Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is DDoS?

DefinitionDDoS (Distributed Denial of Service) is an attack that overwhelms a website, application or network with traffic from many sources at once, usually a botnet, to make it slow or unavailable to legitimate users.

How it works

In a denial-of-service (DoS) attack, the goal is to exhaust a resource: bandwidth, network equipment capacity or application processing power. In a DDoS, traffic comes from thousands of compromised devices, such as servers, routers and IoT cameras, which makes blocking by source address impractical. Attacks are usually grouped into three categories:

  • Volumetric: flood the link with traffic, often using amplification through misconfigured services such as DNS and NTP.
  • Protocol: exploit how network protocols work, such as SYN floods, to exhaust the connection tables of firewalls and load balancers.
  • Application layer (layer 7): requests that look legitimate, such as searches and logins, aimed at the most resource-intensive parts of the application.

Why it matters

DDoS does not steal data, but it stops the business: an online store offline, customer service channels unavailable, partner APIs interrupted. It is also used as a smokescreen for another intrusion and as a pressure tactic in extortion, including by ransomware groups during negotiations.

How to protect yourself

Protection combines capacity and filtering before traffic reaches the environment: mitigation services at the carrier or in the cloud, with traffic scrubbing centers, CDN and WAF for the application layer, per-client rate limits, and a response plan that defines who triggers mitigation and how customers are informed. Large volumetric attacks cannot be stopped by the local firewall alone, because the link becomes congested before the traffic reaches it.

Network Secure offers managed security services (MSS).

Frequently asked questions

What is the difference between DoS and DDoS?

In a DoS attack, traffic comes from a single source. In a DDoS attack, it comes from many distributed sources, usually a botnet, which increases the volume and makes blocking harder.

Does a firewall protect against DDoS?

Only partly. Protocol and application attacks can be filtered by a firewall and WAF, but volumetric attacks congest the link before reaching them and require mitigation at the carrier or in the cloud.