A distributed denial of service (DDoS) attack tries to make a website, application, network or internet connection unavailable by flooding it with more traffic or requests than it can handle. The traffic comes from many sources at once, often thousands of hijacked computers, servers and internet-connected devices, which makes it hard to block simply by filtering a few addresses. DDoS mitigation is the set of services and techniques that absorb or filter that traffic so legitimate users can still get through.
At a glance
- DDoS attacks target availability: they aim to slow down or take down a service, not to steal data.
- Attacks range from raw floods that fill an internet connection to smaller, targeted requests that exhaust an application.
- Large attacks usually have to be stopped upstream, by the network provider or a cloud scrubbing service, before they reach your site.
- Mitigation can run all the time (always-on) or switch on when an attack is detected (on-demand); on-demand can leave a delay before protection engages.
What problem it solves
For a business, a DDoS attack means customers cannot reach the website, the ordering system or the login portal, and sometimes staff cannot reach the internet or cloud applications either. Even a few hours of outage can mean lost sales, missed service commitments and support calls. Some attackers pair the flood with a ransom demand to stop it.
The defensive challenge is that the attack often arrives faster and larger than anything a single site’s equipment can handle. A dedicated internet access circuit has a fixed capacity, and an attack bigger than that capacity fills the pipe before your firewall can do anything. DDoS mitigation addresses this by moving the filtering to networks with far more capacity than any one customer connection.
How it works
Volumetric attacks try to use up bandwidth by sending huge amounts of traffic, often by tricking misconfigured servers into sending large replies to the victim (amplification).
Protocol attacks exhaust the connection-tracking resources of firewalls, load balancers or servers with malformed or half-open connections.
Application-layer attacks send requests that look legitimate, such as page loads, searches or login attempts, in numbers that overwhelm the application. They need far less traffic and are harder to tell apart from real users, which is where bot mitigation techniques overlap.
Mitigation approaches include:
- Provider-based protection from your IP transit or internet provider, which filters attack traffic in its network before it reaches your circuit. Some providers offer only remotely triggered blackholing, which drops all traffic to the targeted address and stops the attack by taking the target offline.
- Cloud scrubbing services that take over routing for your network or address range during an attack (or all the time), filter the traffic and pass clean traffic back.
- Proxy-based protection for websites and APIs, where a content delivery network (CDN) or web application and API protection (WAAP) service sits in front of the application and absorbs attacks at its edge.
- DNS protection, since Domain Name System (DNS) services are themselves a common target; a resilient DNS provider keeps your domain resolvable during an attack.
When it matters for buyers
- When revenue or operations depend on an online service. E-commerce, customer portals, SaaS products and remote access gateways are common targets.
- When ordering or renewing internet circuits. Ask what DDoS protection the provider includes and what it costs to add.
- When you have already been hit. Many companies buy mitigation after their first attack; arranging it in advance avoids a scramble.
- When customers or contracts require uptime. Service commitments to your customers are hard to meet without a plan for attacks.
Our DDoS mitigation overview compares provider, cloud and proxy-based options.
Questions to ask vendors
- Is protection always-on or on-demand, and how long does it take to engage when an attack starts?
- Which attack types are covered: volumetric, protocol, application-layer?
- Is there a cap on attack size or a limit on the number of attacks per month, and what happens beyond it?
- Do you protect a whole network or address range, or only specific websites and applications?
- Will you ever blackhole our traffic, and under what conditions?
- What does mitigation add in latency, and how is clean traffic returned to us?
- Are there surge or overage charges during an attack?
- What reporting do we get during and after an attack?
How it differs from a denial-of-service (DoS) attack
A denial-of-service (DoS) attack has the same goal, making a service unavailable, but comes from a single source or a small number of sources. That makes it easier to identify and block by address. A distributed attack spreads the traffic across many sources, often a botnet, so it can reach much larger volumes and cannot be stopped simply by blocking a handful of addresses. DDoS mitigation and DDoS protection are not other names for the attack; they are the defensive services described above.
