Deepfield Defender
Advanced DDoS network security by Nokia
Protect your network with an AI-driven DDoS security solution tailored for service providers, cloud builders and new digital enterprises.
Nokia’s comprehensive DDoS security solution
In a world where cyber threats are continuously evolving, Nokia Deepfield Defender provides a robust and scalable solution to protect your network against DDoS attacks. Our AI-driven platform ensures real-time threat detection and automated mitigation, keeping your services secure and operational.
What is Deepfield Defender?
Deepfield Defender, a software application, combines network data (telemetry, DNS, BGP, etc.) with Nokia’s patented Deepfield Secure Genome® - a cloud-based, up-to-date data feed that tracks the security context of the internet.
What is Deepfield Secure Genome®?
Deepfield Secure Genome® is a cloud-based, up-to-date data feed that tracks the security context of the internet. It’s a “security map of the internet,” updated hourly, and with detailed visibility into over 5 billion IPv4 and IPv6 addresses, tracking internet traffic over 30 categories and deploying more than 100 Machine Learning rules (ML) for automatic classification and precise allocation of applications and flows into security-related traffic types and categories, Secure Genome “knows” intricate security details of the internet (e.g., details about prior attacks, insecure servers, and compromised IoT devices that can be used for DDoS attacks).
Why do we need a new approach to DDoS security?
The DDoS threat landscape has undergone a significant transformation in recent years, rendering traditional security measures ineffective. The proliferation of insecure and compromised IoT devices, along with multi-gigabit connectivity in the access layer, has created a vast army of potential bots, enabling malicious parties to exploit the increased bandwidth and connectivity and new generations of attacks with unprecedented ease. Network owners and operators – from enterprises to CSPs to cloud builders can no longer rely on traditional, static security solutions to protect against new generations of DDoS attacks; a new, more intelligent, agile and automated approach to DDoS security is needed to stay ahead of these evolving threats.
What is Nokia’s approach to DDoS security
Nokia Deepfield’s approach to DDoS security combines petabyte-scale big data IP analytics (provided by Deepfield Defender) with the power of advanced network routers (such as Nokia Service Routers and Service Interconnect Routers) and next-generation DDoS mitigation systems (such as 7750 Defender Mitigation System) to fight DDoS with unprecedented scale, efficiency and cost-efficiency.
Real-time DDoS detection and automated mitigation
Deepfield Defender identifies and mitigates DDoS attacks in real-time, using advanced algorithms that adapt to new threats. Our system rapidly scales to match the size of the attack, ensuring minimal disruption to your network.
- AI-driven analysis: Continuously learns and evolves to provide accurate threat detection.
- Scalable defense: Handles attacks of any size, from small-scale disruptions to massive, coordinated assaults.
- Real-time mitigation: Instantly neutralizes threats without human intervention.
How does Deepfield Defender detect DDoS?
Deepfield Defender correlates knowledge from Deepfield Secure Genome with the telemetry information obtained from the network (e.g., flow-based information and sampled mirrored packets) to detect DDoS faster and more accurately. Using artificial intelligence and machine learning (ML) algorithms, we create peacetime traffic models and raise DDoS threat alerts when we observe real-time anomalies. With knowledge about the larger internet security context and real-time, network-wide insight into network traffic, we are able to detect DDoS threat patterns as they happen—with much improved accuracy and speed.
How does Deepfield Defender help with DDoS mitigation?
Deepfield Defender considers the network's actual mitigation capabilities, overlooking all types of mitigation instruments and systems—from the network itself (when network-based mitigation is used) to additional scrubbing and mitigation systems that may be at the network’s disposal. Using AI-based decision trees and deep learning models, the most optimal mitigation strategy for a DDoS attack or a combination of DDoS attacks is created in seconds, so that precise filtering and mitigation strategies can be applied to mitigation systems such as programmable routers like Nokia FP4/FP5-based IP routers, or dedicated next-generation scrubbers like 7750 Defender Mitigation System.
Automated protection
The Nokia DDoS security solution integrates DDOS protection into the network, continuously monitoring traffic and detecting anomalies that could signify a DDoS attack. To automate DDoS protection and scale your defense to petabyte levels, Defender delivers optimized auto-mitigation. This allows DDoS attacks to be mitigated automatically, without supervision and manual tuning options. Extensive reports and customization options allow for further optimization, streamlining and automation of security workflows.
Elevate your security game with a managed security service offer
As an option to its core functionality, Deepfield Defender provides an extensive set of features that allow service providers to become a managed DDoS security service provider (MSSP) and offer a managed security service to their customers.
Service providers can use Deepfield Defender to provide premium DDoS protection services to their customers in the form of managed DDoS security services, effectively optimizing their network security while creating new revenue streams. When Deepfield Defender is used to enable DDoS Protection as a Service (DDoS-aaS) via Managed Security Service Provide portal functionality, service providers can enhance their services with added and customizable security services such as Basic protection (automatically included for all customers) and Premium protection (Enhanced protection for select customers such as high-risk industries (finance, gaming, cloud providers), while offering detailed insights and reporting to their premium customers via customizable user interfaces (UIs).
Let our team of experts assist you
Maximize your investment in Deepfield Defender and improve your security agility with the Nokia Deepfield Emergency Response Team Support (ERTS) service, provided directly by our global Nokia Deepfield Emergency Response Team (ERT).
Recap: Why choose Deepfield Defender?
- AI-driven DDoS mitigation: Deepfield Defender automatically detects and mitigates DDoS attacks with minimal impact on network performance.
- The most accurate detection: Deepfield Defender sets new standards for quick and accurate DDoS detection, with an extremely low rate of false positives and false negatives.
- Automated mitigation: Deepfield Defender's network-optimized mitigation strategy is automatically enacted in seconds by the network itself (in the case of network-based mitigation using sophisticated IP routers) or by advanced, dedicated DDoS mitigation systems, such as the 7750 Defender Mitigation System.
- Scalable for large networks: Designed for service providers and large enterprises, our solution can defend against even the largest attacks.
- Proactive protection: Deepfield Defender’s machine learning capabilities continuously evolve, ensuring your network is protected from the latest threats.
Why Nokia?
Nokia is a global leader in network security and innovation. With decades of experience, we provide cutting-edge solutions to keep your network safe from ever-evolving cyber threats.
Frequently Asked Questions
Distributed Denial of Service or DDoS is malicious traffic that aims to deny access or degrade or stop connectivity for individual users, internet hosts and service provider network infrastructure. Learn more about DDoS.
DDoS protection is a service or solution that detects and mitigates distributed denial-of-service (DDoS) attacks, which overwhelm a network with traffic to disrupt service.
AI-driven DDoS mitigation systems learn from previous attacks and adapt in real-time to provide faster and more accurate threat detection. Read more about how we harness Machine Learning and AI for adaptive, extensible and automated DDoS protection in our application note.
Deepfield Defender is ideal for service providers, cloud builders (such as internet exchange points, IXPs), large digital enterprises, financial institutions, and any organization that relies on continuous network availability.
Resources
Application notes
Customer success
- Bitė Latvia invests 5 million euros to implement Nokia's latest generation IP network and security technologies
- K2 Telecom partners with Nokia to strengthen its network security and create new revenue streams in Brazil
- Netplus partners Nokia to deliver future-proof and world-class broadband services
- Nokia and NL-ix deploy Deepfield for the largest IXP-based anti-DDoS protection for enterprises across Europe
- Nokia selected to upgrade Stealth Communications’ core network for increased capacity and DDoS security
- Telecentro Argentina partners with Nokia to modernize network transformation by using IP solutions for ultra-broadband services
Related solutions and products
Solution
Gain a holistic view of your network, services and subscribers
Solution
Protect your network with multi-layered embedded IP network security.
Product
Use big data analytics to understand your network traffic
Product
Troubleshoot anomalies, resolve issues and improve network performance
Product
Understand how services and content are delivered to your subscribers
Product
Deliver the best possible OTT video streaming experience
Learn more about DDoS

Event

Event

Blog

Blog

Blog

Analyst report

Customer success

Blog
Ready to talk?
Please complete the form below.
The form is loading, please wait...
Thank you. We have received your inquiry. Please continue browsing.