No more typing reviews! Try our Samantha, our new voice AI agent.

Arbor DDoS vs Neustar UltraDDoS [EOL] comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Arbor DDoS
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
57
Ranking in other categories
Distributed Denial-of-Service (DDoS) Protection (4th)
Neustar UltraDDoS [EOL]
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
1
Ranking in other categories
No ranking in other categories
 

Featured Reviews

reviewer1331304 - PeerSpot reviewer
Director Of Research And Development at a comms service provider with 11-50 employees
Automated threat intelligence and flow-based mitigation have improved our DDoS defense
A very useful feature in Arbor DDoS is its ability to send flow spec announcements to routers. For example, if it is clear that a Layer 3 or Layer 4 attack is occurring and the attack pattern is identified through source and destination IP addresses and ports, you can generate flow spec filters. These filters are transferred through BGP to border routers, which automatically build filters, mitigating the attack even at the network's boundary and preventing it from reaching the TMS. This allows the TMS to focus on other tasks. This is a highly effective feature that can mitigate huge volumetric attacks; for example, we experienced a 32-gigabit attack, and all those 32 gigabits were dropped by our border routers, not by Arbor DDoS itself. The flow spec announcement was generated by Arbor DDoS, and as far as I know, the same technology is used by Radware, but it comes under a different feature and a different license. At the time, we were told that flow spec mitigation was an additional very expensive license to purchase from Radware, while Radware included everything in one package.
JT
Manager Strategic Planning at Endurance International Group
Identifies a request that comes up multiple times, block holds that particular IP, and lets the genuine traffic pass through
Genuine traffic coming in is still getting better. While I understand that it's some sort of algorithm that is written in this scale, that algorithm can be a little bit better because sometimes while we are doing DDoS mitigation, genuine traffic does get blocked. While it is one of the greatest features it can still be improved. I would like to see a dashboard that shows you the data that is transferred from which end. It's where people start looking at abuse management. People keep questioning when the mitigation is on what service it is and how many GBs are passing through. An end user dashboard that will help you identify all of these questions and that can be visible in your entire organization is something that would make sense.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The AI capabilities and anomaly detection using machine learning modules like isolation forests and auto-encoders are the most effective in mitigating DDoS attacks."
"Arbor DDoS helps consolidate visibility on traffic and on DDOS attacks attempts, can perform direct mitigation action on the network, and has helped us achieve our network and application uptime goals."
"We found what we wanted in Arbor DDoS; it met our expectations as IT users of different types of complex environments and fit our needs."
"Without Arbor, we'd probably be around 75 to 80 percent uptime."
"Inside this product, there are many different configurations for protection, and we have one of the best experiences with it, specifically with the Atlas product."
"It has an easy-to-understand GUI...Stability-wise, I rate the solution a ten out of ten."
"I have a lot of experience with the technical support for multiple vendors (HPE, Cisco, Palo Alto Networks, Imperva, etc.) and the Arbor support is really good; usually, they respond with the workaround for your issue."
"It is fully mitigating the attacks. We've dealt with other ones where we didn't necessarily see that. The detection is very good. It's also very simple to use. Arbor is a single pane of glass, whereas with other solutions you might have a detection pane of glass and then have to go to a separate interface to deal with the mitigation. That single pane of glass makes it much simpler."
"Scalability is awesome, and they have grown two folds or three folds since we started using them, with no concerns even as we protect close to 60,000 hosted sites for business and e-commerce customers."
"In the DDoS it's difficult to validate what is a genuine request from an end user. We've started being able to do that with the logistics that they have set up. With the protection that they have provided, they are able to identify what is valid and what is not valid. We see that a person who is getting DDoS Neustar service is able to block that particular user. However, while they are doing that it doesn't affect other customers on the server."
 

Cons

"A small improvement could be a better reporting system."
"Their RESTful API is still a work-in-progress."
"An improvement to Arbor DDoS would be to make evaluation licenses and virtual machines available."
"I would also like more visibility into their bad actor feeds, their fingerprint feeds. We try to be good stewards of the internet, so if there are attacks, or bad actors within our networks, if there were an easier way for us to find them, we could stop them from doing their malicious activity, and at the same time save money."
"An issue which needs to be addressed concerns information I received of attacks on the radar and Arbor, allegedly, not taking any action."
"It could include a lot of enhancements related to AI and automation."
"The implementation should be made easier."
"If we want to see live traffic, we can see do so. But once an attack that lasts for five minutes is done, the data is no longer there. It would be an improvement if we could see recent traffic in the dashboard. We can check and download live traffic, but a past attack, with all the details, such as why it happened and how to mitigate and prevent such future attacks, would be helpful to see."
"I would like to see a dashboard that shows you the data that is transferred from which end. It's where people start looking at abuse management. People keep questioning when the mitigation is on what service it is and how many GBs are passing through. An end user dashboard that will help you identify all of these questions and that can be visible in your entire organization is something that would make sense."
"Genuine traffic coming in is still getting better because sometimes while we are doing DDoS mitigation, genuine traffic does get blocked."
 

Pricing and Cost Advice

"I believe that the price of Arbor DDoS falls under the bracket of medium to high price."
"Regarding pricing, I would rate it as average. Arbor DDoS offers good value for money with our DDoS filter device. For higher protection needs, Arbor’s CloudMeter’s DDoS mitigation or hardware devices might be more expensive, but customers who need them are usually prepared for the cost and the additional resources required."
"The price of Arbor DDoS depends on many parameters. It depends on the physical capacity of the environment, and it is not a straight-line price. It's fairly competitive in the market on the price."
"The solution's pricing is based on a licensing model that is expensive when compared to other tools."
"You need to find a way to get a good offering from Arbor by negotiating a price. That is the challenge."
"Start with a small license. Measure your bandwidth requirements."
"The price is a little high."
"I don't deal with the pricing, but it seems that you need to get basic support in order to upgrade the software and implement some patches."
Information not available
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
914,938 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Comms Service Provider
12%
Outsourcing Company
11%
Construction Company
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise14
Large Enterprise29
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
I would say if it’s an ISP that will build a scrubbing center, Netscout/Arbor is a good solution. In all other solutions, Imperva is a great choice.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Arbor DDoS?
The prices for Arbor DDoS are expensive. The licensing is subscription-based. From our sales department, they discuss that prices are very high.
Ask a question
Earn 20 points
 

Also Known As

Arbor Networks SP, Arbor Networks TMS, Arbor Cloud for ENT
Neustar UltraDDoS, UltraDDoS
 

Overview

 

Sample Customers

Xtel Communications
Choxi
Find out what your peers are saying about Radware, Cloudflare, Imperva and others in Distributed Denial-of-Service (DDoS) Protection. Updated: September 2026.
914,938 professionals have used our research since 2012.