DDoS security
What DDoS attacks are, why they are harder to stop than ever, and how AI-driven, network-based security stops them in seconds
What is DDoS?
DDoS stands for distributed denial of service: a cyberattack designed to make a website, application or network unavailable by overwhelming it with malicious traffic or requests that it cannot fulfill — like a crowd blocking a store entrance so real customers cannot get in. DDoS attacks are launched from many devices and locations at once, usually a botnet of compromised computers, routers, cameras and other connected devices, remotely controlled by a botmaster using command-and-control (C2) instructions sent to insecure devices. DDoS attacks are larger, harder to trace and harder to block than single-source denial-of-service (DoS) attacks. DDoS attacks come in three main forms — volumetric, protocol and application-layer — and are often combined using multi-vector campaigns. DDoS defense uses monitoring, traffic analysis and mitigation to detect attacks, limit disruption and keep services available.
DDoS security explained Follow a botnet DDoS attack stage by stage
Why it matters
Availability is the target
Even a brief interruption can lead to outages, failed transactions, SLA penalties and reputational damage; losses from a single major incident can range from thousands to millions of dollars.
It is often a smokescreen
A DDoS attack does not steal data, but it can run alongside another security threat to divert security teams — with the highest stakes for critical infrastructure.
Service providers are exposed on every front
Residential customers see degraded quality of experience, enterprise customers see SLA breaches, and regulations such as NIS2 impose reporting obligations. Additionally, outbound attacks from compromised subscriber devices consume the operator’s own capacity, attack other devices within or outside the network, which can create legal liability.
Why are DDoS attacks harder to stop than ever?
DDoS attacks have grown sharply in size, frequency and sophistication — from one or two per day to well over 100 per day in many networks. Most are launched from botnets of insecure IoT devices over gigabit broadband, and increasingly from residential proxies that route attack traffic through ordinary household connections, making it look like genuine users. Attacks now originate inside service provider networks as well as outside, and AI-assisted campaigns shift vectors in seconds while monitoring how defenders respond. They are also shorter and smaller: most end before a human can react, which defeats any defense that needs minutes to divert traffic to a scrubbing center. The next generation of DDoS defense must understand the context of traffic, not just its volume; remove threats without harming legitimate users; learn from every encounter; and be built into the network itself.
of DDoS attacks in 2025 ended within five minutes, up from 44% in 2024 — faster than manual response allows.
active residential-proxy endpoints associated with DDoS in 2026, up from about 1 million a year earlier.
largest attack observed (October 2025); terabit-scale attacks now occur roughly five times more often than a year earlier.
How does Nokia stop modern DDoS attacks?
Nokia’s approach turns the network itself into the sensor and the enforcer. Deepfield Defender correlates network-wide telemetry with Deepfield Secure Genome® — Nokia’s hourly-updated security map of more than 5 billion IP addresses — to detect attacks with high confidence. Its AI models then create a mitigation strategy within seconds and enforce it on Nokia routers (7750 SR, 7330 SXR, 7250 IXR) or third-party routers (e.g., Juniper, Cisco) at line rate, with the 7750 Defender Mitigation System handling the most complex application-layer attacks. No backhauling to scrubbing centers, no diversion delay.
AI-driven detection that understands context, not just volume
Instead of static thresholds that mistake a game launch for an attack, Deepfield Defender enriches real-time network data with internet-scale context — device type, known vulnerabilities, behavior and botnet affiliation — cutting false positives and enabling confident automated response in seconds.
The network as sensor and enforcer
Modern routers enforce hundreds of thousands of ACL rules at line rate. Deepfield Defender programs them via NETCONF, FlowSpec or BGP in real time, stopping attacks at the network edge. Research indicates that over 95% of DDoS attacks can be mitigated on existing routers; the 7750 DMS handles the most advanced and complex ones.
Proactive, always-on protection with Genome Shield
Genome Shield compiles six continuously updated threat intelligence sources into automated policies enforced in the router data plane — disrupting botnet command-and-control (C2) communication before attacks launch and covering outbound threats from compromised subscriber devices, as well as inbound DDoS attacks.
Our vision is clear: from reactive, human-in-the-loop mitigation to proactive, continuously enforced, network-wide protection that learns from every attack.
Nokia DDoS security solution
The Nokia DDoS security solution combines Deepfield Defender and Secure Genome with Genome Shield, programmable Nokia and third-party routers and the 7750 Defender Mitigation System. Hetzner uses it to protect hundreds of thousands of servers across European data centers; Cinia uses it as the foundation of a managed, 24/7 protection service for Finland’s critical infrastructure.
Deepfield Defender
Next-gen, big data and AI-driven DDoS detection and mitigation solution.
Deepfield Genome Shield
Proactive, always-on, network-wide DDoS protection for the AI era.
7750 Defender Mitigation System
A next-generation platform for Layer 4–7 DDoS mitigation.
Customer success stories
Frequently asked questions
A distributed denial of service (DDoS) attack is a coordinated attempt to overwhelm a website, application or network with malicious traffic from many devices and locations at once, so that legitimate users’ traffic cannot get through. Service providers should care because attacks now exceed 100 per day in many networks, degrade quality of experience for residential customers, break enterprise SLAs, carry regulatory obligations (such as NIS2 in the EU), and — because much of today’s attack traffic originates from compromised subscriber devices inside the network — consume the operator’s own capacity and damage its IP reputation. Nokia Deepfield research shows most attacks now end within five minutes, faster than manual response allows.
A denial-of-service (DoS) attack generally originates from a single system. A distributed denial of service (DDoS) attack spreads traffic across many devices and locations — typically a botnet of compromised computers, routers, cameras and other IoT devices — making it larger, harder to trace and harder to block. Nearly all significant attacks today are distributed.
DDoS protection identifies malicious traffic and blocks, limits or redirects it while keeping legitimate users connected. Common methods include network monitoring and traffic analytics, traffic filtering, rate limiting, web application firewalls, content delivery networks with Anycast routing, and traffic scrubbing — deployed on-premises, in the cloud, in the service provider network, or in hybrid models. No single method stops every attack; modern network-based DDoS security, such as the Nokia Deepfield solution, combines AI-driven detection with automated mitigation enforced directly on network routers.
Traditional defenses rely on static thresholds, traffic baselines and known signatures. These fail against modern attacks because botnets generate traffic from real (not spoofed) IP addresses, from outside and from within the network; AI-assisted campaigns shift vectors within seconds; residential proxy networks rotate millions of consumer IP addresses past reputation lists; and most attacks now end within five minutes — before traffic can be diverted to a centralized scrubbing center. A modern defense must be intelligent, automated and integrated into the network itself.
Instead of backhauling traffic to centralized scrubbing centers, Nokia uses the network itself as sensor and enforcer. Nokia Deepfield Defender combines big data telemetry with Deepfield Secure Genome — an hourly-updated security map of more than 5 billion IP addresses — and AI engines that detect and auto-mitigate attacks in seconds, enforcing surgical filtering rules on existing IP routers at line rate. This delivers fewer false positives than threshold-based competitors, petabit-scale mitigation without a scrubbing bottleneck, detection of both inbound and outbound DDoS (including botnet traffic originating inside the network), and — through the 7750 Defender Mitigation System — fine-grained L4–L7 scrubbing for the most complex attacks. The same AI-driven approach counters AI-driven attacks: machine learning classifies shape-shifting campaigns that defeat static rules.
Nokia Deepfield Genome Shield is the foundation for proactive security automation and orchestration in the Nokia Deepfield DDoS security solution, built on Deepfield Defender. It aggregates threat intelligence from six continuously updated sources — Cloud Genome, Secure Genome, the Global DDoS Threat Alliance (GDTA), DeepRange, community data and licensed data — compiles it into automated security policies and enforces them in the data plane of existing Nokia and third-party routers and the 7750 Defender Mitigation System, with no diversions and no added latency. Against botnet and residential proxy DDoS specifically, Genome Shield disrupts communication between compromised devices and their command-and-control (C2) infrastructure — Nokia estimates its continuously updated rules block over 99% of all DDoS C2 malicious traffic — so enrolled devices never receive instructions to attack. Predictive protection keeps always-on rate limiters in place before campaigns begin, custom policies let operators block scanning, AI crawlers and malware sites, and observability dashboards track compromised devices, botnet endpoints and security trends — for inbound and outbound threats alike.
Learn more
Brochure
Blog
Article
Article
Blog
Blog
Blog
Blog
Ready to see how your network can become the shield against DDoS?
Please complete the form below.
The form is loading, please wait...
Thank you. We have received your inquiry. Please continue browsing.