Distributed Denial of Service / DDoS
DDoS is a distributed denial-of-service attack. Instead of attacking from one place, the attacker uses a large number of compromised devices, rented infrastructure and reflected traffic to bury the target in web requests until the server is blocked. The aim is not data theft but choking the service into unavailability.
Term
description · examples · notesDDoS is a distributed denial-of-service attack. Instead of attacking from one place, the attacker uses a large number of compromised devices, rented infrastructure and reflected traffic to bury the target in web requests until the server is blocked. The aim is not data theft but choking the service into unavailability.
Description
The attack can hit network capacity, the transport layer, or the application itself. Sometimes a huge volume of traffic is sent to congest the link, sometimes connections are exhausted, and sometimes expensive application requests are sent that consume CPU, memory or the database. On the victim's side the result is the same: the service stops working.
DDoS is not always a technical show of force. It can be a method of extortion, political pressure, disruption of a competitor, or a smokescreen while something else is attempted in parallel. So it is worth looking not only at the traffic graph but at the context in which the attack begins.
Examples
- A botnet of compromised IoT devices sends enormous traffic at the public site of a financial institution.
- The attack hits the network layer and the application's login endpoint at the same time, so protection at one layer is not enough.
- An online service becomes unreachable during an important event because application requests exhaust the database and the backend.
Notes
- DDoS is not solved while the attack is under way. It takes capacity arranged in advance, scrubbing, a CDN, rate limiting and a clear line to the provider.
- If all the traffic has to reach your infrastructure before you can filter it, you are in a poor position.
Mentioned in the news
- 5. MAJ 2026. Canonical pod DDoS napadom, proiranska grupa traži kontakt →
- 20. APR 2026. DDoS napad poremetio rad platforme Bluesky skoro 24 sata →
- 5. MAR 2026. Zabeleženo 149 hakktivističkih DDoS napada u 110 zemalja →
- 30. APR 2026. Europol IOCTA 2026: AI, enkripcija i proxy servisi šire sajber kriminal →
- 28. MAR 2026. Rast Mirai botneta podstiče nove talase DDoS napada →
- 21. MAR 2026. Međunarodna akcija poremetila rad velikih DDoS botneta koji zloupotrebljavaju IoT uređaje →
- 20. MAR 2026. Koalicija ISAC grupa upozorava na rast rizika od sajber i fizičkih napada povezanih sa Iranom →
- 19. MAR 2026. Napadači preuzimaju mrežne uređaje za DDoS napade i rudarenje kriptovaluta →
- 4. MAR 2026. Iranski hakeri podižu nivo pretnje prema SAD i saveznicima →
Techniques
carried out with 2Techniques used to carry it out. Select one to open its page.
Defenses
countered by 4How it is defended against. Select one to open its page.