Main content

DDoS security

What DDoS attacks are, why they are harder to stop than ever, and how AI-driven, network-based security stops them in seconds

What is DDoS?

DDoS stands for distributed denial of service: a cyberattack designed to make a website, application or network unavailable by overwhelming it with malicious traffic or requests that it cannot fulfill — like a crowd blocking a store entrance so real customers cannot get in. DDoS attacks are launched from many devices and locations at once, usually a botnet of compromised computers, routers, cameras and other connected devices, remotely controlled by a botmaster using command-and-control (C2) instructions sent to insecure devices. DDoS attacks are larger, harder to trace and harder to block than single-source denial-of-service (DoS) attacks. DDoS attacks come in three main forms — volumetric, protocol and application-layer — and are often combined using multi-vector campaigns. DDoS defense uses monitoring, traffic analysis and mitigation to detect attacks, limit disruption and keep services available.
 

DDoS security explained   Follow a botnet DDoS attack stage by stage

Why it matters

Availability is the target

Even a brief interruption can lead to outages, failed transactions, SLA penalties and reputational damage; losses from a single major incident can range from thousands to millions of dollars.

It is often a smokescreen

A DDoS attack does not steal data, but it can run alongside another security threat to divert security teams — with the highest stakes for critical infrastructure.

Service providers are exposed on every front

Residential customers see degraded quality of experience, enterprise customers see SLA breaches, and regulations such as NIS2 impose reporting obligations. Additionally, outbound attacks from compromised subscriber devices consume the operator’s own capacity, attack other devices within or outside the network, which can create legal liability.

Why are DDoS attacks harder to stop than ever?

DDoS attacks have grown sharply in size, frequency and sophistication — from one or two per day to well over 100 per day in many networks. Most are launched from botnets of insecure IoT devices over gigabit broadband, and increasingly from residential proxies that route attack traffic through ordinary household connections, making it look like genuine users. Attacks now originate inside service provider networks as well as outside, and AI-assisted campaigns shift vectors in seconds while monitoring how defenders respond. They are also shorter and smaller: most end before a human can react, which defeats any defense that needs minutes to divert traffic to a scrubbing center. The next generation of DDoS defense must understand the context of traffic, not just its volume; remove threats without harming legitimate users; learn from every encounter; and be built into the network itself.

78%

of DDoS attacks in 2025 ended within five minutes, up from 44% in 2024 — faster than manual response allows.

8–9 million

active residential-proxy endpoints associated with DDoS in 2026, up from about 1 million a year earlier.

33 Tbps

largest attack observed (October 2025); terabit-scale attacks now occur roughly five times more often than a year earlier.

How does Nokia stop modern DDoS attacks?

Nokia’s approach turns the network itself into the sensor and the enforcer. Deepfield Defender correlates network-wide telemetry with Deepfield Secure Genome® — Nokia’s hourly-updated security map of more than 5 billion IP addresses — to detect attacks with high confidence. Its AI models then create a mitigation strategy within seconds and enforce it on Nokia routers (7750 SR, 7330 SXR, 7250 IXR) or third-party routers (e.g., Juniper, Cisco) at line rate, with the 7750 Defender Mitigation System handling the most complex application-layer attacks. No backhauling to scrubbing centers, no diversion delay.

AI-driven detection that understands context, not just volume

Instead of static thresholds that mistake a game launch for an attack, Deepfield Defender enriches real-time network data with internet-scale context — device type, known vulnerabilities, behavior and botnet affiliation — cutting false positives and enabling confident automated response in seconds.


Explore Deepfield Defender

The network as sensor and enforcer

Modern routers enforce hundreds of thousands of ACL rules at line rate. Deepfield Defender programs them via NETCONF, FlowSpec or BGP in real time, stopping attacks at the network edge. Research indicates that over 95% of DDoS attacks can be mitigated on existing routers; the 7750 DMS handles the most advanced and complex ones.


Discover the 7750 Defender Mitigation System

thumbnail
abstract image

Proactive, always-on protection with Genome Shield

Genome Shield compiles six continuously updated threat intelligence sources into automated policies enforced in the router data plane — disrupting botnet command-and-control (C2) communication before attacks launch and covering outbound threats from compromised subscriber devices, as well as inbound DDoS attacks.


Explore Deepfield Genome Shield

Our vision is clear: from reactive, human-in-the-loop mitigation to proactive, continuously enforced, network-wide protection that learns from every attack.

Nokia DDoS security solution

The Nokia DDoS security solution combines Deepfield Defender and Secure Genome with Genome Shield, programmable Nokia and third-party routers and the 7750 Defender Mitigation System. Hetzner uses it to protect hundreds of thousands of servers across European data centers; Cinia uses it as the foundation of a managed, 24/7 protection service for Finland’s critical infrastructure.

Frequently asked questions

Ready to see how your network can become the shield against DDoS?

Please complete the form below.

The form is loading, please wait...

Thank you. We have received your inquiry. Please continue browsing.