Introducing Deepfield Genome Shield
Nokia Deepfield Genome Shield is a foundation for proactive security automation and orchestration, enabling continuously updated, always-on, network-wide protection against modern distributed denial-of-service (DDoS) attacks and broader security threats. Attacks now originate from within telecommunications provider networks through remotely controlled residential proxy botnets comprising approximately 200 million compromised subscriber devices. Genome Shield is designed to help network security teams (NetOps and SecOps) keep pace with fundamental shifts in the DDoS and broader cybersecurity threat landscape.
AI-era proactive security
Industry-first proactive, always-on security automation built for the AI era — pre-positioned defense, not reactive mitigation
Intelligent data plane policies
Six continuously updated intelligence sources compiled into automated policies and enforced in the data plane of routers that service providers already deploy.
Network as a shield
Turns the network itself into the shield — no diversion, no detour, no added latency.
The security automation challenges
The DDoS threat landscape has changed dramatically since 2025. Earlier, attacks originated from outside the network; now, many of the largest threats come from our subscribers within telco networks, including more than 200 million compromised subscriber devices worldwide. Subscriber malware and DDoS traffic can overwhelm telecom provider infrastructure, resulting in degraded performance or outages. For a detailed perspective on the latest DDoS trends, check out our web page on the new DDoS threat landscape.
Genome Shield addresses three main security automation challenges:
Reactive mitigation is too slow
Proactive, network-wide protection. Traditional detect-then-mitigate approaches cannot respond to bursty, sub-minute attacks — what the datasheet calls DDoS tsunamis — and cloud-diversion ramp-up times exceed attack duration. Genome Shield provides a pre-positioned, continuously enforced defense.
Infrastructure protection gap
Outbound and subscriber threat management. Compromised devices within telecommunications providers' subscriber bases attack outward — a problem class that no existing commercial DDoS product addresses at scale. Genome Shield manages both inbound and outbound threat vectors.
Security automation vacuum
Dynamic threat management and automated response. Major telcos are currently building ad hoc scripts and dedicating five-to-ten-person teams to maintain custom security workflows. Genome Shield provides a scalable, commercial alternative.
Achieve more with Deepfield Genome Shield
Genome Shield turns Deepfield Defender into a unified, always-on shield against modern DDoS attacks.
Always-on protection without diversion delay
Pre-positioned policies enforced continuously across the network — eliminating the detect-then-divert gap that lets sub-minute DDoS tsunamis through.
Stop botnets at the source
Block command-and-control communications before attacks are launched, disrupting botnet operations rather than waiting to absorb the traffic they generate.
Inbound and outbound coverage
Defend against incoming DDoS attacks and outbound threats from compromised subscriber devices — a problem that no existing commercial DDoS product addresses at scale.
Replace ad hoc tooling and dedicated teams
Retire custom scripts and 5–10-person manual ops teams in favor of a unified, automated platform — at lower operational cost and with audit-ready policy enforcement.
Works with the network you have
Compatible with Nokia 7750 SRs (FP4/FP5), 7330 SXR (FPcx), 7250 IXR, the 7750 DMS, and third-party routers — your network becomes the shield.
Powerful features for proactive DDoS protection
Genome Shield extends Deepfield Defender with four pillars of proactive enforcement, powered by six continuously updated threat-intelligence sources.
Botnet C2 disruption
Block command-and-control communications before attacks are launched. Named rule families major botnet and residential proxy C2 disruptors, each maintained through ongoing Secure Genome updates and live intelligence from DeepRange – Deepfield’s cyber range.
DDoS policers
Suppress amplification and volumetric attack traffic through proactive rate limiting — pre-positioned across enforcement points so protection runs continuously rather than waiting for a detect-then-mitigate workflow to fire.
Custom policies
User-defined rules via open APIs and the Deepfield Defender UI for tailored, operator-specific threat responses that fit unique network topologies and policy frameworks.
Security observability
Detailed, security-focused dashboards for compromised devices, botnet endpoints, and emerging security trends — the visibility teams need to validate Genome Shield's automated responses and surface new patterns.
Multi-source intelligence
Genome Shield aggregates threat intelligence from six continuously updated sources:
- Cloud Genome: internet-scale traffic classification mapping applications, content providers, and infrastructure.
- Secure Genome: DDoS detection rules across 5+ billion IPv4/IPv6 endpoints, with hourly updates and 100+ ML classification rules.
- Global Deepfield Threat Alliance: real-time global DDoS telemetry aggregated from Deepfield Defender deployments (opt-in).
- DeepRange: Nokia's cybersecurity range — live insights from malware reverse engineering and C2 infiltration.
- Community data: open-source threat intelligence feeds and community-shared indicators of compromise.
- Licensed data: commercial threat intelligence and IP-reputation data from third-party providers.
Where Deepfield Genome Shield makes an impact
Telecommunications and hosting infrastructure protection
Operators with millions of subscriber devices need both inbound DDoS protection and outbound C2 disruption from their own subscriber base. Genome Shield delivers bidirectional protection at scale, addressing both sides of the proxy-botnet problem from a single automated platform.
Defense for AI and cloud, and large digital enterprises
AI providers, cloud builders, transit providers, IXPs, research and education networks, and large digital enterprises with high-value compute infrastructure are prime targets for DDoS attacks as AI workloads scale. Genome Shield provides always-on defense without diversion latency.
Sovereign, managed, and replacement deployments
Service providers with sovereign and on-shore security mandates that cannot accept hyperscaler or cloud-based DDoS services. MSSPs and managed DDoS providers can monetize DDoS protection as a premium service. Network operators can retire outdated defenses using a unified, automated security platform.
Technical specifications
Genome Shield's enforcement, intelligence, and deployment building blocks for operators planning a rollout.
Specification
Detail
Product type
Software platform for security automation and orchestration. Requires Deepfield Defender.
Deployment models
On-premises, cloud-based, and hybrid.
Protection mode
Proactive, continuously enforced.
Protection direction
Inbound DDoS mitigation, outbound C2 disruption, and infrastructure defense.
Enforcement protocols
NETCONF (granular filter management), BGP RTBH (immediate traffic discard), FlowSpec (protocol-specific filtering).
Supported infrastructure
Nokia 7750 Service Routers (FP4/FP5 silicon), 7330 SXR (FPcx), 7250 IXR; Nokia 7750 DMS-1-24D for dedicated L4-L7 scrubbing (up to 2.8 Tb/s per system, Advanced Countermeasures Engine); third-party routers (e.g., Juniper, Cisco).
Intelligence sources
Cloud Genome, Secure Genome, GDTA, DeepRange, community data, licensed data.
Management interfaces
Deepfield Defender UI, REST API.
Licensing
Pay-as-you-grow. Operators can start with a focused deployment and expand coverage as their threat surface and traffic volumes grow.
Genome Shield network integration
Defender security automation: from intelligence to enforcement
Resources
Application notes
Solution brochure
Infographics
Related solutions and products
Solution
Turn data from your network into your competitive edge.
Product
Transform your network operations with actionable network intelligence
Product
Next-gen, big data and AI-driven DDoS detection and mitigation solution.
Product
Turn subscriber insights into revenues
Customer success stories
Genome Shield is used by Deepfield Defender customers today, addressing both inbound DDoS attacks and outbound threats originating from compromised subscriber devices.
Frequently asked questions
Deepfield Genome Shield is a proactive security automation and orchestration platform that delivers continuously updated, always-on, network-wide protection against modern DDoS attacks and broader security threats.
The DDoS threat landscape has fundamentally shifted: attacks now originate from inside the network — residential proxy botnets of roughly 200 million compromised subscriber devices, capable of delivering DDoS tsunamis (1–10+ Tb/s bursts) that arrive in minutes.
Traditional detect-then-divert mitigation was built for spoofed, multi-hour attacks from outside the network and is structurally too slow for sub-minute bursts; it also cannot address compromised devices attacking outward from within (outbound DDoS).
Genome Shield extends Deepfield Defender to close that gap: it aggregates threat intelligence from six continuously updated sources, compiles it into automated security policies, and enforces them in the data plane of the routers operators already run — no diversion, no detour, no added latency — turning the network into a self-defending protection mechanism against both inbound and outbound threats.
.
Genome Shield is built specifically for the residential proxy botnet era, in which roughly 200 million compromised subscriber devices launch non-spoofed attacks using real IP addresses from behind home firewalls and NAT. Rather than waiting to detect and divert, it enables Deepfield Defender to pre-position continuously enforced protection across the network, so that the network can respond to bursty, sub-minute attacks that would otherwise defeat reactive detect-then-divert models. Genome Shield’s dynamic threat feed infrastructure delivers real-time protection against thousands of constantly changing malicious IP addresses at line speed — solving the filter-scale problem that defeats conventional defenses — while continuously updated rules disrupt botnet and residential proxy command-and-control (C2) at the source (Nokia estimates that over 99 percent of C2 malicious traffic is blocked). Critically, it protects in both directions, addressing inbound DDoS and the outbound threats from compromised subscriber devices that legacy products were never designed to handle.
A DDoS tsunami is a hyper-volumetric attack that arrives in massive bursts of 1–10+ Tb/s, ramping up within minutes (or seconds), lasting only minutes, and often recurring in waves. Unlike the spoofed, multi-hour attacks of the past, these bursts are non-spoofed, give defenders almost no warning, and are over before traditional cloud-diversion or off-ramp scrubbing can ramp up. That timing mismatch is exactly why Genome Shield's pre-positioned, continuously enforced protection is required: defense must be already in place when the wave hits, not activated after detection.
Genome Shield is a software platform that requires Deepfield Defender and can be deployed on-premises, in the cloud or in a hybrid model. It requires no new dedicated security appliances, because it enforces through the network's own existing points. Edge mitigation is performed at line rate by Nokia routers (7750 SR with FP4/FP5 silicon, 7730 SXR with FPcx, and 7250 IXR) or third-party routers such as Cisco and Juniper, and can be combined with the Nokia 7750 DMS for dedicated scrubbing (up to 2.8 Tb/s per system). Policies are pushed using standard enforcement protocols — NETCONF for granular filtering, FlowSpec for interoperability and BGP RTBH for bulk discard — and the whole system is managed through the Deepfield Defender GUI and REST API.
Yes. It can be deployed with Deepfield Defender and your existing Nokia or third-party router edge, and optionally with the Nokia 7750 DMS, enabling you to move from reactive mitigation to proactive, always-on protection without re-architecting the network.
Learn more about DDoS
Article
Blog
Blog
Blog
Blog
Blog
Blog
Blog
Ready to protect your network from DDoS tsunamis and the residential-proxy-botnet era?
Please complete the form below.
The form is loading, please wait...
Thank you. We have received your inquiry. Please continue browsing.