7–9 Apr 2026
Jaarbeurs Supernova
Europe/Amsterdam timezone

Security Days Organisational Committee

Session

DDoS Mitigation

8 Apr 2026, 11:00
Mission 1 Room (Jaarbeurs Supernova)

Mission 1 Room

Jaarbeurs Supernova

Utrecht, Netherlands

Conveners

DDoS Mitigation

  • Eugene Brin (DFN-CERT)

Description

DDoS attacks are a constant reality for research and education networks. The attacks keep getting bigger, the infrastructure behind them keeps evolving, and the threat actors just won't chill. This track brings together security teams, network engineers, and researchers dealing with this on the front lines.

We'll look at real attack data and what it tells us about current traffic patterns. We'll cover automated approaches for hunting threat actor infrastructure. And we'll dig into the surprising sources powering modern attacks. From IoT botnets to cheap Android TV boxes turned into DDoS machines.

Three talks, real experiences, practical takeaways. This is about understanding the current landscape, sharing what works and staying ahead of the next wave. If you're defending networks against DDoS, this track is for you.

Presentation materials

There are no materials yet.

  1. Scott Campbell (GEANT)
    08/04/2026, 11:00
    Presentations 1
    Single Presentation (25 min)

    Most sites with a mature DDoS defense strategy have a number of historical assumptions baked into how traffic dynamics happen in and around the larger NREN community. These assumptions are necessary for the development of mental models and understanding for security teams, but it is important to periodically walk through real attack data and make sure that these critical assumptions still...

    Go to contribution page
  2. Floris Dankaart-Chang (Fox-IT)
    08/04/2026, 11:30
    Presentations 1
    Single Presentation (25 min)

    This session looks at how modern security programmes combine deception techniques (such as honeypots and canaries), using practical examples from the education sector.

    Go to contribution page
  3. Jérôme Meyer (Nokia)
    08/04/2026, 12:00
    Presentations 1
    Single Presentation (25 min)

    In October 2025, Nokia Deepfield observed a 33 terabits-per-second DDoS attack against a gaming provider—a volume exceeding the total capacity of many national internet backbones. Terabit-scale attacks are now a daily occurrence, with 78% of campaigns concluding in under five minutes. The era of IoT botnets has given way to something far more insidious: residential proxy networks commanding an...

    Go to contribution page
Building timetable...