DDoS
Distributed Denial of Service
- Pronunciation
- DEE-doss
In short
A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
What is a DDoS attack?
A denial-of-service (DoS) attack tries to make a service unusable for legitimate users by sending it more requests or data than it can handle. In a distributed denial-of-service (DDoS) attack, that traffic comes from thousands or even millions of devices at once, usually a botnet of hacked computers, routers, cameras, and other internet-connected devices. Because the traffic arrives from so many places, it can't be stopped by blocking a single IP address.
DDoS attacks target different layers. Volumetric attacks try to fill the victim's network bandwidth, protocol attacks such as SYN floods exhaust the connection capacity of servers, firewalls, and load balancers, and application-layer attacks send huge numbers of realistic-looking HTTP requests to expensive pages such as search or login. Attackers often use amplification, sending small requests with a forged source address to misconfigured public services that reply to the victim with much larger responses.
Think of a small shop suddenly packed with a crowd that has no intention of buying anything, so real customers can't get through the door. DDoS attacks are used for extortion, as a distraction during other intrusions, or to disrupt businesses, online games, and public institutions, and they are illegal in most countries.
Defending against DDoS is mostly about capacity and filtering. Common measures include serving traffic through a CDN or a dedicated DDoS mitigation service that can absorb very large floods, rate limiting and caching at the edge, firewall and web application firewall rules that drop malicious patterns, autoscaling, and a prepared incident response plan. A DDoS attack is not a data breach, since it targets availability rather than stealing data, but the resulting downtime can still be very costly.
Key takeaways
- A DDoS attack floods a target with traffic from many devices to make it unavailable.
- The traffic usually comes from a botnet of compromised computers and IoT devices.
- Attacks can target network bandwidth, protocols, or the application itself.
- Defenses include CDNs, dedicated mitigation services, rate limiting, and firewalls.
- DDoS attacks target availability; on their own, they don't steal data.
Example
# Helps against small application-layer floods; large attacks must be
# absorbed upstream by a CDN or a DDoS mitigation service
limit_req_zone $binary_remote_addr zone=per_ip:10m rate=10r/s;
limit_conn_zone $binary_remote_addr zone=conn_per_ip:10m;
server {
server_name example.com;
location / {
limit_req zone=per_ip burst=20 nodelay; # allow short bursts, reject floods
limit_conn conn_per_ip 20; # cap open connections per IP
limit_req_status 429;
proxy_pass http://app_servers;
}
}Readers ask
What is the difference between DoS and DDoS?
A DoS attack comes from a single source, so it can often be stopped by blocking that source. A DDoS attack comes from many sources at once, usually a botnet, which makes it far harder to filter and able to generate much more traffic.
Can a firewall stop a DDoS attack?
A firewall can filter some malicious traffic, but a large volumetric attack can saturate your internet connection before the traffic even reaches it. That is why large attacks are usually absorbed by CDNs or dedicated DDoS mitigation networks with far more capacity.
How can I tell if my site is under a DDoS attack?
Typical signs are a sudden, unexplained spike in traffic, many requests from unusual regions or to a single endpoint, and the site becoming slow or unreachable. Monitoring and traffic analytics help tell an attack apart from a legitimate surge, such as a product launch that goes viral.
See also
- Rate LimitingBackend & APIs, p. 37Rate limiting is a technique that caps how many requests a client can make to a server or API within a time window, protecting it from abuse and overload.
- CDNDevOps & Cloud, p. 7A CDN is a network of servers spread around the world that stores copies of website content and delivers it to each user from the nearest location.
- FirewallNetworking, p. 8A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.
- Load BalancerDevOps & Cloud, p. 34A load balancer is a server or service that spreads incoming traffic across several backend servers so no single one is overloaded and the app stays available.
- BandwidthNetworking, p. 2Bandwidth is the maximum amount of data a network connection can carry per second, usually measured in megabits or gigabits per second (Mbps or Gbps).
- TCPNetworking, p. 30TCP is a core internet protocol that delivers data between two programs reliably and in order, by opening a connection and resending anything that gets lost.
Spotted a mistake or something missing on this page?Suggest an edit