DDoS Attack
Distributed Denial-of-Service (DDoS) Level: Beginner

A Distributed Denial-of-Service (DDoS) attack is a cyberattack in which an attacker uses many systems or devices simultaneously to send a large amount of traffic or requests to a target such as a website, server, network, or application.
The goal is usually to exhaust the target's resources, making the service slow, unavailable, or completely inaccessible to legitimate users.

How a DDoS Attack Works
A typical DDoS attack can be understood in four stages:
1. Botnet or compromised systems
Attackers control many compromised computers, servers, IoT devices, or other systems.
2. Attack traffic is generated
These systems simultaneously send packets, connections, or application requests toward the target.
3. Resources become exhausted
The target may run out of:
- Network bandwidth
- CPU
- Memory
- Connection capacity
- Application resources
4. Legitimate users are affected
Normal users experience slow responses, timeouts, or complete service unavailability.
Major Types of DDoS Attacks
1. Volumetric Attacks
Attempt to consume the target's available network bandwidth with large amounts of traffic.
2. Protocol Attacks
Exploit weaknesses or limitations in network and transport protocols to exhaust network infrastructure or connection resources.
3. Application-Layer Attacks
Target applications such as websites and APIs by generating large numbers of seemingly legitimate requests.
Why DDoS Attacks Are Dangerous
DDoS attacks can cause:
- Website or application downtime
- Business disruption
- Financial losses
- Customer dissatisfaction
- Increased infrastructure costs
- Reputational damage
DDoS attacks can also be used as a distraction, allowing attackers to conduct another malicious activity while security teams focus on the availability incident.
How Organizations Defend Against DDoS
Common defensive measures include:
- DDoS protection services
- Traffic filtering and rate limiting
- Web Application Firewalls (WAF)
- CDN and distributed infrastructure
- Network monitoring
- Traffic baselining and anomaly detection
- Load balancing
- Incident response procedures
Key Takeaway
DDoS is fundamentally an availability attack. Instead of necessarily trying to steal or modify information, the attacker attempts to make a service unavailable by overwhelming the resources required to serve legitimate users.
In simple terms:
Many sources → Massive traffic/requests → Resource exhaustion → Service disruption
Latest posts
3 entries, most recent posts.
Understanding Network Traffic During an Investigation
Level: Intermediate

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Category: Phishing / Artificial Intelligence

Citrix patches NetScaler SAML zero-day exploited in attacks
Severity: High CVSS: 8.7 Affected Products: Citrix NetScaler ADC & NetScaler Gateway Attack Type: Denial of Service / Possible Remote Code Execution

