Providing trusted research, analysis and insight in telecom security

Subscribe to receive HardenStance reports

a
M

Subscribe to receive HardenStance reports

A new home front in outbound DDoS Defence

24 Jun 2026

HardenStance first made the case that telco security operations teams should engage in the open source RDK-B and prpl home router ecosystems in a White Paper published last October. The idea may have seemed a bit ‘out there’ because as of today the core missions of RDK-B and prpl are to enable telcos to more easily monetize networking apps in the home. Their core missions are not to help telco security teams block outbound DDoS and other cyber threats spewing out of the home LAN and into their access, aggregation and core networks.

But speaking with Nokia Deepfield’s VP and General Manager, Jeff Smith, and CTO, Craig Labovitz, last week confirmed I’m not the only one thinking about what a new direction might look like here. Nokia Deepfield is one of many vendors publishing threat reports that point to the vast scale of this problem of outbound DDoS threats and the disruption it’s causing in terms of service degradations and outages in telco networks. This is basically yours and my home network, and those of our friends and families, becoming an unwitting ‘Insider Threat’ to our home broadband provider when IoT ‘things’ in our homes gets infected and enslaved into a botnet. Most of the time, we’re not even aware of it.

Telcos are suffering DDoS attacks in the tens of terabits

Using techniques like residential proxies, threat actors are able to access the legitimate IP addresses of telcos and ISPs to evade most traditional security controls that are more effective at defending against spoofed IP addresses. As recently as a couple of years ago, 5 or 6 Terabit/s DDoS attacks were the new 1 Terabit/s attacks, but they were still fairly rare. Now, Nokia reports attacks peaking at tens of Terabits/s, with more frequent daily occurrences of terabit-level attacks across telco and ISP networks. Consistent with reporting from other DDoS protection vendors, the company also reports a high percentage of very short duration attacks now – what it calls ‘3 minute tsunamis’.

So how is this relevant to the home network space and the open source prpl and RDK-B open home router ecosystems? A couple of weeks ago Nokia Deepfield announced the launch of a new ‘Genome Sheild’ DDoS protection platform. Whereas householders are unknowingly becoming an insider threat to their broadband provider, Nokia Deepfield has found a way to be an insider threat to botnets by design. One of the six threat intel feeds that drive the platform is from hundreds of devices out on the Internet that have been programmed so that they appear to more than 30 of the largest botnets as one of their own enslaved devices. Nokia Deepfield has enabled these devices with features that enable them to get past the Botnet master’s own security controls, onboard themselves, and establish a persistent presence within the botnet undetected.

So right now there are hundreds of Nokia Deepfield devices out there with privileged access to botnet Command and Control (C2) messages, which include highly dynamic changes as to which instructions enslaved devices should be taking, where from, and in what sequence. Genome Shield then uses that threat intelligence to dynamically spin up Access Control Lists (ACLs) that can block its telco and ISP customers’ edge and core routers from communicating with these botnets.

Genome Shield-informed ACLs in a home gateway?

Discussing Genome Shield DDoS protection with Jeff Smith, and Craig Labovitz, it was good to hear that the Nokia Deepfield team has been exploring the case for extending Genome Shield to the home LAN along similar lines to what I’ve been thinking about. Consistent with a layered approach to security could there, for example, be a case for telco security operations deploying Genome Shield-informed ACLs in a home gateway to complement what they have elsewhere in the network? Hence might there also be a case for turning to the prpl, and RDK-B ecosystems to embed capabilities that support that?

To be absolutely clear, Jeff and Craig emphasized that the idea of extending Genome Shield DDoS Protection to the home LAN is at a very preliminary, exploratory stage. I nevertheless came away with two reasons to be positively fired up.  I’ve been tracking Nokia Deepfield in the DDoS protection space for ten years – since Nokia acquired Deepfield. To be honest, for most of those ten years, the company’s momentum in DDoS protection has been pedestrian. With the team now citing 60 DDoS protection wins, of which 50 have been awarded in the last 18 months, these are grounds for believing a corner may have been turned. Initial deliberations on the potential for extending protections to the home LAN also show the right kind of long-term thinking about where the industry could or should go next. The DDoS protection market is crying out for more and better competition – so what’s not to like?