logo

Identifying potential DDoS cases based on ASN with KQL Queries

ID: cca0065b-6c1a-5593-af1e-7223b9089721

STIX ID: report--cca0065b-6c1a-5593-af1e-7223b9089721

Feed Name: Detect FYI

Date Published: 2025-06-04

Date Updated: 2026-04-19

Author: Sergio Albea

...
...

This article presents a defensive approach to identifying and mitigating DDoS activity by analyzing network telemetry with KQL, mapping RemoteIPs to ASNs, and detecting anomalies in connection patterns by ASN and country. It provides practical detection logic (e.g., low success-to-attempt ratios, sudden spikes vs. historical averages) using DeviceNetworkEvents, and recommends segmenting and routing traffic by ASN reputation to protect service performance (e.g., directing suspicious ASNs to isolated replicas via WAF or load balancers) while preserving access for trusted users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.