10 New Alert Policy Templates for Kentik Protect!
We are thrilled to drop a powerful batch of pre-configured Alert Policy Templates designed to level up your network defense, compliance posture, and threat visibility in a flash! Whether you are defending high-capacity service provider backbones, managing complex enterprise environments, or squashing aggressive DDoS vectors, we've got you covered.
Here is everything you need to know about what’s new, why it matters, and how you can tune these shiny new templates to fit your environment like a glove!
⚡ What’s New?
We’ve added 10 brand-new out-of-the-box policy templates targeting high-impact security risks, advanced carpet bombing tactics, and specialized outbound threats:
🛡️ Outbound Security & DDoS Vectors (Built for Service Providers & Complex Enterprise Networks)
Outbound threats are notoriously tricky for large-scale environments. Unmonitored outbound floods can quickly degrade upstream peering links, harm your IP reputation, or lead to costly transit overages. We’ve added dedicated templates specifically engineered for these topologies:
- DDoS: Outbound Volumetric UDP Flood
Catches internal source IPs or interface blocks generating abnormal outbound UDP traffic volumes. Crucial for service providers to spot compromised subscriber hosts or internal systems participating in outbound reflection/DDoS attacks before they disrupt transit capacity. - DDoS: Outbound TCP SYN Flood
Detects sudden spikes in outbound TCP packets with only the SYN flag set originating from your internal IP space. Protects your brand reputation by catching compromised hosts launching outbound SYN floods. - Security: Internal Vertical IP Scanning
Spots lateral movement and reconnaissance across complex networks by alerting when a single internal source IP attempts to sweep across an unusually high number of unique destination IPs. - Security: Threat Feed Compromised Hosts
Flags internal network assets actively communicating with external threat infrastructure mapped directly against Spamhaus Botnet C&C nodes and malicious hosts.
🌐 Advanced Carpet Bombing Defense
Modern DDoS attacks don't always target a single IP with massive traffic—they scatter traffic across whole subnets to bypass traditional single-target thresholds. These templates give you multi-layered coverage against distributed attacks:
- DDoS: Carpet Bombing CIDR Aggregation
Identifies horizontal carpet bombing attacks spread across broad subnets, aggregating volumetric anomalies at the /24 routing prefix level. - DDoS: Carpet Bombing Port Fragmentation
Detects fragmented, high-intensity stateless traffic (UDP, ICMP, reflection vectors) aimed at a wide array of destination IPs across a single target service port. - DDoS: Carpet Bombing Interface Impact
Acts as an essential safety net by tracking traffic anomalies distributed across an entire downstream customer or internal interface block.
🔒 Geo-Compliance & Sanction Monitoring
- Security: Embargoed Country Traffic (Tier 1)
Monitors bidirectional traffic touching comprehensively embargoed nations and disputed territories to immediately flag high-risk compliance violations. - Security: Sanctioned Country Traffic (Tier 2) & Regime-Targeted Traffic (Tier 3)
Provides granular compliance tracking for high-risk, sanctioned, or UN-embargoed jurisdictions across secondary tiers.
🎯 Why This Matters to You
- Instant Protection, Zero Setup Hassle: No need to build complex flow filters or mathematical baseline models from scratch. These templates come with industry-tested baselines and static thresholds.
- Protect Your Brand & Transit Capacity: For Service Providers and Enterprise Edge networks, catching outbound malicious floods ensures your IP space stays off global blocklists and preserves upstream provider SLAs.
- Defend Against Stealthy Distributed DDoS: By aggregating traffic across /24 subnets, service ports, and entire interface blocks, you can stop carpet bombing campaigns that traditionally slip under single-IP alert radars.
- Automated Regulatory Compliance: Maintain strict, automated compliance oversight against international sanction lists without setting up manual geo-fencing rules.
🛠️ How to Enable & Tune Policies for Your Network
By default, these templates are imported in a disabled state so you can safely review and tune them before going live.
Step 1: Enable the Template
- Head over to Alerting > Manage Alert Policies > Alert Policy Templates in the Kentik portal.
- Search for the template name (e.g., DDoS: Outbound Volumetric UDP Flood or DDoS: Carpet Bombing CIDR Aggregation).
- Then click the “Create policy from template” icon to add the alert policy to your account.
Step 2: Tailor & Tune to Your Environment
Every network has its own unique baseline. Here is how you can make these templates fit seamlessly:
Adjust Static & Baseline Thresholds:
- For high-volume service provider backbones, you can scale up static packet/bit thresholds to match your transit capacities.
- For tight enterprise environments, lower the required percentage jump above historical baselines.
Refine Traffic Filters & Boundaries:
- Ensure your network boundary tags (e.g., internal vs external, or inside vs outside) are accurately defined so outbound flood and lateral scanning policies evaluate traffic correctly.
Attach Notifications & Automated Mitigations:
- Link your team's preferred notification channels (Slack, PagerDuty, Webhooks, or Email) under the policy's Notifications section.
- For DDoS templates, attach Mitigation Associations if you want Kentik Protect to automatically trigger RTBH, BGP Flowspec, or third-party mitigation platforms upon activation