Skip to main content

IT security

What is a DDoS attack?

A DDoS attack overwhelms your systems with traffic from thousands of machines. See how the attacks work, and what to do before and during an attack.

In short

A DDoS attack (Distributed Denial of Service) overloads a website, server or internet connection with so much traffic that it cannot serve real users.

The service is effectively down, even though nothing has been hacked. 'Distributed' means the traffic comes from thousands of machines at once, typically a botnet: a network of infected computers, servers and IoT devices that the attacker remotely controls without the owners' knowledge.

DDoS is used for extortion, as a diversion during other attacks and as political activism, and Danish businesses and public authorities are regularly hit by exactly that last type. The defence lies not in your own server capacity, but in preparation: DDoS protection in front of the website, an internet provider with a scrubbing agreement and a contingency plan that establishes who does what when the traffic comes flooding in.

MI Support IT helps Danish businesses with both prevention and preparedness.

Back to the glossary

What is a DDoS attack?

DDoS stands for Distributed Denial of Service: an attack that does not break in, but shuts down by drowning the target in traffic. The website, webshop or VPN connection is bombarded with more requests than it can handle, and real users cannot get through. Typically no data is stolen; the damage is downtime, lost revenue and a strained reputation. See also the broader overview under cyber attack.

How does a DDoS attack work?

The attacks hit at three layers:

  • Volumetric attacks: raw data volume (hundreds of gigabits per second) that saturates the internet connection itself. Nothing behind the connection can help when the pipe is full.
  • Protocol attacks: exploit weaknesses in network protocols (such as SYN floods) so that firewalls and load balancers run out of resources.
  • Application attacks: fewer but "heavy" requests against, for example, search functions or login pages, which are harder to distinguish from real traffic.

DDoS has also become a commodity: "booter" services rent out attacks for a few hundred kroner, and attacks are used both for extortion ("pay, or we continue") and as a smokescreen while a real break-in takes place elsewhere in the network.

What is a botnet?

A botnet is the attacker's army: thousands of compromised devices (PCs, servers, routers, IP cameras and other IoT devices), infected with malware, that let a single operator control them remotely as one. The owners typically have no idea; the device appears to work normally but participates in attacks, spam campaigns or cryptomining in the background. Because the traffic comes from ordinary devices all over the world, it cannot simply be blocked by sender address. Your own hygiene matters here: updated devices and changed default passwords keep your equipment out of other people's botnets.

Hit by DDoS: what do you do NOW?

  1. Confirm that it is DDoS: Check that the downtime is caused by a traffic storm and not a fault. Your provider or monitoring can see the traffic pattern.
  2. Contact your internet provider/hosting immediately: They can filter or reroute traffic upstream. You cannot do that yourself.
  3. Activate your protection: If you have a DDoS service in front of the site, switch it to heightened mode ("under attack mode").
  4. Follow the contingency plan: Inform management, employees and, if relevant, customers. Decide in advance who speaks publicly.
  5. Do not pay extortion demands, and stay sceptical: investigate whether the attack is covering for intrusion attempts elsewhere, and report it to the police (in Denmark, the NSK).

DDoS protection in practice

Effective defence is established before the attack: a CDN/DDoS service (such as Cloudflare or equivalent) in front of the website that absorbs volumetric attacks; an agreement with the internet provider on traffic scrubbing; hardened and updated systems so application attacks score no cheap points; and an IT contingency plan where the DDoS scenario is described with roles, contacts and communication. Rehearse the scenario once, and the plan is suddenly worth more than the paper.

How MI Support IT helps

MI Support IT helps assess your exposure, get the right protection in front of your critical services and write the DDoS scenario into an IT contingency plan that holds up in practice, as part of the overall IT security effort. Contact us, preferably before the traffic comes flooding in.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.