DDoS Attacks - How They Work and How to Mitigate
About 2 min read
A DDoS attack (Distributed Denial of Service) is an attack that sends a massive volume of requests to a target server from many computers, rendering the service unusable. A network of infected devices known as a botnet is often used to carry out the attack, making it a serious threat that endangers the availability of websites and online services. In 2024, Cloudflare reported mitigating the largest DDoS attack ever recorded, reaching 5.6 Tbps.
Types of DDoS Attacks
Volumetric attacks saturate bandwidth with massive amounts of traffic. UDP floods and DNS amplification are representative, sometimes reaching the scale of hundreds of Gbps. Protocol attacks exhaust server resources with techniques such as SYN floods. Application-layer attacks send large volumes of HTTP requests to overload web servers. Multi-vector attacks that combine several techniques cannot be handled by a single countermeasure, which makes it harder for defenders to respond.
How Attacks Are Mitigated in Practice
A DDoS attack is usually observed as a traffic surge far beyond normal levels, and if left unaddressed, the server or the infrastructure in front of it becomes unresponsive. In practice, response does not rely on a single measure: it is common to combine several means, such as absorbing traffic with a CDN, rate limiting at the WAF, and cloud-based DDoS mitigation services. Mitigation services divert attack traffic to high-capacity dedicated infrastructure and pass only legitimate requests through to the server. Whether such a mitigation path has been prepared in advance makes a large difference in how long recovery takes.
DDoS Attack Patterns
Real-World Impact and Concrete Scenarios
A common misconception is that "DDoS attacks only target large corporations." In reality, the e-commerce sites and game servers of small and medium-sized businesses are also frequently attacked. For example, if an online shop is hit by a DDoS attack during a sale, one hour of downtime can result in millions of yen in lost sales. When a service goes down due to a DDoS attack, password resets and two-factor authentication may become unavailable. By keeping your passwords stored offline in a password manager, you can still access your account information even during a service outage.
Preparation for Individual Users
DDoS attacks do not directly target individuals, but preparing for when a service you use comes under attack is important. Set up multiple authentication methods for important accounts so that you can still access them through alternative means during a service outage.
Was this article helpful?