Network Security

Five ways security teams can combat hyper-volumetric DDoS attacks

Cybercriminals using botnets to perform large-scale DDoS attacks on websites

COMMENTARY: Hyper-volumetric attacks are the new DDoS nightmare, flooding networks with an unprecedented level of requests. Just a few weeks ago, reports came out that a new record was set on the heels of an Aisuru attack that peaked at 29.7 terabits-per-second (Tbps).

Another one of last year’s larger assaults spiked at 7.3 Tbps / 4.8 Bpps, effectively barraging systems with 37.4 terabytes of malicious data within 45 seconds.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

These are hardly one-offs. Hyper-volumetric attacks have accelerated massively in volume, speed, and ferocity, and they are getting worse. The hyper-volumetric attacks of 2025 used AI to adapt to the target’s defenses, threatening networks with cunning and intelligence as well as brute force. In the face of such attacks, traditional defenses aren’t just inadequate, they’re almost invisible.

Security teams need to overhaul their DDoS attack prevention strategies and solutions to make them fit for purpose in the age of hyper-volumetric bot attacks – and they need to do it fast.

Here are five tips to stand resilient against the ongoing tsunami of DDoS attacks:

  • Move fast – and move to the cloud: Hyper-volumetric DDoS attacks are intense, but short-lived. Data from Nokia shows that 78% of attacks last under five minutes, and 37% under two minutes. That’s not a blessing – if a company’s protections can’t react in less than a minute, they’ll be too late to be much help. The solution: move defenses to the cloud. Cloud-based DDoS protection can scale more easily to absorb the impact of multiple terabytes, respond instantly, and deliver always-on global coverage. In comparison, on-premise protections are often   constrained by uplink size and hardware capacity, are slow to respond, and run expensive if provisioned for always-on availability, while coverage and resilience are limited.
  • Cover all vectors: Hyper-volumetric attacks can cover a wide area. Attackers take advantage of AI to build blended multi-target, multi-vector campaigns with carefully considered sequencing, frequently hitting multiple hosts simultaneously with two or more attack vectors. Recent attacks target both the network layer (L3-L4) and the application layer (L7). Traditional protections were typically designed to cover a single vector. Update them to recognize adaptive, coordinated, multi-vector attacks, even when individual attacks stay below threat thresholds. AI and ML are vital for identifying the patterns of complex hyper-volumetric DDoS attacks.
  • Prepare for anything: Hyper-volumetric DDoS attacks cleverly make use of trusted IPs and residential proxies. Traditional firewalls don’t block them because they are part of the regular network traffic – until they are used as players in the DDoS game. Teams need AI and ML to monitor “clean” household traffic for anomalous behaviors that could be the precursor to a DDoS attack, and react fast enough when the spike suddenly occurs. At the same time, “regular” DDoS attacks are continuing. Security teams need to plan enough bandwidth and provisioning to accommodate slower attacks like Slowloris as well as sudden spikes. This requires always-on defenses, because the team can’t expect to have enough time to trigger an on-demand system.
  • Close IoT backdoors: Closing down IoT wormholes is an old tune that’s depressingly evergreen. New generations of Mirai-family DDoS attacks still target run-of-the-mill home and office devices that were never secured properly. Nokia research from February 2025 shows over 30,000 compromised IoT devices, enough to support 30 Tbps with spikes approaching 15 Gpps (million packets per second) and a time-to-peak of one to three minutes. It’s beyond time for organizations to get a grip on their IoT supply chains. One team needs to take responsibility for ensuring all devices are secured, updated on time, and removed entirely from the ecosystem when they’re retired.
  • Don’t bring a knife to a gunfight: We have to come to grips with the arrival of AI-powered automation with these DDoS attacks. Instead of manual orchestration, attackers are using intelligent systems that can test network protections and monitor and adapt to network defenses. They’ll take steps like switching vectors and requeuing bot traffic to spot chinks in the coverage. In this environment, trying to manage DDoS protection manually is like trying to hold back a tsunami with an umbrella. Once again, security teams need to harness AI and ML to build automated, adaptive, self-defending architecture, fed by real-time intelligence.

Holding up the barriers against today’s overwhelmingly large hyper-volumetric DDoS attacks takes a lot of work, but it’s definitely doable. Security teams need to prepare for high-volume, short-lived, multi-vector dynamic attacks by speeding up response times, ensuring scalability, and taking advantage of AI.

David Balaban, owner, Privacy-PC

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds