Arbor Data-Sharing Program

NETSCOUT Arbor DDoS Solutions help Service Providers and Enterprises stay ahead of advanced DDoS attacks and emerging cyber threats that threaten availability, degrade performance, and drain critical resources across the Internet.

Every Arbor solution is powered by the global visibility and threat intelligence delivered by ATLAS™ and the ATLAS Security Engineering and Research Team (ASERT). Together, they provide actionable insight into the threats your customers face—faster than threat actors can evolve.

While ASERT conducts deep internal research and analysis, Arbor’s threat intelligence gets even more valuable through community-driven learning. Through Arbor’s Data-Sharing program, customers share information about attacks and methodologies they observe in real-world conditions. This input is analyzed by NETSCOUT and translated back into improved protections for the broader community. Customers control what is shared through options provided by their products—enabling faster, more scalable response without exposing unnecessary identifying information.
 

Powered by Global Threat Intelliegnce

FAQs

Why should I participate?

DDoS attack methods can spread globally in days. A new technique or source seen on one side of the world can appear elsewhere almost immediately. The most effective defense is collective, enabled by trusted, automated data-sharing—so threats are shared, detected and mitigated with speed and at Internet scale.

What information is being shared?

NETSCOUT Arbor Edge Defense (AED) Customers

AED Data-Sharing participants provide feedback into the Arbor Intelligence Feed (“AIF”). AED shares statistics on traffic that matches AIF policies—high-level threat data only—without including information that identifies your organization (such as IP addresses or payload data). This feedback validates ATLAS threat protection intelligence and continuously strengthens AIF policy quality. For example, NETSCOUT uses feedback data to refine confidence values for AIF policies.

AED may also provide performance and configuration details. You may optionally share the location of your organization and your industry to further improve research and analysis.
Data elements may include:

  • Byte and packet volumes
  • Volumes of traffic blocked or dropped
  • Policies and blacklists triggered
  • Source IP of attacks and associated volumes (depending on your sharing settings)
  • AED system health (CPU & memory consumption)
  • Hosts blocked
  • Number of connections
  • Webcrawlers encountered

Arbor Sightline / Threat Mitigation System (TMS) Customers

Sightline/TMS participants share anonymized information to help improve community defenses, including:

  • Anonymous Sightline deployment size
  • Anonymized Sightline web UI usage statistics
  • Anonymized TMS mitigation setting values

Sightline also shares the following data with NETSCOUT:

  • Medium- and high-severity DoS alerts
  • Top TCP/UDP applications, protocols, and packet lengths
  • Anonymous overall network traffic (incoming and outgoing)

You may also choose to provide your organization’s location and your provider type.

Optional IP anonymization: If you share IP addresses associated with DoS alerts, you choose the anonymization level:

  • Mask internal IP addresses, or
  • Convert them to cryptographic hash values

If IP addresses are shared without anonymization, NETSCOUT can correlate data across ATLAS participants and other sources to help identify DDoS attack patterns. NETSCOUT cannot associate the shared IP data with the identity of any natural person.
 

How is the information transmitted?

Shared data is transmitted over an HTTPS encrypted channel. To reduce risk of misuse, NETSCOUT anonymizes and/or aggregates shared information and does not identify the customer to third parties as the source of the data.

How does NETSCOUT use this information?

NETSCOUT may use shared data for research and business purposes, including:

  • Research and analysis of network traffic and threat data
  • Deriving statistical/usage data related to software and service functionality
  • Improving software and services
  • Developing and providing other NETSCOUT products and services
  • Sharing data with affiliates and business partners

NETSCOUT may also combine or incorporate shared data with other information derived from licensees, users, or other sources. 

NETSCOUT reserves the right to use shared data across relevant NETSCOUT programs and technologies, including ATLAS, AED, Arbor Enterprise Manager, Sightline, and TMS.

To the extent applicable, shared data is governed by NETSCOUT’s Privacy Policy and its GDPR compliance program.