166 terms · 75/46/45
Defense № 028 · class: resilience

DDoS Protection

DDoS protection encompasses technologies and services that detect and mitigate distributed denial-of-service attacks before malicious traffic reaches or overwhelms the target infrastructure.

Term

description · examples · notes

DDoS protection encompasses technologies and services that detect and mitigate distributed denial-of-service attacks before malicious traffic reaches or overwhelms the target infrastructure.

Description

These solutions operate at the network and application layers, filtering malicious traffic while allowing legitimate requests through. They can be implemented as a cloud service, an on-premises appliance, or a combination.

Effective protection requires sufficient capacity to absorb large traffic volumes and intelligent algorithms to distinguish legitimate from malicious traffic.

What people often say

  • A perimeter firewall is sufficient for DDoS defense.
  • DDoS protection is only needed by large organizations.

Covers / does not cover

Covers

  • Filtering high-volume volumetric attacks
  • Mitigating network and application layer attacks
  • Automatic recognition and blocking of DDoS traffic patterns
  • Maintaining service availability during an attack

Does not cover

  • Attacks targeting application vulnerabilities rather than availability
  • Resource exhaustion caused by legitimate traffic
  • Threats that do not affect network availability
Composite

Threats

reduces 6

Techniques

neutralizes 2

Techniques it neutralizes. Select one to open its page.