This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

DDoS attack

Infrastructure

A DDoS attack (distributed denial-of-service attack) is a cyberattack aimed at taking down a website or server by overloading it with a huge number of fake requests from many infected devices (a botnet). As a result, the resource becomes unavailable to real users.

What is a DDoS attack in simple words

A DDoS attack is an artificial overload of a website or server with a huge number of requests from different computers. The goal is to make the resource stop opening for ordinary users, as its capacity cannot cope with the flow. Imagine a popular supermarket designed for 100 customers. Suddenly a crowd of 10,000 people comes to the doors. They do not buy anything, but just stand, create a crush and occupy all the space. As a result, real customers cannot get inside, and the store turns out to be blocked.

Anatomy of a DDoS attack: botnet, target and the overload mechanism Diagram of a DDoS attack structure: botnet (infected devices) → flow of requests → target server (overloaded), indicating consequences: 502/503 errors, site unavailability. Anatomy of a DDoS attack How a botnet overloads the target server Bot 1 (Infected PC) Bot 2 (Server) Bot 3 (Router) Bot N (Camera / IoT) Botnet (thousands of infected devices) 🎯 Target server / Website Huge volume of fake requests → Overload → Denial of service Result: 502/503 errors, slow loading or complete unavailability Losses from site / service downtime
DDoS attack — diagram 1

Attackers use a network of infected devices (a botnet) — computers, routers, surveillance cameras around the world. The owners of these devices may not even guess that their equipment is participating in the attack. That is why the attack is called “distributed” — requests come not from one place, but from everywhere, so it is difficult for the system to block one specific address.

In the modern digital world, DDoS attacks have become one of the most common tools of cyberwarfare and unfair competition. According to research, the number of such attacks grows by tens of percent annually, and their power is measured in terabits per second. Read more about cyber threats in the article Cyber fraud.

Why attackers conduct DDoS attacks

  • Unfair competition: Companies can order attacks on business competitors to attract their customers while they cannot access services.
  • Extortion (blackmail): Attackers attack a website and then demand a ransom from the owners to stop the attack.
  • Hacktivism (protest): Expressing a political or social position. Hacker groups attack government portals and banks to draw attention to problems.
  • Distraction: A powerful DDoS attack can be used as a smoke screen. While the security service is busy repelling the overload, hackers penetrate the system through other vulnerabilities.

Read about information security threats in the article Information security incident.

How to understand that a DDoS attack is underway

  • A sharp jump in traffic: The traffic graph takes off hundreds and thousands of times without visible reasons.
  • Server errors: The resource returns codes 502, 503 or 504 instead of ordinary pages.
  • Slow loading or failure: The website loads endlessly or completely stops opening.
  • Strange geography: The analytics shows that most requests come from countries or regions where you have no target audience.

How to protect against DDoS attacks

The most effective way of protection is the use of specialized cloud services (Anti-DDoS and CDN), which redirect traffic through their filtering nodes. Such platforms analyze incoming connections in real time and cut off bots before they reach your server.

  • Cloudflare — a global network for protecting any resource.
  • DDoS-Guard — a domestic service for filtering anomalous requests.
  • Yandex Cloud — built-in solutions with WAF integration.

Setting up request rate limiting also helps reduce the load on the server. Read about other protection methods in the article Information security.

Methods of protection against DDoS attacks: Anti-DDoS, CDN, WAF, Rate Limiting Diagram of DDoS protection methods: cloud Anti-DDoS services (Cloudflare, DDoS-Guard), CDN for load distribution, WAF for filtering, Rate Limiting for limiting request frequency. Methods of protection against DDoS attacks How to ensure service availability ☁️ Cloud Anti-DDoS Traffic filtering Cloudflare · DDoS-Guard Yandex Cloud · AWS Shield 🌐 CDN + WAF Distribution + Filtering Static content caching Web Application Firewall ⏱️ Rate Limiting Request rate limiting Protection against brute force and bots 🔄 Auto-scaling Horizontal scaling Adding resources under load Comprehensive approach = 99.99% availability even during an attack
DDoS attack — diagram 2

Liability for DDoS attacks

Organizing and participating in DDoS attacks are illegal actions. In Russia, such acts are qualified under Articles 272-274 of the Criminal Code of the Russian Federation and entail serious criminal liability. The punishment can include imprisonment for up to 7 years and large fines. Abroad (in the USA and EU countries), hackers face real prison terms of 10 to 20 years.

Read about the legal aspects of cybersecurity in the article Cyber fraud.

Frequently asked questions

What is a DDoS attack in simple words?

A DDoS attack is an artificial overload of a website or server with a huge number of requests from different computers. The goal is to make the resource stop opening for ordinary users. Attackers use a network of infected devices (a botnet) around the world. Read about ways to protect against such attacks in the article Information security.

How to understand that a DDoS attack is underway?

Main signs: a sharp jump in traffic without visible reasons, server errors 502/503/504, slow loading or complete unavailability of the website, strange geography of requests (from countries where you have no audience). If you notice these signs, check the server logs and contact your hosting provider. Read about problem diagnostics in the article Information security incident.

What is the difference between DoS and DDoS?

DoS (Denial of Service) is an attack from one device. DDoS (Distributed Denial of Service) is an attack from many sources (distributed), using a botnet. A DDoS attack is harder to block, since the traffic comes from legitimate addresses of real users whose devices were infected. Read about network threats in the article Firewall.

What is the penalty for a DDoS attack?

Organizing or participating in a DDoS attack entails criminal liability. In Russia — under Articles 272-274 of the Criminal Code of the Russian Federation (up to 7 years of imprisonment and fines up to 2 million rubles). In the USA and EU countries — from 10 to 20 years of imprisonment. Civil lawsuits for damages are also possible. Read about legal consequences in the article Cyber fraud.

How to protect against DDoS attacks?

The most effective way is to connect cloud protection services (Anti-DDoS) that filter traffic before it reaches your server. We recommend using Cloudflare, DDoS-Guard or built-in solutions from Yandex Cloud. Setting up request rate limiting and using a WAF also helps. Read about comprehensive protection in the article Information security.

Was this information helpful?

Infrastructure Back

DDoS attack

A DDoS attack (distributed denial-of-service attack) is a cyberattack aimed at taking down a website or server by overloading it with a huge number of fake requests from many infected devices (a botnet). As a result, the resource becomes unavailable to real users.

Build reliable IT infrastructure

Build a modern, fault-tolerant IT infrastructure. Design, equipment supply, installation and maintenance turnkey.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm