What’s New in NFA v26.03: Automated Threat Mitigation, Advanced Filtering, and Entra SSO
Network Anomaly and DDoS Detection with FlowSpec Mitigation
NFA now supports network threat and DDoS detection using multiple attack detection algorithms. Users can configure anomaly detection rules, review current anomaly feeds and historical activity, and exclude selected IP addresses through a whitelist. Detected threats can be addressed using FlowSpec mitigation actions for traffic dropping, rate limiting, and IPv4/IPv6 traffic redirection. NFA supports detection of the following anomaly types: DNS, NTP, SNMP, and memcached amplification attacks; SSH, UDP, TCP SYN, TCP ACK, and TCP ACK PUSH floods; HTTP/HTTPS, smurf, CLDAP, and SSDP flood attacks. Read the documentation →

Noction Flow Analyzer v26.03 introduces Network Anomaly and DDoS detection, automated FlowSpec mitigation options, Microsoft Entra single sign-on, and additional controls for sharing and analyzing network data. Continue reading

