Deepfield Genome Shield

Proactive, network-wide DDoS protection

blue background image with dna like structure

Introducing Deepfield Genome Shield

Nokia Deepfield Genome Shield is a foundation for proactive security automation and orchestration, enabling continuously updated, always-on, network-wide protection against modern distributed denial-of-service (DDoS) attacks and broader security threats. Attacks now originate from within telecommunications provider networks through remotely controlled residential proxy botnets comprising approximately 200 million compromised subscriber devices. Genome Shield is designed to help network security teams (NetOps and SecOps) keep pace with fundamental shifts in the DDoS and broader cybersecurity threat landscape. 

AI-era proactive security

Industry-first proactive, always-on security automation built for the AI era — pre-positioned defense, not reactive mitigation

Intelligent data plane policies

Six continuously updated intelligence sources compiled into automated policies and enforced in the data plane of routers that service providers already deploy.

Network as a shield

Turns the network itself into the shield — no diversion, no detour, no added latency.

The security automation challenges

The DDoS threat landscape has changed dramatically since 2025. Earlier, attacks originated from outside the network; now, many of the largest threats come from our subscribers within telco networks, including more than 200 million compromised subscriber devices worldwide. Subscriber malware and DDoS traffic can overwhelm telecom provider infrastructure, resulting in degraded performance or outages. For a detailed perspective on the latest DDoS trends, check out our web page on the new DDoS threat landscape

Genome Shield addresses three main security automation challenges:

Reactive mitigation is too slow

Proactive, network-wide protection. Traditional detect-then-mitigate approaches cannot respond to bursty, sub-minute attacks — what the datasheet calls DDoS tsunamis — and cloud-diversion ramp-up times exceed attack duration. Genome Shield provides a pre-positioned, continuously enforced defense.

Infrastructure protection gap

Outbound and subscriber threat management. Compromised devices within telecommunications providers' subscriber bases attack outward — a problem class that no existing commercial DDoS product addresses at scale. Genome Shield manages both inbound and outbound threat vectors.

Security automation vacuum

Dynamic threat management and automated response. Major telcos are currently building ad hoc scripts and dedicating five-to-ten-person teams to maintain custom security workflows. Genome Shield provides a scalable, commercial alternative.

Achieve more with Deepfield Genome Shield

Genome Shield turns Deepfield Defender into a unified, always-on shield against modern DDoS attacks.

Always-on protection without diversion delay

Pre-positioned policies enforced continuously across the network — eliminating the detect-then-divert gap that lets sub-minute DDoS tsunamis through.

Stop botnets at the source

Block command-and-control communications before attacks are launched, disrupting botnet operations rather than waiting to absorb the traffic they generate.

Inbound and outbound coverage

Defend against incoming DDoS attacks and outbound threats from compromised subscriber devices — a problem that no existing commercial DDoS product addresses at scale.

Replace ad hoc tooling and dedicated teams

Retire custom scripts and 5–10-person manual ops teams in favor of a unified, automated platform — at lower operational cost and with audit-ready policy enforcement.

Works with the network you have

Compatible with Nokia 7750 SRs (FP4/FP5), 7330 SXR (FPcx), 7250 IXR, the 7750 DMS, and third-party routers — your network becomes the shield.

Powerful features for proactive DDoS protection

Genome Shield extends Deepfield Defender with four pillars of proactive enforcement, powered by six continuously updated threat-intelligence sources.

Botnet C2 disruption

Block command-and-control communications before attacks are launched. Named rule families major botnet and residential proxy C2 disruptors, each maintained through ongoing Secure Genome updates and live intelligence from DeepRange – Deepfield’s cyber range.

DDoS policers

Suppress amplification and volumetric attack traffic through proactive rate limiting — pre-positioned across enforcement points so protection runs continuously rather than waiting for a detect-then-mitigate workflow to fire.

Custom policies

User-defined rules via open APIs and the Deepfield Defender UI for tailored, operator-specific threat responses that fit unique network topologies and policy frameworks.

Security observability

Detailed, security-focused dashboards for compromised devices, botnet endpoints, and emerging security trends — the visibility teams need to validate Genome Shield's automated responses and surface new patterns.

Multi-source intelligence

Genome Shield aggregates threat intelligence from six continuously updated sources:

  • Cloud Genome: internet-scale traffic classification mapping applications, content providers, and infrastructure.
  • Secure Genome: DDoS detection rules across 5+ billion IPv4/IPv6 endpoints, with hourly updates and 100+ ML classification rules.
  • Global Deepfield Threat Alliance: real-time global DDoS telemetry aggregated from Deepfield Defender deployments (opt-in).
  • DeepRange: Nokia's cybersecurity range — live insights from malware reverse engineering and C2 infiltration.
  • Community data: open-source threat intelligence feeds and community-shared indicators of compromise.
  • Licensed data: commercial threat intelligence and IP-reputation data from third-party providers.

Where Deepfield Genome Shield makes an impact

Telecommunications and hosting infrastructure protection

Operators with millions of subscriber devices need both inbound DDoS protection and outbound C2 disruption from their own subscriber base. Genome Shield delivers bidirectional protection at scale, addressing both sides of the proxy-botnet problem from a single automated platform.

Defense for AI and cloud, and large digital enterprises

AI providers, cloud builders, transit providers, IXPs, research and education networks, and large digital enterprises with high-value compute infrastructure are prime targets for DDoS attacks as AI workloads scale. Genome Shield provides always-on defense without diversion latency.

Sovereign, managed, and replacement deployments

Service providers with sovereign and on-shore security mandates that cannot accept hyperscaler or cloud-based DDoS services. MSSPs and managed DDoS providers can monetize DDoS protection as a premium service. Network operators can retire outdated defenses using a unified, automated security platform.

Technical specifications

Genome Shield's enforcement, intelligence, and deployment building blocks for operators planning a rollout.

Specification

Detail

Product type

Software platform for security automation and orchestration. Requires Deepfield Defender.

Deployment models

On-premises, cloud-based, and hybrid.

Protection mode

Proactive, continuously enforced.

Protection direction

Inbound DDoS mitigation, outbound C2 disruption, and infrastructure defense.

Enforcement protocols

NETCONF (granular filter management), BGP RTBH (immediate traffic discard), FlowSpec (protocol-specific filtering).

Supported infrastructure

Nokia 7750 Service Routers (FP4/FP5 silicon), 7330 SXR (FPcx), 7250 IXR; Nokia 7750 DMS-1-24D for dedicated L4-L7 scrubbing (up to 2.8 Tb/s per system, Advanced Countermeasures Engine); third-party routers (e.g., Juniper, Cisco).

Intelligence sources

Cloud Genome, Secure Genome, GDTA, DeepRange, community data, licensed data.

Management interfaces

Deepfield Defender UI, REST API.

Licensing

Pay-as-you-grow. Operators can start with a focused deployment and expand coverage as their threat surface and traffic volumes grow.

Genome Shield network integration

Defender security automation: from intelligence to enforcement

genome network integration

Related solutions and products

Solution

Turn data from your network into your competitive edge.

Product

Next-gen, big data and AI-driven DDoS detection and mitigation solution.

Frequently asked questions

Ready to protect your network from DDoS tsunamis and the residential-proxy-botnet era?

Please complete the form below.

The form is loading, please wait...

Thank you. We have received your inquiry. Please continue browsing.