Meet The Attackers – Breaking Down the Global Threat Landscape
Download resourcesAbout this session
Patrick and Andrew from NetScout, joined by a non-presenting colleague named Dylan, use a Taylor Swift concert analogy to introduce three DDoS vectors: volumetric (a crowd blocking the door), state exhaustion (fans nursing one drink to occupy a seat), and application layer (an absurdly complex order that ties up service). Andrew walks through NetScout's twice-yearly Threat Report, drawn from visibility into roughly 90 percent of the world's service providers: attack counts keep climbing, and the mix has shifted away from reflection-amplification attacks, now easy to block, toward botnet-driven direct-path attacks like SYN and RST floods. He profiles two hacktivist groups, Anonymous Sudan and the custom-tooled, gamified NoName057, and covers a rise in attacks on authoritative DNS servers, including DNS water torture. Patrick explains why defense is hard and argues over 70 percent of attacks now bypass volumetric protection, making a stateless, always-on inline appliance in front of the firewall the recommended complement in a hybrid model. Andrew closes on DDoS rarely happening in isolation: NetScout found 65 percent overlap between verified DDoS bot activity and command-and-control honeypots. Q&A covers AI's limited effect on attack techniques and cloud-native defense.
The Global Threat Landscape is Evolving – Are you prepared to effectively Defend Yourself? Spoiler alert: Everyone is a Target.
Distributed Denial of Service (DDoS) attacks have been with as for as long as the Internet itself and have been used by a variety of attackers in a variety of different ways for a variety of reasons over the years. In this discussion we will take a look at some of the motivations, methods and goals of the attackers, and explain best practices around mitigation of common attacks. We than ask the next important question - is this just about denial of service, or is there more to it? And if so, what are we able to do about it?
Key takeaways
- Do not assume your ISP or cloud provider's DDoS protection is sufficient: over 70% of attacks NetScout tracks are now state-exhaustion or application-layer, which volumetric-focused defenses miss.
- Deploy a stateless, always-on inline appliance in front of your firewall to catch state-exhaustion and application-layer attacks, and pair it with cloud/ISP scrubbing for the volumetric case (a hybrid model).
- Treat any DDoS attack as a possible smokescreen: check for concurrent reconnaissance, scanning, or command-and-control activity from the same source IPs rather than closing the case once the attack stops.
- Expect short, repeated attacks designed to outlast your manual mitigation response time rather than one large sustained attack; automated, instant detection matters more than raw capacity.
- If most of your web content sits behind a CDN, remember it does not protect non-web infrastructure like VPN, SMTP, or DNS servers, those need separate DDoS defense.
Speakers

With over 35 years in the IT industry, Andrew Cockburn has broad experience in roles ranging from software design and development, pre-sales and consulting, to engagement and project management in various industry sectors including Online… Read moreRead less
With over 35 years in the IT industry, Andrew Cockburn has broad experience in roles ranging from software design and development, pre-sales and consulting, to engagement and project management in various industry sectors including Online Transaction Processing, Billing & Mediation, Layer 7 Parser Development and other Security Products. Previously working for companies such as Honeywell, AT&T GIS, IBM and Narus, he is currently in his 13th year at NETSCOUT, and is NETSCOUT’s CTO Office DDoS Specialist, assisting in pre-sale activities focused on Anti-DDoS solutions for Enterprises, Tier 1 and 2 carriers in North America as well as product feedback to Engineering and Product Management and enablement for field personnel.
