Distributed Denial of Service (DDoS)
An attack that uses many compromised or rented systems to flood a target with traffic or requests, exhausting bandwidth, server resources or application capacity so that legitimate users cannot be served.
DDoS attacks fall into three broad types. Volumetric attacks saturate network links, often through reflection and amplification, in which small spoofed requests to open DNS, NTP or memcached servers produce much larger responses directed at the victim. Protocol attacks, such as SYN floods, exhaust connection tables in servers, firewalls and load balancers. Application-layer attacks send seemingly legitimate HTTP requests that consume processing resources and are harder to distinguish from real users.
Attack traffic usually comes from botnets of compromised computers, servers and insecure IoT devices such as cameras and routers; the Mirai botnet of 2016 showed the scale achievable with IoT devices that still used default passwords. DDoS is used for extortion, hacktivism, distraction during other intrusions and disruption of businesses or public services, and DDoS-for-hire services make attacks easy to launch.
Mitigation relies on upstream capacity that individual organisations rarely have, so cloud-based scrubbing services, content delivery networks, anycast networks and provider-level filtering are common. Rate limiting, web application firewalls and autoscaling help at the application layer. A response plan agreed in advance with internet service providers and mitigation vendors shortens the time to recovery.
Key points
- Volumetric, protocol and application-layer attacks target different resources.
- Botnets of compromised computers and IoT devices commonly generate the traffic.
- Reflection and amplification multiply attack volume.
- Mitigation usually relies on upstream scrubbing and CDN capacity.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.