What is a DDoS attack? How it works, the three types and what you see when you are hit
What is a DDoS attack? A distributed denial of service attack makes many devices spread across the internet flood one target at once, exhausting its bandwidth, connections or CPU so real users cannot get in. It steals no data and breaks into nothing: it attacks availability.
What is a DDoS attack? DDoS stands for distributed denial of service: an attacker uses a large number of devices spread across many different networks to send traffic or requests to the same target at the same time, exhausting its uplink bandwidth, connection tables or CPU until legitimate users are crowded out. It is not the same as stealing an account or breaking into a server. A DDoS attack never needs to get inside your system and takes no data; its only goal is to stop the service from working.
What “distributed” and “denial of service” mean
The name has two halves:
- Denial of service is the outcome. A server, network or application has its resources used up and can no longer serve real users. The resource can be bandwidth, a firewall’s connection table, a server’s CPU and memory, or a web application’s worker processes and database connections.
- Distributed is the method. The attack traffic comes from hundreds, thousands or more sources. Most are compromised devices under the attacker’s control, collectively called a botnet; others are legitimate public services that the attacker abuses.
Being distributed has two direct consequences, and they are the reason DDoS is hard to defend against:
- Sheer volume. A single device has limited upload bandwidth, but tens of thousands of them together can far exceed the inbound capacity of an entire data center.
- Too many sources to block. There are thousands of sources, and in many network-layer attacks the source addresses are spoofed, so blocking IPs one by one on the server achieves nothing.
Is a DDoS attack hacking or phishing?
No. DDoS belongs to a different class from phishing, malware and intrusions. The target, the method and the defense are all different:
| Attack | What it targets | Needs access to your systems? | Typical result | Main defenses |
|---|---|---|---|---|
| DDoS | Availability | No | Site unreachable, players disconnected, congested links | Spare bandwidth, scrubbing, DDoS-protected IPs, rate limiting |
| Phishing | People’s judgment | No; it tricks users into handing over their credentials | Stolen accounts, financial loss | Security awareness training, two-factor authentication, email filtering |
| Malware or intrusion | Control of the system | Yes | Data theft, server taken over | Patching, least privilege, host security, auditing |
| Ransomware | Availability of data | Yes | Files encrypted and a ransom demanded | Backups, isolation, patching |
Security risk is usually measured against three properties: confidentiality, integrity and availability, often called the CIA triad. Phishing and intrusions mainly threaten confidentiality and integrity; DDoS targets availability only.
The two classes are still connected. Most devices that send DDoS traffic were first compromised through malware or weak passwords and turned into bots. Some attackers also use a DDoS to create chaos and then try to break in while the operations team is busy fighting it. “It is not an intrusion” does not mean you can stop watching the security logs during an attack.
The three types of DDoS attack, with one example each
DDoS attacks are generally grouped into three types by the layer they hit. Here is one example of each to show the difference; the mechanics of each type deserve a guide of their own.
| Type | Resource exhausted | Example | In one sentence |
|---|---|---|---|
| Volumetric | Link bandwidth | UDP reflection/amplification | Abuses open public services on the internet, such as DNS resolvers, to bounce large volumes of responses at the target and fill its inbound bandwidth |
| Protocol | Connection tables, protocol stack | SYN flood | Opens huge numbers of TCP handshakes that never complete, filling the half-open connection queue of the server or firewall |
| Application layer (layer 7) | Application workers, CPU, database | HTTP flood | Sends large numbers of normal-looking web requests until the web service runs out of capacity |
Each type is also measured in a different unit: volumetric attacks in bps (bits per second), protocol attacks in pps (packets per second), and application-layer attacks in rps (requests per second). That is why an attack of “only a few tens of Mbps” can still take a website down.
What a DDoS attack looks like on the server
The first thing operators usually notice is trouble on the server itself, and the symptoms differ clearly by attack type:
| What you see | Most likely | How to confirm |
|---|---|---|
| Inbound bandwidth pinned at the port limit (for example a 1 Gbps port holding above 900 Mbps), heavy ping loss, SSH will not connect | Volumetric | Switch port traffic graph; sar -n DEV 1 and watch rxkB/s |
| Bandwidth is not high, but half-open connections spike and new connections cannot be established | Protocol | ss -tan state syn-recv | wc -l |
| The kernel log keeps reporting that the connection tracking table is full | Protocol, or a flood of small packets | dmesg | grep -i "table full" |
| Bandwidth and SSH are fine, but the website is slow or returns 502/504, and CPU is high | Application layer | Web access logs and the state of application processes |
| Traffic suddenly drops from very high to near zero; nothing is reachable from the internet, but the internal network works | The public IP may have been blackholed by the data center or its upstream | Contact your data center |
The last case often confuses people. From the server it looks as if the attack has stopped, but in fact the data center has dropped all traffic to that IP upstream to protect its shared uplinks, and legitimate visitors are dropped along with the attack.
There is also the opposite case: outbound bandwidth suddenly saturates while nothing has changed in the business. That usually means the server itself has been compromised and is being used as a bot to attack others. Treat it as an intrusion, not as an attack on you.
What the data center network sees
For a hosting provider or data center network, an attack usually reaches well beyond the machine being hit:
- Access port: the attacked server’s switch port is saturated inbound, and utilization on that switch’s uplink jumps with it;
- Uplinks and edge: when attack traffic exceeds the capacity of the data center’s edge or of a particular carrier link, other customers behind the same edge also see higher latency and packet loss;
- Flow data: in NetFlow or sFlow samples, a large number of sources point at a single destination IP, and the protocol and port distribution is unusually concentrated;
- Mitigation: scrubbing kicks in, or once a threshold is crossed the data center or upstream carrier blackholes the IP;
- Tickets and complaints: the customer under attack and the neighbors caught in the collateral damage report problems at the same time, and support can easily mistake it for a carrier outage.
So in a data center, a DDoS attack is never just one server’s problem. The response has to account for both the customer under attack and everyone else sharing the same links.
DDoS or something else? Telling an attack apart from other outages
A site that will not load is not necessarily under attack. These situations are often confused:
| Situation | Bandwidth | Connections and CPU | Scope | Key clue |
|---|---|---|---|---|
| Volumetric DDoS | Inbound saturated | The server may not be busy | Everything on the same link may suffer | Scattered sources, concentrated protocols |
| Carrier or upstream failure | Drops or falls to zero | Normal | A whole link or the whole data center | Many customers affected at once; traceroute stops at an upstream hop |
| Software bug or slow queries | Normal | CPU high | One application | No unusual sources; started after a release or change |
| Legitimate traffic peak | Rises | Rises | One application | A clear cause such as a launch or promotion; normal visitor distribution |
| Compromised server sending attacks | Outbound saturated | Unknown processes using resources | One server and its switch port | Abnormal outbound traffic with no change in the business |
Handling DDoS in a data center management system
Beyond scrubbing and blackholing, two routine tasks tie DDoS directly to the data center management system. The first is the billing basis. Attack traffic is inbound, so if a traffic pool meters inbound or total traffic, the attack counts toward the customer’s usage. Traffic and 95th percentile billing in Toplink DCIM can meter outbound, inbound, total or peak traffic; choose the basis that matches the contract when the customer signs, and there is less to dispute after an attack. The second is outbound anomalies. When a colocated server is compromised and starts sending attack traffic, automatic bandwidth limiting throttles its switch port to a set rate based on average bandwidth over the last few minutes, then lifts the limit automatically once traffic stays low, so one machine does not drag down an entire uplink.
FAQ
What is the difference between DoS and DDoS?
A DoS attack comes from a single source. One machine has limited bandwidth and packet rate, so once you find the source you can block it. A DDoS attack comes from thousands of devices at once, adds up to far more traffic, and cannot be stopped by blocking a handful of IPs.
Is a DDoS attack illegal?
Yes. Most countries treat it as a computer crime, for example under the Computer Fraud and Abuse Act in the US and the Computer Misuse Act in the UK. Buying an attack from a service sold as 'stress testing' and pointing it at someone else is illegal too. If you are attacked, keep traffic graphs, logs and any extortion messages, and report it to law enforcement.
Can a small website or game server get hit by a DDoS attack?
Yes. Launching a small attack takes little money or skill, so personal sites and small game servers are attacked too, often over a dispute or as extortion. What differs is the size: the less the attacker spends, the more likely the data center can scrub or contain it.