Presenting the necessity of transitioning to automation-centric AISecOps to respond to multi-vector and sophisticated attack environments
As DDoS attacks become more complex and sophisticated due to the combination of cloud computing and large-scale botnets, the limitations of existing defense methods are becoming increasingly apparent. NetScout stated that to respond to these changes in the attack environment, it is necessary to transition to an intelligent and automated DDoS defense system based on AI and machine learning.
NetScout announced on the 5th that it participated in 'Security MegaVision 2026' held at the L Tower in Yangjae-dong, Seocho-gu, Seoul on the afternoon of February 4, 2026, and unveiled a next-generation DDoS defense strategy based on AI and machine learning (AI/ML).
At this event, Hong Jeong-pyo, Managing Director of NetScout Korea, gave a presentation on the topic of "Evolving DDoS Attacks, We Must Change the Paradigm of Defense – AI/ML-based DDoS Defense," pointing out the limitations of existing threshold-based defense methods. He explained that today's DDoS attacks are evolving beyond simple traffic surges into a multi-vector form combining volume, protocol, and application attacks.
Recently, DDoS attacks have become more sophisticated, utilizing cloud-based infrastructure and large-scale botnets for hyper-volumetric attacks, UDP carpet bombing, and C2 concealment. It is explained that as DDoS attacks become service-oriented, their accessibility and frequency have increased, establishing them as a structural risk that directly threatens an organization's business continuity.
NetScout stated that an AI and machine learning-based intelligent defense system is necessary in this environment. It explained that defense policies can be dynamically adjusted by detecting abnormal behavior through real-time traffic pattern analysis and automatically recognizing new types of attacks by having machine learning models learn from past and present data.
Furthermore, they explained that AISecOps automates the entire process—from detection and analysis to protection group creation, policy enforcement, and block verification—thereby reducing operational complexity and accelerating response speed. This is assessed to allow security personnel to be freed from repetitive operational tasks and focus on strategic response.
NetScout provides inline protection using AEDs in data centers, and a multi-layered DDoS defense architecture combining SiteLine, TMS, and Arbor Cloud in large-scale network and cloud environments. They stated that combining global threat intelligence with AI and machine learning models enables more sophisticated detection and response.
Kim Jae-wook, General Manager of NetScout Korea, stated that the key to DDoS defense lies in accuracy and automation rather than speed, and that AI and machine learning-based defense will be a turning point in security operations.















