GlossaryAttack surface and pentesting

DDoS

Short answer

A DDoS (Distributed Denial of Service) attack floods a website, application or network with traffic from many sources at once, so that legitimate users cannot reach it. It does not usually steal data, but it can stop sales, services and operations for hours or days.

How it works

Attackers use botnets, networks of compromised devices such as routers, cameras and servers, to send huge volumes of requests. Volumetric attacks saturate the connection. Protocol attacks exhaust firewalls and load balancers. Application layer attacks send requests that look legitimate but overload the web server or database, and are the hardest to filter.

Why companies are targeted

Motives include extortion (pay or the attack continues), hacktivism against public bodies and companies in Europe, competition, and distraction while another intrusion takes place. DDoS services are cheap to hire, which makes these attacks accessible to almost anyone.

How to protect against it

Protection is mostly architectural and needs to be in place before an attack: a CDN or DDoS protection service in front of public websites and APIs, a web application firewall, rate limiting, agreements with the internet provider and a response procedure. Knowing which services are exposed, through attack surface management, tells you what needs protecting.

Where it shows up in compliance

Availability is one of the core security properties in ISO 27001, the ENS and NIS2. A DDoS that disrupts an essential service can be a reportable incident under NIS2, and the scenario belongs in the business continuity plan and the incident response plan.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub