A DDoS attack overwhelms websites or online services with massive traffic from multiple sources, making them inaccessible to legitimate users. Learn how DDoS attacks work, the different types, and the most effective methods to protect your infrastructure against them.
DDoS attack is an attempt to make a website, server, or online service unavailable by generating a load that the infrastructure cannot process in time. Instead of hacking systems or stealing data, attackers send a massive number of requests, overwhelming available network or computing resources.
The main feature of a DDoS is its distributed nature. Traffic can originate simultaneously from thousands or even millions of devices, so simply blocking a single source won't solve the issue. When bandwidth, CPU, memory, or connection limits are exhausted, regular users start to experience errors, delays, or are unable to access the service at all.
Below, we'll explain what a DDoS attack is in simple terms, how a large number of requests overloads a server, what types of these attacks exist, and how modern protection systems separate malicious traffic from legitimate users.
DDoS stands for Distributed Denial of Service. The essence of the attack is to create such a load on a website, server, or network equipment that the system can no longer serve normal users properly.
Imagine an online store that can handle several thousand visitors at once. If suddenly hundreds of thousands of devices start sending requests, the server is forced to spend resources processing them. When available resources run out, pages load slowly, errors appear, and in some cases, the site stops responding entirely.
The key difference between a DDoS and a classic DoS (Denial of Service) attack is the number of traffic sources. While a DoS attack may come from one or a few systems, a DDoS attack involves requests from many different points across the network-hence the "distributed" name.
Importantly, a DDoS attack does not necessarily mean the attacker has hacked the server. The main goal is to disrupt the service's availability. Databases and user files may remain untouched, but accessing the site, app, or API during an attack becomes difficult or impossible.
Various infrastructure elements can be overloaded. Sometimes attackers try to saturate all available internet bandwidth; other times, they overwhelm network hardware with too many connections, or send requests that demand significant CPU, memory, or database resources.
From the user's perspective, the result looks similar: slow website loading, dropped connections, server errors, or an unresponsive service. However, the underlying causes within the infrastructure can differ greatly, and so do the protection strategies for different types of DDoS attacks.
Every server has limited resources. It can process only a certain number of requests per second, support a finite number of connections, and transmit data within its bandwidth limits. A DDoS attack aims to exceed one or more of these thresholds.
When a user accesses a website, their device sends a request through the network to the service's infrastructure. The server receives it, identifies the required resource, may query the application or database, and forms a response.
Each request consumes time and resources. Even if a single operation takes just fractions of a second, the server can only handle a limited number of these simultaneously. Excess requests are queued or wait for resources to become available.
During a DDoS, the flow of requests spikes dramatically. Instead of thousands per second, the infrastructure may receive hundreds of thousands or millions. Queues grow, connections remain occupied, CPU and memory usage soar, and the network channel may reach capacity.
As a result, a regular user's request is technically no different from the rest-it too must wait for free resources. If the server is maxed out, the connection can time out or return errors like 502, 503, or 504.
Sometimes the server can keep running, but requests may not even reach it if the attacking traffic saturates the internet channel. For example, if your infrastructure has a 10 Gbps link but receives 50 Gbps of incoming traffic, the excess must be dropped before it ever reaches your application.
To overload a service, attackers do not need to send unusual or exploitative requests-sheer volume of ordinary requests can suffice.
The load is especially pronounced if each request triggers resource-intensive operations: searching a large database, generating a complex page, querying multiple internal services, or calculating a dynamic response. One such request can consume far more resources than loading a small static file.
Another method involves establishing a large number of simultaneous connections. Even if each transmits little data, the server or network equipment must track connection states and allocate resources for them.
So, infrastructure can be overloaded in several ways: saturating the network channel, exhausting connection limits, or forcing the application to handle too many operations at once. The type of DDoS attack and the best protection method depend on which resource becomes the bottleneck.
DDoS attacks vary based on which infrastructure resource the attacker seeks to exhaust. Some generate massive data streams to clog the internet channel, others overload network equipment, and still others force the application to perform excessive operations.
The main goal of a volumetric attack is to fill the available bandwidth to capacity. An enormous data stream is directed at the server or its network infrastructure, leaving no room for normal traffic.
In this scenario, the web server may still function, but users cannot access the site because the communication channel to it is already overloaded. Attack load is typically measured in bits per second-the higher the attack traffic, the more bandwidth is needed to process it.
Filtering traffic before it reaches the server is vital in these cases. If the link to the data center is saturated, blocking requests within the application itself is almost useless.
This class of DDoS targets not the volume of data, but the limited resources of the network stack and hardware.
To establish and maintain connections, routers, firewalls, load balancers, and servers store certain operational information. If the number of new connections becomes too great, state tables and queues can fill up.
The result: devices stop handling new connections properly-even if overall traffic volume isn't extreme. So, relatively little data can create a major infrastructure load under the right conditions.
At the application layer, attack traffic may look much like regular user activity. For example, the server receives a flood of HTTP or HTTPS requests to pages, search, APIs, or other site features.
The problem arises when each request requires significant resources. The server must execute application code, query databases, perform calculations, and generate dynamic responses.
If the volume of such requests is too high, CPU, memory, database connection pools, or other components reach capacity. In these cases, network traffic volume may be modest, making this type of attack harder to detect based on bandwidth alone.
Dividing DDoS into these categories is important for defense. A mechanism that handles network channel overload well may not stop a flood of seemingly legitimate application requests. That's why modern protection systems analyze multiple layers-from overall traffic and network connections to the behavior of individual HTTP requests.
One reason DDoS is hard to stop with simple blocking is the large number of traffic sources. Attackers often use a botnet-a network of devices they can remotely control without the owners' knowledge.
A botnet can include infected computers, servers, routers, IP cameras, network storage devices, and other IoT devices. Each device alone can send only a modest amount of traffic, but the combined load of thousands is substantial.
For example, if one device sends just a few dozen requests per second, a large botnet can generate hundreds of thousands or millions of requests. To the attacked server, these appear from many different IP addresses and networks, making it much harder to distinguish them from real users.
This distributed nature makes blocking by single address ineffective. Even if some sources are filtered, the rest will continue generating traffic. Moreover, overly aggressive filtering may accidentally block legitimate users in the same networks or regions.
Botnets are typically created in advance: vulnerable devices are infected with malware and connected to a command infrastructure. The operator can then simultaneously instruct all devices to send traffic to a chosen target.
To learn more about how botnets are formed and how infected devices become part of an attacker's infrastructure, check out our in-depth guide: What is a Botnet: How Botnets Work, Dangers, and Protection Tips.
Note that a botnet is not required for every DDoS attack. Load can be generated in other ways, but a large number of distributed sources highlights the main difference between DDoS and regular denial-of-service: attack traffic comes from many independent points in the network.
DDoS protection is built on multiple layers of technology. The system's job is to detect abnormal load as early as possible, separate suspicious traffic from legitimate traffic, and prevent core infrastructure from being overwhelmed.
The first step is to determine if a traffic spike is due to an attack or just a surge in legitimate users. Monitoring systems track request volumes, new connections, and how traffic is distributed across IPs, regions, and other markers.
Behavioral changes, not just raw load, are important. For instance, if a site typically gets a few thousand requests per minute but suddenly sees tens of thousands, that may indicate a DDoS attack.
No single metric is enough, though. Sudden popularity can be legitimate-after a major announcement or viral link, for example. Modern systems compare many parameters to judge whether current traffic looks like normal user behavior.
After identifying suspicious traffic, some requests can be dropped before reaching the main server. This involves network filters, rate limiting rules, and client behavior analysis systems.
A basic mechanism is rate limiting, which caps the number of requests a single source (or group) can make in a given time. If the threshold is exceeded, further requests are blocked or deprioritized.
For web application attacks, a WAF (Web Application Firewall) can analyze HTTP and HTTPS requests and help screen out suspicious activities before they reach the app.
The challenge is not to block genuine users along with attack traffic. Effective defense rarely relies solely on hard limits or IP blocklists.
Another key principle is to avoid having a single server handle all incoming traffic. Load can be distributed among several servers, data centers, and network nodes.
CDNs, load balancers, and distributed network infrastructure are commonly used. The more resources and points of presence a system has, the harder it is to overwhelm with a concentrated traffic surge.
For a detailed look at how request distribution works, see: What is a Load Balancer: Key Concepts and Algorithms for Scalable, Reliable Services.
Large network infrastructures also use Anycast. Here, a single IP address is served by multiple nodes in different locations, and incoming traffic is routed to the most suitable one. This distributes load and reduces the chance that all attack traffic hits a single point.
For more on this mechanism, read: Anycast DNS: How It Works, Benefits, and Why It Matters.
Absolute protection from DDoS is impossible because every infrastructure has physical limits on bandwidth and computing power. Sufficiently large attacks can overload even the most robust systems.
Therefore, the goal of protection is not to make attacks impossible, but to maximize the volume of load that the system can withstand and filter out malicious traffic before it affects normal users.
In practice, the most resilient solutions combine continuous monitoring, automatic filtering, rate limiting, load balancing, and external traffic-scrubbing services. This multi-layered approach enables services to keep serving legitimate users even during large-scale attacks.
A DDoS attack disrupts a website or service by overloading the infrastructure's limited resources. The flood of requests may saturate the network channel, exhaust available connections, or force the application to handle more operations than it can manage.
Distributed attacks, where traffic comes from a large number of devices, are particularly difficult to defend against. In such cases, simply blocking IP addresses is ineffective; protection must analyze request behavior and distribute load across several nodes.
Effective DDoS protection is multi-layered: monitoring detects anomalies quickly, filtering and rate limiting cut off some malicious requests, and CDN, Anycast, and load balancers reduce the burden on individual servers. The earlier malicious traffic is separated from legitimate, the higher the chance a service will remain available even during a major attack.