Perimeter Defense Best Practices Using Arbor Edge Defense

The Need for On-Premises & In-Cloud Collaboration

NETSCOUT Adaptive DDoS Protection Strategy leverages a robust, always-on, on-premises solution specifically designed to automatically identify and neutralize all types of DDoS attacks against enterprises and service providers. Adapting to the escalating intensity and complexity of cyber threats ensures unimpeded access to your business-critical services. This strategy incorporates intelligent systems that swiftly detect and counteract threats, preventing potential disruptions before they affect the availability and performance of your vital network infrastructure. This proactive approach provides a robust shield, ensuring your enterprise is always protected against evolving cyber threats.

Although traditional cloud-based DDoS protection solutions, including those provided by ISPs or CDNs, are designed to stop large volumetric DDoS attacks, they struggle to eliminate other types of DDoS attacks designed to evade their efforts.  Cloud-based mitigation is an augmentation of on-premises protection. On-premises DDoS attack protection has capabilities intended to identify and mitigate those attacks designed to circumvent cloud-based solutions.

What’s more, due to the dynamic, multi-vector nature of the modern-day DDoS attack, the Best Practice is to employ both on-premises and a cloud solution with an intelligent and automated integration that offers a dynamic adaptable DDoS protection.

The Internet, ISP Backbone, and On-Prem Inline
Click to enlarge image

An On-Premises Adaptive DDoS Protection Solution Should be a Priority

Industry analysts are coming to grips with the fact that due to today’s growing frequency and dynamic nature of DDoS attacks, the need for a multilayer, adaptable DDoS protection strategy is now a requirement. Furthermore, due to the creation of new attack vectors like Adaptive DDoS Attack, which change vectors based on the defense that is presented, the need for On-Premises DDoS attack mitigation real-time in-line attack analysis a priority.

On-Premises DDoS Protection White Paper

Excellent tool. Before installing NETSCOUT Arbor we were unaware of the amount of unwanted traffic hitting our network. Being able to block these has definitely given our firewall some breathing space.

Gary Booth, IT Manager, South Staffordshire College

Why On-Premises Protection Should Be The Foundation of an Adaptive DDoS Protection Strategy

On-Premises DDoS Attack Protection

NETSCOUT Arbor DDoS Attack protection solution is an intelligently automated, combination of in-cloud and on-premises DDoS attack protection that is continuously backed by global threat intelligence and expertise.

Stopping Application Layer Attacks

Because application layer attacks are typically made up of lower volume traffic, they do not automatically trigger volumetric monitors employed by cloud scrubbing solutions and require on-premise devices like Arbor Edge Defense (AED) to automatically detect and mitigate.

Protecting Stateful Devices

Stateful devices within your network like NGFWs, VPN Concentrators and Load Balancers are common targets for state exhaustion attacks. Protecting them in an always on manner can only be accomplished with an On Premise stateless device like AED.

Blocking Internal & External C2 Communications

Once an attacker breaches your network, compromised internal devices will communicate with their command-and-control infrastructure for further instructions. Deployed outside your firewall, Arbor Edge Defense (AED) blocks Indicators of Compromise (IoC) acting as a last line of defense for your organization.

Stopping Attacks in Encrypted Traffic

When cyber criminals embed attacks within encrypted traffic the only way to detect them is through decryption. Unlike decryption in the cloud, a safer method is to utilize the on-premises, embedded decryption capabilities in Arbor Edge Defense (AED).

2022 CyberSecured Award Winner: Network Security

AED has definitely improved uptime for applications that are bringing business value to the company.

-Manager of Cyber Defense Center Engineering for a logistics firm

CyberSecured Awards 2022

What to Do If You Are Experiencing a DDoS Attack

NETSCOUT’s industry leading DDoS mitigation experts provide 365/24/7 DDoS Attack Support.