惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Stack Overflow Blog
Stack Overflow Blog
S
SegmentFault 最新的问题
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
U
Unit 42
GbyAI
GbyAI
B
Blog RSS Feed
博客园 - Franky
L
LangChain Blog
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
云风的 BLOG
云风的 BLOG
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 三生石上(FineUI控件)
Microsoft Azure Blog
Microsoft Azure Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
Last Week in AI
Last Week in AI
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research

NETSCOUT

From Data Overload to Network Intelligence | NETSCOUT How IT and Executives View Business Impact of Network Disruptions | NETSCOUT Cyberattack in Poland Causes Heat and Power Outages for 50,000 Residents | NETSCOUT NETSCOUT Earns Top Recognition in 2026 for DDoS Mitigation | NETSCOUT Observability with AI-Ready Data Helps Reduce Time to Solve Problems | NETSCOUT Getting Beyond the Noise for Data That Really Thinks | NETSCOUT The Future of Observability Isn’t More Data; It’s Smarter Data | NETSCOUT What Is Keeping IT Leaders and Teams Up at Night Right Now? | NETSCOUT The Compelling Need for AI-Ready ‘Smart Data’ | NETSCOUT How AI Is Reshaping the Radio Access Network | NETSCOUT Six Critical Business Benefits of Real-Time Data Insights | NETSCOUT AI Reality Check: Why IT Teams Are Embracing AI | NETSCOUT The Future of Telecom Operations Is Powered by Autonomy at Scale | NETSCOUT Why Customer Lifetime Value Begins on the Network | NETSCOUT Service Providers Rethink Fraud Detection in the 5G Era | NETSCOUT Resilience Is the Foundation of Modern Security Strategy | NETSCOUT How Machines Are Taking Over Network Traffic | NETSCOUT Why AI Moves Faster Than the Controls Built to Manage It | NETSCOUT NETSCOUT Named a SPARK Matrix™ Leader in Network Observability for the Third Consecutive Year | NETSCOUT Why CDNs Alone Are Not Sufficient for Modern DDoS Protection | NETSCOUT All That Glitters Isn’t Gold: Why AI Needs Better Data | NETSCOUT From Horseback to Real-Time Observability | NETSCOUT Why Digital Twins Are Now Mission-Critical for Scaling 5G with Confidence | NETSCOUT NETSCOUT Earns Six Leader Badges in the G2 Summer 2026 Grid Reports | NETSCOUT When Too Much Data Becomes Too Big an AI Problem | NETSCOUT Game-Changing AI in the RAN Plays by Its Own Rules | NETSCOUT 75,000 DDoS-for-Hire Actors Targeted by Law Enforcement | NETSCOUT What Is NETSCOUT Smart Data and Why Is It So Important? | NETSCOUT Understanding Network Traffic for Threat Hunting | NETSCOUT Black Box Versus Glass Box DDoS Protection
Smarter DDoS Security at Scale
2025-11-24 · via NETSCOUT

Stopping encrypted attacks with NETSCOUT Arbor Edge Defense

Person in hoodie looking at hex data.

In today’s digital landscape, encrypted traffic is the norm—not the exception. While encryption such as Transport Layer Security (TLS) 1.3 protects user privacy and data integrity, it also presents a growing challenge for security teams: How do you defend against threats hidden inside encrypted traffic without overwhelming your systems?

The Challenge of Encrypted DDoS Attacks

Threat actors are always looking for ways to circumvent modern defenses, and one of the most popular distributed denial-of-service (DDoS) attack methods is to hide the attacks in what looks like ordinary traffic. Enormous amounts of internet traffic now rely on Hypertext Transfer Protocol Secure (HTTPS). Since decrypting TLS 1.3 traffic typically requires proxy-based solutions—which are resource-intensive—many security products struggle to inspect encrypted sessions effectively. This blind spot makes encrypted DDoS attacks harder to detect and mitigate.

Block First, Ask Questions Later

One way to minimize the impact of encrypted attack traffic is to simply drop it before decrypting. There are several methods we employ to filter out the garbage quickly and efficiently:

  • Known source blocking: Many attackers are now using open internet proxies to hide the source of their HTTPS attacks. We constantly track these sources, and our ATLAS Intelligence Feed (AIF)-powered countermeasure can block them automatically.
  • TLS attack prevention: This countermeasure looks at the TLS handshake (pre-encryption) and can block TLS sessions that don’t follow standard user behaviors​.
  • TCP connection limiting: This countermeasure looks at TCP connection behavior from each source. Sources opening too many connections or engaging in abusive behaviors over TCP can be blocked.
  • Rate-based protections: Usually attackers will be sending more traffic than legitimate users, and these protections can distinguish and block those sources automatically​.
  • Selective decryption: This is used to decrypt and deal with more-advanced attacks, when encrypted traffic behavior mimics legitimate users.

Why Full Decryption Isn’t Always the Answer

Decrypting all traffic isn’t practical. It’s computationally expensive and can quickly exhaust system resources. What’s needed is a smarter approach—one that focuses decryption efforts only where it’s truly necessary.

NETSCOUT’s Solution: Selective Decryption

NETSCOUT’s Arbor Edge Defense (AED) offers a powerful solution via selective decryption. Positioned at the network edge, AED intelligently decides which traffic to decrypt based on threat indicators and client validation.

Here’s how it works:

  • Intelligent decryption: As the traffic enters, AED identifies valid client traffic and passes it on without requiring decryption
  • Suspicious traffic decryption: Only nonvalidated encrypted traffic is decrypted and analyzed for DDoS threats
  • Customizable decryption: Users can enable decryption for specific protection groups or levels, allowing targeted inspection without wasting resources

Chart

Benefits of Selective Decryption

Efficient resource use: Focuses decryption on suspicious traffic, preserving system performance
Scalable protection: Enables high-scale defense against encrypted threats without compromising throughput
Flexible configuration: Tailors decryption policies to match the needs of different services and threat levels

Conclusion

As encrypted traffic continues to grow, so does the need for smarter security solutions. NETSCOUT AED’s selective decryption approach empowers organizations to defend against encrypted DDoS attacks efficiently and effectively—without sacrificing performance.

    Learn more about Arbor Edge Defense.