Join our Newsletter — 33% off our NHI Course

DDoS and sustained DNS pressure: what security teams need now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Sustained internet demand, higher DNS noise, and longer, more automated DDoS activity defined the end of 2025, with attackers increasingly using prolonged pressure rather than brief spikes to stress infrastructure, according to DigiCert. That shifts resilience from burst handling to continuous operations across DNS, network, and application layers.

Editorial analysis by NHI Mgmt Group, based on content published by DigiCert: “DigiCert Releases Q4 2025 RADAR Brief”.

Key questions

Q: How should security teams prepare for sustained DNS and DDoS pressure?

A: Teams should plan for prolonged pressure, not just peak traffic.

Q: Why do sustained DNS failures and NXDOMAIN noise matter to availability?

A: They matter because they show the environment is under constant pressure, not just occasional load.

Q: What are the signs that low-noise application probing is becoming a real risk?

A: Look for repeated request variation, unexpected cookie manipulation, steady automated activity, and control behaviour that changes under small input differences.

Practitioner guidance

  • Harden DNS endurance testing Stress-test authoritative and recursive DNS paths under sustained query volume, repeated NXDOMAIN noise, and mixed automated traffic so the team can see when degradation starts.
  • Validate multiday DDoS response coverage Exercise the full mitigation chain across scrubbing, rate limiting, escalation, and vendor coordination for attacks that last longer than a single shift.
  • Tune application controls for quiet probing Review cookie handling, request variation tolerance, and anomaly thresholds so low-noise automated testing is surfaced before it becomes exploitation.

Bottom line: DigiCert's Q4 brief shows that sustained traffic growth and longer DDoS campaigns are replacing the old burst-and-recover model.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Sustained pressure is now the operating condition, not the exception: The article shows that DNS demand and malicious traffic both remained elevated for long stretches, which collapses the old assumption that teams can recover between spikes. That matters because resilience programmes built around burst handling can look healthy in calm windows while failing under continuous load. Practitioners should treat endurance as a control property, not a capacity afterthought.

A question worth separating out:

Q: When should organisations treat internet traffic growth as a resilience governance issue?

A: When demand stays elevated for weeks, the problem is no longer just capacity planning. It becomes governance over how DNS, network, and application teams coordinate under sustained pressure, because availability now depends on joined-up ownership rather than isolated controls.

👉 Read our full editorial: Q4 traffic and DDoS pressure are reshaping internet resilience


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.