Contact

What is DDoS Attack?

Definition

A DDoS (distributed denial-of-service) attack tries to make a website, server or network unavailable to legitimate users by flooding it with traffic from many devices at once. The traffic usually comes from botnets of compromised computers and IoT devices. Attacks can target bandwidth, the resources of network protocols, or the application itself, and defences are designed around those same layers.

Also known as: DDoS, distributed denial of service, denial-of-service attack, DoS attack

Comparison of an unprotected origin overwhelmed by a botnet flood and an edge network scrubbing traffic so only legitimate requests pass

From DoS to distributed

A denial-of-service attack is anything that stops legitimate users from reaching a system. When it comes from one source, blocking that source usually ends it. In a distributed attack the traffic arrives from thousands or even hundreds of thousands of addresses. As the US Cybersecurity and Infrastructure Security Agency (CISA) points out, those addresses typically belong to botnets built from poorly secured, compromised devices, IoT gear in particular. That spread makes the traffic hard to filter and the attacker hard to trace.

Three layers, three bottlenecks

TypeResource exhaustedWhere it is stopped
VolumetricLink bandwidth; the pipe fills before traffic reaches the server.Upstream, at the ISP or a high-capacity mitigation network. Nothing on the server can help.
Protocol (L3/L4)Connection state in servers, firewalls and load balancers.Edge filtering and traffic scrubbing infrastructure.
Application (L7)CPU, database, and expensive pages such as search, cart and login.WAF rules, rate limiting, caching, bot detection.

Application-layer attacks can succeed with modest traffic. A few hundred requests per second, each triggering a heavy database query, can do more damage than hours of static-file requests, and because each request looks like a normal visit they are harder to separate from real users.

Attack or popularity?

Slow pages and a rise in 503 errors and timeouts do not automatically mean an attack; a TV spot or a viral post looks similar on a dashboard. The logs tell them apart:

  • Is traffic concentrated on one URL, or spread across the site?
  • Do user agents, referrers and geography match the site's usual profile?
  • Do these visitors log in, navigate between pages and convert?

CISA also warns that a DDoS can be a distraction. Watch other systems for unusual access while the attack is under way.

Defence in layers

  • Put capacity in front. An anycast CDN or dedicated mitigation service spreads traffic across many locations and absorbs volumetric floods before they reach you.
  • Hide the origin. Allow connections to the server behind the protection network only from that network's IP ranges; otherwise attackers simply go around it.
  • Guard expensive endpoints. Apply rate limiting to login, search and form endpoints, and serve anything cacheable from cache.
  • Do not lean on autoscaling alone. Adding servers mostly converts an outage into a large bill. Put a ceiling on it.

Preparing before it happens

Write a short response plan rather than improvising mid-incident: emergency contacts at your host and mitigation provider, which settings to tighten and how, who makes the call, and how users will be informed. Threshold alerts on traffic and error rates let you notice before customers do. Walking through the plan once on a quiet day, against a realistic scenario, saves precious minutes when it counts.

Related terms

← Back to the glossary