.
NETSCOUT said the AED enhancements extend its DDoS protection portfolio to address the increasingly important connection between shared cloud delivery infrastructure and business-critical applications.
For enterprises whose revenues, operations and public services depend on application availability, the company said the additional protection layer can help strengthen resilience at the point where successful attacks can have the greatest business impact.
NETSCOUT Systems, Inc., listed on Nasdaq as NTCT, provides network observability, AIOps, cybersecurity, carrier service assurance and DDoS protection solutions to enterprises, service providers and public-sector organisations.





























