News

Nokia targets the new DDoS threat with network-wide Genome Shield automation

Nokia says its Deepfield Genome Shield can turn live threat intelligence into network-wide controls as residential proxy botnets make short, high-volume attacks harder to stop.

Smartphones and radio-testing equipment on an editorial desk
Product claims are checked against official documentation and clearly attributed.

Nokia has announced a new security automation system designed to help telecommunications providers respond to a DDoS landscape that is becoming faster, more distributed and harder to contain. Called Deepfield Genome Shield, the system is intended to move network protection beyond reactive traffic scrubbing and toward continuously updated controls applied across an operator’s infrastructure.

In its official announcement on 9 June 2026, Nokia said the product is aimed at telecom providers, hosting companies, internet exchange points and cloud builders. That makes it relevant to mobile services even though it is not a consumer-facing phone feature: compromised subscriber devices can become part of residential proxy botnets, while attacks against an operator’s network can affect connectivity, applications and online services at scale.

A faster DDoS problem

Nokia says the threat has changed significantly over the past year. Instead of relying only on large, easily identifiable data-center sources, attackers are increasingly using real subscriber devices and rapidly rotating IP addresses across thousands of nodes. The company estimates that residential proxy botnets now represent roughly 250 to 600 Tbps of potential attack capacity, while around 200 million devices worldwide may be compromised and available for abuse.

The practical difficulty is speed. Nokia says some attacks now arrive in bursts lasting only seconds or minutes, leaving little time for a conventional mitigation workflow that detects an incident, diverts traffic to a scrubbing service and waits for a response. AI-assisted code generation is also helping attackers adapt evasion techniques more quickly, according to the company.

For a mobile operator, the consequences can extend well beyond a single website. Network congestion or abuse of compromised customer connections can create pressure on access networks, core infrastructure and services hosted at the edge. A successful attack may not disconnect every smartphone, but it can still degrade applications, enterprise links, payment services or other systems that depend on reliable connectivity.

From intelligence to enforcement

Genome Shield is built on Nokia Deepfield Defender and combines several threat-intelligence sources. Nokia says its Secure Genome service covers more than five billion internet endpoints, while its cyber range produces current telemetry from live malware and botnet command-and-control activity. The system compiles that information into automated policies that can be enforced across the network.

The announced approach is organised around four functions. Botnet command-and-control disruption aims to block communications before compromised devices can be used to launch attacks. DDoS policers can apply proactive rate limits to suppress amplification and volumetric traffic. Custom policies allow operators to define their own rules through open APIs, while observability tools provide views of compromised devices, botnet endpoints and emerging security patterns.

The distinction between detection and enforcement is important. A threat feed is useful only if an operator can turn it into a decision at the network edge without relying on a long manual process. Nokia’s proposal is to keep protection active across the network, updating the rules as the threat picture changes rather than waiting for each attack to become a separate incident.

What operators can deploy

Nokia says Genome Shield is compatible with router-based edge mitigation and with its 7750 Defender Mitigation System for dedicated Layer 4 to Layer 7 DDoS scrubbing. The company also lists on-premises, cloud-based software-as-a-service and hybrid deployment models. The announcement does not publish consumer pricing or a general availability timetable for every capability.

Initial Genome Shield capabilities have already been introduced within Deepfield Defender and are in use by customers, according to Nokia. Additional features are expected to roll out during 2026. Reddot Technologies is identified as one of the first operators to deploy the system, with a focus on both inbound attacks and outbound traffic from compromised subscriber devices.

That outbound angle matters for mobile networks. An infected phone may be a victim rather than an attacker, but its connection can still be recruited into a proxy service or botnet. Detecting and limiting that activity at the network level could reduce harm to other networks while giving the operator a clearer way to identify affected customers and investigate the source of abnormal traffic.

What this means for smartphone users

Genome Shield is infrastructure software, so users should not expect a new setting or app on their phones. It also cannot replace basic device security: keeping the operating system and apps updated, avoiding untrusted downloads, reviewing unusual permissions and responding to an operator’s security warning remain important precautions.

The broader significance is that mobile-network security is becoming more automated and more closely tied to the behaviour of connected devices. As smartphones, home routers and other endpoints generate more traffic, operators need to protect both their own services and the wider internet from abuse originating inside subscriber networks. Nokia’s announcement presents one response to that challenge, but its real-world impact will depend on deployment quality, the accuracy of its intelligence feeds and how transparently operators handle devices identified as compromised.

For now, the announcement is best understood as a shift in defensive strategy: detect malicious infrastructure earlier, distribute controls across the network and keep them updated as attacks evolve. That is a more direct answer to short-lived, AI-assisted DDoS campaigns than relying solely on emergency mitigation after an attack is already under way.

Sources and evidence

Official source: nokia.com (opens in a new tab)