Arbor Data-Sharing Program

NETSCOUT Arbor DDoS Solutions help Service Providers and Enterprises stay ahead of advanced DDoS attacks and emerging cyber threats that threaten availability, degrade performance, and drain critical resources across the Internet.

Every Arbor solution is strengthened by the global visibility and threat intelligence delivered through the NETSCOUT ATLAS‚ collection platform, along with expert analysis from the NETSCOUT ASERT team, an elite group of engineers and researchers specializing in information security. Together, they deliver actionable insight into the threats your customers face, helping you move faster than threat actors can adapt.

While ASERT conducts deep internal research and analysis, Arbor's threat intelligence gets even more valuable through community-driven learning. Through Arbor's Data-Sharing program, customers share information about attacks and methodologies they observe in real-world conditions. This input is analyzed by NETSCOUT and the ASERT team and translated back into improved protections for the broader community. Customers control what is shared through options provided by their products, enabling faster, more scalable response without exposing unnecessary identifying information.

Powered by Global Threat Intelliegnce

FAQs

Why should I participate?

DDoS attack methods can spread globally in days. A new technique or source seen on one side of the world can appear elsewhere almost immediately. The most effective defense is collective, enabled by trusted, automated data-sharing-so threats are shared, detected, and mitigated with speed and at Internet scale.

What information is being shared?

NETSCOUT Arbor Edge Defense (AED) Customers

Arbor Edge Defense Data-Sharing participants provide feedback via the ATLAS Intelligence Feed. Arbor Edge Defense shares statistics on traffic that matches the ATLAS Intelligence Feed policies, high-level threat data only, without including information that identifies your organization (such as IP addresses or payload data). This feedback validates ATLAS threat protection intelligence and continuously strengthens ATLAS Intelligence Feed policy quality. For example, NETSCOUT uses feedback data to refine confidence values for ATLAS Intelligence Feed policies.

Arbor Edge Defense may also provide performance and configuration details. You may also optionally share the location of your organization and your industry to further improve research and analysis.

Data elements may include:

  • Byte and packet volumes
  • Volumes of traffic blocked or dropped
  • Policies and blacklists triggered
  • Source IP of attacks and associated volumes (depending on your sharing settings)
  • Arbor Edge Defense system health (CPU & memory consumption)
  • Hosts blocked
  • Number of connections
  • WebCrawler's encountered
     

Arbor Sightline and Arbor Threat Mitigation System Customers

Arbor Sightline and Arbor Threat Mitigation System participants share anonymized information to help improve community defenses, including:

  • Anonymous Arbor Sightline deployment size
  • Anonymized Arbor Sightline web UI usage statistics
  • Anonymized Arbor Threat Mitigation System mitigation setting values

Arbor Sightline also shares the following data with NETSCOUT:

  • Medium and high-severity DDoS alerts
  • Top TCP/UDP applications, protocols, and packet lengths
  • Anonymous overall network traffic (incoming and outgoing)

You may also choose to provide your organization's location and your provider type.
Optional IP anonymization: If you share IP addresses associated with DDoS alerts, you choose the anonymization level:

  • Mask internal IP addresses, or
  • Convert them to cryptographic hash values

If IP addresses are shared without anonymization, NETSCOUT can correlate data across ATLAS participants and other sources to help identify DDoS attack patterns. NETSCOUT cannot associate the shared IP data with the identity of any natural person.

How is the information transmitted?

Shared data is transmitted over an HTTPS encrypted channel. To reduce risk of misuse, NETSCOUT anonymizes and/or aggregates shared information and does not identify the customer to third parties as the source of the data.

How does NETSCOUT use this information?

NETSCOUT may use shared data for research and business purposes, including:

  • Research and analysis of network traffic and threat data
  • Deriving statistical/usage data related to software and service functionality
  • Improving software and services
  • Developing and providing other NETSCOUT products and services
  • Sharing data with affiliates and business partners

NETSCOUT may also combine or incorporate shared data with other information derived from licensees, users, or other sources. NETSCOUT reserves the right to use shared data across relevant NETSCOUT programs and technologies, including ATLAS, Arbor Edge Defense, Arbor Enterprise Manager, Arbor Sightline, and the Arbor Threat Mitigation System.

To the extent applicable, shared data is governed by NETSCOUT’s Privacy Policy and its GDPR compliance program.