Volumetric DDoS attacks against the RAN control plane threaten network accessibility and can trigger costly manual intervention. This custom workflow automates detection and response by deploying lightweight AI agents at the edge that analyze traffic flows in real time. When an attack pattern is identified, these agents coordinate with core DDoS scrubbing centers and automatically apply rate-limiting or filtering rules at the RAN node. The architecture integrates with RAN Intelligent Controllers (RICs) and security information and event management (SIEM) systems, transforming a reactive security process into a closed-loop, autonomous defense system that reduces mean time to contain (MTTC) and protects revenue.




