What Is DDoS (Distributed Denial of Service)?

Also called: DDoS attack

Related problems: Website or customer portal knocked offline by a flood of traffic; Internet connection saturated during an attack; Not sure whether our ISP protects us from DDoS; Customers asking how we keep online services available

A distributed denial of service (DDoS) attack tries to make a website, application, network or internet connection unavailable by flooding it with more traffic or requests than it can handle. The traffic comes from many sources at once, often thousands of hijacked computers, servers and internet-connected devices, which makes it hard to block simply by filtering a few addresses. DDoS mitigation is the set of services and techniques that absorb or filter that traffic so legitimate users can still get through.

At a glance

  • DDoS attacks target availability: they aim to slow down or take down a service, not to steal data.
  • Attacks range from raw floods that fill an internet connection to smaller, targeted requests that exhaust an application.
  • Large attacks usually have to be stopped upstream, by the network provider or a cloud scrubbing service, before they reach your site.
  • Mitigation can run all the time (always-on) or switch on when an attack is detected (on-demand); on-demand can leave a delay before protection engages.

What problem it solves

For a business, a DDoS attack means customers cannot reach the website, the ordering system or the login portal, and sometimes staff cannot reach the internet or cloud applications either. Even a few hours of outage can mean lost sales, missed service commitments and support calls. Some attackers pair the flood with a ransom demand to stop it.

The defensive challenge is that the attack often arrives faster and larger than anything a single site’s equipment can handle. A dedicated internet access circuit has a fixed capacity, and an attack bigger than that capacity fills the pipe before your firewall can do anything. DDoS mitigation addresses this by moving the filtering to networks with far more capacity than any one customer connection.

How it works

Volumetric attacks try to use up bandwidth by sending huge amounts of traffic, often by tricking misconfigured servers into sending large replies to the victim (amplification).

Protocol attacks exhaust the connection-tracking resources of firewalls, load balancers or servers with malformed or half-open connections.

Application-layer attacks send requests that look legitimate, such as page loads, searches or login attempts, in numbers that overwhelm the application. They need far less traffic and are harder to tell apart from real users, which is where bot mitigation techniques overlap.

Mitigation approaches include:

  • Provider-based protection from your IP transit or internet provider, which filters attack traffic in its network before it reaches your circuit. Some providers offer only remotely triggered blackholing, which drops all traffic to the targeted address and stops the attack by taking the target offline.
  • Cloud scrubbing services that take over routing for your network or address range during an attack (or all the time), filter the traffic and pass clean traffic back.
  • Proxy-based protection for websites and APIs, where a content delivery network (CDN) or web application and API protection (WAAP) service sits in front of the application and absorbs attacks at its edge.
  • DNS protection, since Domain Name System (DNS) services are themselves a common target; a resilient DNS provider keeps your domain resolvable during an attack.

When it matters for buyers

  • When revenue or operations depend on an online service. E-commerce, customer portals, SaaS products and remote access gateways are common targets.
  • When ordering or renewing internet circuits. Ask what DDoS protection the provider includes and what it costs to add.
  • When you have already been hit. Many companies buy mitigation after their first attack; arranging it in advance avoids a scramble.
  • When customers or contracts require uptime. Service commitments to your customers are hard to meet without a plan for attacks.

Our DDoS mitigation overview compares provider, cloud and proxy-based options.

Questions to ask vendors

  • Is protection always-on or on-demand, and how long does it take to engage when an attack starts?
  • Which attack types are covered: volumetric, protocol, application-layer?
  • Is there a cap on attack size or a limit on the number of attacks per month, and what happens beyond it?
  • Do you protect a whole network or address range, or only specific websites and applications?
  • Will you ever blackhole our traffic, and under what conditions?
  • What does mitigation add in latency, and how is clean traffic returned to us?
  • Are there surge or overage charges during an attack?
  • What reporting do we get during and after an attack?

How it differs from a denial-of-service (DoS) attack

A denial-of-service (DoS) attack has the same goal, making a service unavailable, but comes from a single source or a small number of sources. That makes it easier to identify and block by address. A distributed attack spreads the traffic across many sources, often a botnet, so it can reach much larger volumes and cannot be stopped simply by blocking a handful of addresses. DDoS mitigation and DDoS protection are not other names for the attack; they are the defensive services described above.

Frequently Asked Questions

Does my internet provider protect me from DDoS attacks?
Some do, some sell it as an add-on and some only act after an attack is already affecting their network. Basic provider protection may cover only certain attack types or sizes, or may simply drop all traffic to your address to protect other customers. Ask exactly what is included and how it is triggered.
Is a DDoS attack a data breach?
Not by itself. A DDoS attack targets availability, not data. It does not steal information on its own, though attackers sometimes use one as a distraction while attempting something else, so it is worth checking other alerts during an attack.
What is the difference between always-on and on-demand DDoS mitigation?
Always-on mitigation routes your traffic through the scrubbing service all the time, so filtering is already in place when an attack starts. On-demand mitigation diverts traffic only when an attack is detected, which can leave a delay before protection takes effect. Latency and total cost depend on routing, scrubbing design, capacity, the billing model and any attack-related fees, so compare those terms between offers rather than assuming one model is cheaper or faster.
Can a firewall stop a DDoS attack?
Only partly. A firewall can block some malicious traffic, but a large volumetric attack can fill your internet connection before traffic ever reaches the firewall, and the firewall itself can be overwhelmed. Protection against large attacks usually has to happen upstream, at the provider or a cloud scrubbing service.
Who launches DDoS attacks against mid-sized companies?
Motives include extortion, protest, competition, revenge by a former customer or employee, and disruption of a larger target that shares infrastructure with you. Attack-for-hire services make it cheap for almost anyone to launch one, so being a small company does not rule you out.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.