9 challenges of DDoS mitigation efforts

Dr Emad Fahmy, Director of Systems Engineering for the Middle East at NETSCOUT, explores overcoming common hurdles to maximise distributed denial-of-service (DDoS) protection.

In the first half of 2025, NETSCOUT’s Threat Intelligence report observed more than eight million DDoS attacks worldwide, including 3.2 million in EMEA. Within this, the Middle East stood out as one of the hardest-hit regions, with Saudi Arabia, Egypt and the United Arab Emirates experiencing hundreds of thousands of attacks targeting critical industries.

Cyber adversaries are getting more sophisticated. With powerful malware, ransomware and other cyberattacks continually getting more evasive and malicious, cybersecurity teams need to stay alert. Another type of cyberattack that is increasing in complexity is the DDoS attack. These attacks are getting larger, smarter and more destructive.

The Threat Intelligence Report illustrates the sheer scale of this problem — showing where and how often attacks occur. But scale is only half the story. To understand why defending against DDoS remains so difficult, we looked to IDC’s study, which identifies the top challenges organisations face when mitigating these attacks.

  1. DDoS as a tactic to obscure or enhance other data theft/intrusion/extortion attempts (41 per cent of respondents)
    In the Middle East, where critical infrastructure like telecom, finance and energy are frequent targets, a large-scale attack can divert attention at the exact moment attackers attempt to exfiltrate sensitive data or compromise systems.

    DDoS attacks are often used as a smoke screen to distract teams from other nefarious activities. While the network and security teams are busy fighting to get key services and applications back online during a DDoS attack, adversaries can exploit other areas of the network to gain access and carry out stages of a full-scale cyberattack or extract data.

  1. Security gaps/blind spots due to complexity of environment (39 per cent)
    Scalability is key to a holistic DDoS protection solution. If you cannot see into every area of the network and application layers, then there are places there that attackers can exploit. Regional telecom operators in Saudi Arabia and the UAE, which recorded some of the highest-volume and longest-running DDoS attacks in the region, illustrate the challenge of maintaining oversight across massive, interconnected environments.
  2. High frequency of attacks results in excessive costs for mitigation (37 per cent)
    Most organisations get their DDoS attack protection from a managed security services provider. Many of these services charge their customers an attack mitigation fee that is applied per attack. The more attacks, the higher the costs. With Saudi Arabia alone recording over 270,000 attacks — roughly one every 90 seconds — organisations face mounting costs from both incident response and downtime. This frequency makes cost efficiency and scalable protection especially critical.
  3. Stealthy application layer attacks that avoid triggering detections (34 per cent)
    Application layer attacks, also known as layer 7 DDoS attacks, are often smaller in volume, but are equally or more destructive than their large-scale volumetric relatives. Not having dedicated DDoS protection solutions that monitor these smaller-volume attacks can be detrimental to application availability, because many ISP-provided or other solutions function based on thresholds, and if an attack is smaller in size it may not trigger mitigation. Enabling protection at the application layer that looks for anomalies and other telltale signs of a DDoS attack customised to your environment can help prevent these devastating attacks from being successful. In Egypt, where attacks against education and data services lasted more than three hours, smaller application-layer campaigns have proven just as capable of degrading services as their larger volumetric counterparts.
  4. Large-scale volumetric attacks overwhelm existing defences (30 per cent)
    Saudi Arabia recorded a one terabit-per-second strike — the largest in the region to date — capable of overwhelming defences and cutting off connectivity nationwide. In the UAE, peak attacks exceeded 430 Gbps, underscoring the escalating scale. Adequate scrubbing and mitigation capacity cannot be undervalued as volumetric attacks continue to get larger and larger.
  5. Widely distributed attacks targeting a broad range of IP addresses to avoid detection, such as a carpet-bombing attack (29 per cent)
    Carpet-bombing DDoS attacks can be devastating to large enterprise and service provider networks. Having holistic, adaptive DDoS defences that can block attacks as they change targets within your IP range can automatically detect and mitigate these attacks should DDoS misuse traffic be detected across the entire network, not just on a per-host basis. With the Middle East’s heavy reliance on satellite, cloud, and telecom networks, this technique poses a growing risk to regional operators tasked with defending vast IP ranges.
  1. Multi-vector attacks complicate detection and mitigation efforts (25 per cent)
    Whether the different attack vectors target a host or network simultaneously or change from one to another as they are blocked, a solution that can handle the full gambit of DDoS attack vectors and evolves as the attack matures and gets smarter is a necessity. In Saudi Arabia, some campaigns combined as many as 24 different attack methods simultaneously. This level of complexity makes it harder for defenders to distinguish attack traffic from legitimate use and forces them to adapt in real time.
  1. Specific protocols require specialised protection, such as DNS (22 per cent)
    Domain Name System (DNS) DDoS protection is imperative to ensuring DNS water torture/NXDOMAIN attacks are not successful. DNS disruptions pose significant risks in the UAE’s finance and cloud sectors
  2. Short-burst/rapid-fire attacks that exploit long detection times (22 per cent)
    Some DDoS protection solutions have duration thresholds for mitigating attacks. This can lead to successful short-burst attacks — or worse, a series of successful rapid-fire attacks that connect to render key services and applications unavailable for extended periods of time. This trend is increasingly observed in the Middle East, where shorter attacks are often layered alongside prolonged strikes — as seen in Egypt’s record three-hour attack that was paired with a series of smaller bursts.

The Middle East is experiencing some of the most challenging conditions anywhere in the world when it comes to DDoS defence. With Saudi Arabia, Egypt, and the UAE all facing record volumes, longer durations, and increasingly complex attack techniques in 2025, the region highlights why defending against DDoS is no longer a purely technical issue but a strategic priority for business and national resilience.

This feature appeared in issue 146 of Security Middle East magazine. 

Tags:
No Comments

Sorry, the comment form is closed at this time.

1