DDoS attack
A DDoS attack (distributed denial-of-service attack) is a cyberattack aimed at taking down a website or server by overloading it with a huge number of fake requests from many infected devices (a botnet). As a result, the resource becomes unavailable to real users.
Contents
What is a DDoS attack in simple words
A DDoS attack is an artificial overload of a website or server with a huge number of requests from different computers. The goal is to make the resource stop opening for ordinary users, as its capacity cannot cope with the flow. Imagine a popular supermarket designed for 100 customers. Suddenly a crowd of 10,000 people comes to the doors. They do not buy anything, but just stand, create a crush and occupy all the space. As a result, real customers cannot get inside, and the store turns out to be blocked.
Attackers use a network of infected devices (a botnet) — computers, routers, surveillance cameras around the world. The owners of these devices may not even guess that their equipment is participating in the attack. That is why the attack is called “distributed” — requests come not from one place, but from everywhere, so it is difficult for the system to block one specific address.
In the modern digital world, DDoS attacks have become one of the most common tools of cyberwarfare and unfair competition. According to research, the number of such attacks grows by tens of percent annually, and their power is measured in terabits per second. Read more about cyber threats in the article Cyber fraud.
Why attackers conduct DDoS attacks
- Unfair competition: Companies can order attacks on business competitors to attract their customers while they cannot access services.
- Extortion (blackmail): Attackers attack a website and then demand a ransom from the owners to stop the attack.
- Hacktivism (protest): Expressing a political or social position. Hacker groups attack government portals and banks to draw attention to problems.
- Distraction: A powerful DDoS attack can be used as a smoke screen. While the security service is busy repelling the overload, hackers penetrate the system through other vulnerabilities.
Read about information security threats in the article Information security incident.
How to understand that a DDoS attack is underway
- A sharp jump in traffic: The traffic graph takes off hundreds and thousands of times without visible reasons.
- Server errors: The resource returns codes 502, 503 or 504 instead of ordinary pages.
- Slow loading or failure: The website loads endlessly or completely stops opening.
- Strange geography: The analytics shows that most requests come from countries or regions where you have no target audience.
How to protect against DDoS attacks
The most effective way of protection is the use of specialized cloud services (Anti-DDoS and CDN), which redirect traffic through their filtering nodes. Such platforms analyze incoming connections in real time and cut off bots before they reach your server.
- Cloudflare — a global network for protecting any resource.
- DDoS-Guard — a domestic service for filtering anomalous requests.
- Yandex Cloud — built-in solutions with WAF integration.
Setting up request rate limiting also helps reduce the load on the server. Read about other protection methods in the article Information security.
Liability for DDoS attacks
Organizing and participating in DDoS attacks are illegal actions. In Russia, such acts are qualified under Articles 272-274 of the Criminal Code of the Russian Federation and entail serious criminal liability. The punishment can include imprisonment for up to 7 years and large fines. Abroad (in the USA and EU countries), hackers face real prison terms of 10 to 20 years.
Read about the legal aspects of cybersecurity in the article Cyber fraud.
Frequently asked questions
What is a DDoS attack in simple words?
A DDoS attack is an artificial overload of a website or server with a huge number of requests from different computers. The goal is to make the resource stop opening for ordinary users. Attackers use a network of infected devices (a botnet) around the world. Read about ways to protect against such attacks in the article Information security.
How to understand that a DDoS attack is underway?
Main signs: a sharp jump in traffic without visible reasons, server errors 502/503/504, slow loading or complete unavailability of the website, strange geography of requests (from countries where you have no audience). If you notice these signs, check the server logs and contact your hosting provider. Read about problem diagnostics in the article Information security incident.
What is the difference between DoS and DDoS?
DoS (Denial of Service) is an attack from one device. DDoS (Distributed Denial of Service) is an attack from many sources (distributed), using a botnet. A DDoS attack is harder to block, since the traffic comes from legitimate addresses of real users whose devices were infected. Read about network threats in the article Firewall.
What is the penalty for a DDoS attack?
Organizing or participating in a DDoS attack entails criminal liability. In Russia — under Articles 272-274 of the Criminal Code of the Russian Federation (up to 7 years of imprisonment and fines up to 2 million rubles). In the USA and EU countries — from 10 to 20 years of imprisonment. Civil lawsuits for damages are also possible. Read about legal consequences in the article Cyber fraud.
How to protect against DDoS attacks?
The most effective way is to connect cloud protection services (Anti-DDoS) that filter traffic before it reaches your server. We recommend using Cloudflare, DDoS-Guard or built-in solutions from Yandex Cloud. Setting up request rate limiting and using a WAF also helps. Read about comprehensive protection in the article Information security.
Other terms in «Infrastructure»
Was this information helpful?
Build reliable IT infrastructure
Build a modern, fault-tolerant IT infrastructure. Design, equipment supply, installation and maintenance turnkey.