DDoS Attack definition
A DDoS (distributed denial-of-service) attack is an attempt to make a website, application or network unavailable by flooding it with traffic from many compromised devices at once. The volume or type of requests overwhelms bandwidth, servers or application resources, so legitimate users cannot connect. Mitigation relies on CDNs, scrubbing services and rate limiting.
How does a DDoS attack work?
Attackers control botnets: large networks of compromised devices such as poorly secured IoT cameras, routers and servers. On command, these devices send traffic to a target simultaneously. Because traffic comes from many sources around the world, simply blocking one IP address does not help, and the combined volume can exceed what a single data center or server can absorb. DDoS-for-hire services make such attacks cheap and easy to launch.
Some attacks use amplification, sending small requests with a forged source address to services like DNS or NTP that reply with much larger responses directed at the victim. This multiplies the attacker's bandwidth many times over. Application-layer attacks need far less traffic, because each request triggers expensive work on the server.
Types of DDoS attacks
DDoS attacks are usually grouped by which layer of the network stack they target. Large attacks often combine several types at once, shifting tactics when defenses respond, so protection needs to cover every layer rather than focusing only on raw bandwidth. The three main categories are described below.
- Volumetric attacks: flood bandwidth with massive traffic, such as UDP floods and DNS amplification.
- Protocol attacks: exhaust server or network equipment resources, such as SYN floods.
- Application-layer attacks: send seemingly legitimate HTTP requests that overload expensive pages, searches or APIs.
How to protect against DDoS attacks
The most effective protection sits in front of your infrastructure. Content delivery networks and DDoS mitigation services, such as Cloudflare, Akamai, AWS Shield with CloudFront and Google Cloud Armor, absorb volumetric attacks across their global networks and filter malicious traffic before it reaches your servers. Hiding origin server addresses so attackers cannot bypass the protection layer is just as important as the protection itself.
Application-layer attacks need smarter defenses: web application firewall rules, rate limiting per IP or user, bot detection and challenges, and caching of expensive pages. Design systems to scale automatically and to degrade gracefully, for example by disabling costly features under load. Prepare a response plan with contacts at your provider and clear steps for escalation.
Signs of a DDoS attack
Typical symptoms include a sudden spike in traffic from unusual regions or networks, many requests to a single endpoint, slow or unavailable services without an obvious internal cause, and abnormal patterns such as identical user agents. Not every spike is an attack: marketing campaigns and viral content cause legitimate surges. Good monitoring with baselines for normal traffic helps teams tell the difference quickly and respond appropriately. Logging request rates per endpoint makes this analysis much faster.
Business impact of DDoS
DDoS attacks cause lost revenue during outages, frustrated customers, missed service-level commitments and higher infrastructure costs from autoscaling under attack traffic. They are sometimes used as a distraction while other intrusions take place, or combined with extortion demands. Nexzem's cloud security team configures CDN, WAF and rate-limiting protections for client applications and tests them as part of performance and resilience reviews.