Harden Stance Briefing Allots Doubles Down on DDoS Defence 2025

Harden Stance Briefing Allots Doubles Down on DDoS Defence 2025
Allot is strengthening Smart NetProtect with a hybrid DDoS defense model that adds out-of-band detection and flexible mitigation options for telecom operators. The report highlights surging DDoS volumes, record-breaking attacks, and growing pressure on telco networks from botnets, 5G, and nation-state activity. #Allot #SmartNetProtect #Aisuru #RapperBot #VoltTyphoon #Kyivstar #ENISA #Cloudflare

Keypoints

  • Annual cybersecurity and threat landscape reports typically open with an executive overview, then move into the main threat trends, sector-specific impacts, attack techniques, and strategic vendor or market implications.
  • They often include a section on major incident statistics, benchmark data from industry sources, and comparisons with prior periods to show how threats are changing over time.
  • Another common section covers attacker behavior and TTPs, explaining how threat actors adapt their methods, which infrastructure is being targeted, and what new vulnerabilities are being exploited.
  • Reports usually conclude with defensive recommendations, product or platform updates, and a forward-looking view of how the threat environment is expected to evolve.
  • In this report, cybersecurity is framed as Allot’s long-term growth engine, with Security as a Service generating $16.5 million and accounting for 18% of total revenue in 2024.
  • ENISA data shows DDoS attacks caused 77% of all cyber incidents in the EU in the 12 months to June 2025, a sharp increase from 41% in the previous 12-month period.
  • Cloudflare reported 27.8 million DDoS attacks blocked in just the first half of 2025, exceeding the 21.3 million attacks blocked across all of 2024, indicating rapid threat growth.
  • The telecom sector emerged as a primary target, overtaking gambling and casinos in Cloudflare’s Q2 2025 reporting as the most attacked industry by DDoS activity.
  • The Aisuru botnet was identified as a major driver of 2025 DDoS activity, with compromised smart home devices inside Tier 1 U.S. carrier networks generating large outbound and cross-bound attacks.
  • Aisuru was linked to a record-setting attack peaking at 22.2 Tbps and 10.6 billion packets per second in September 2025, underscoring the escalating scale of volumetric attacks.
  • Nokia reported that 78% of DDoS attacks in the 12 months to June 2025 lasted less than five minutes, up from 44% in the prior year, showing a shift toward shorter but more intense events.
  • The report highlights new risk introduced by 5G NSA, 5G FWA, and the rollout of 5G SA, which expand the attack surface and can amplify outbound DDoS traffic from connected devices.
  • 5G network slices and their SLAs are described as more sensitive to DDoS-driven service and QoE degradation than traditional 4G and 5G NSA environments.
  • Allot’s original Smart NetProtect model relied on inline sensors, behavioral analytics, and machine learning to detect and mitigate inbound and outbound volumetric attacks in near real time.
  • The new 1H 2026 release shifts to a hybrid architecture that keeps inline capabilities but adds out-of-band sensing, aligning more closely with common telecom DDoS defense preferences.
  • Two mitigation paths are emphasized: BGP Flowspec using flow-based sensors at L3/L4, and a more accurate but more expensive off-ramp scrubbing center hosted in the customer’s data center.
  • The report notes that tier 2 carriers will likely favor the lower-cost BGP Flowspec option, while tier 1 carriers may prefer the higher-accuracy off-ramp model.
  • By allowing operators to mix and match mitigation modes based on risk profile, traffic type, and policy, Allot aims to improve scalability and reduce the cost of always-on inline inspection.
  • An optional Security Community feature adds threat intelligence sharing among participating telcos and ISPs, strengthening collaborative defense and notification of known threats.
  • The overall takeaway is that DDoS defense is becoming more complex, more expensive, and more critical for telecom availability, making hybrid, flexible architectures increasingly attractive.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)

Download Report from Github