What is a DDoS attack?
DDoS stands for Distributed Denial of Service: an attack that does not break in, but shuts down by drowning the target in traffic. The website, webshop or VPN connection is bombarded with more requests than it can handle, and real users cannot get through. Typically no data is stolen; the damage is downtime, lost revenue and a strained reputation. See also the broader overview under cyber attack.
How does a DDoS attack work?
The attacks hit at three layers:
- Volumetric attacks: raw data volume (hundreds of gigabits per second) that saturates the internet connection itself. Nothing behind the connection can help when the pipe is full.
- Protocol attacks: exploit weaknesses in network protocols (such as SYN floods) so that firewalls and load balancers run out of resources.
- Application attacks: fewer but "heavy" requests against, for example, search functions or login pages, which are harder to distinguish from real traffic.
DDoS has also become a commodity: "booter" services rent out attacks for a few hundred kroner, and attacks are used both for extortion ("pay, or we continue") and as a smokescreen while a real break-in takes place elsewhere in the network.
What is a botnet?
A botnet is the attacker's army: thousands of compromised devices (PCs, servers, routers, IP cameras and other IoT devices), infected with malware, that let a single operator control them remotely as one. The owners typically have no idea; the device appears to work normally but participates in attacks, spam campaigns or cryptomining in the background. Because the traffic comes from ordinary devices all over the world, it cannot simply be blocked by sender address. Your own hygiene matters here: updated devices and changed default passwords keep your equipment out of other people's botnets.
Hit by DDoS: what do you do NOW?
- Confirm that it is DDoS: Check that the downtime is caused by a traffic storm and not a fault. Your provider or monitoring can see the traffic pattern.
- Contact your internet provider/hosting immediately: They can filter or reroute traffic upstream. You cannot do that yourself.
- Activate your protection: If you have a DDoS service in front of the site, switch it to heightened mode ("under attack mode").
- Follow the contingency plan: Inform management, employees and, if relevant, customers. Decide in advance who speaks publicly.
- Do not pay extortion demands, and stay sceptical: investigate whether the attack is covering for intrusion attempts elsewhere, and report it to the police (in Denmark, the NSK).
DDoS protection in practice
Effective defence is established before the attack: a CDN/DDoS service (such as Cloudflare or equivalent) in front of the website that absorbs volumetric attacks; an agreement with the internet provider on traffic scrubbing; hardened and updated systems so application attacks score no cheap points; and an IT contingency plan where the DDoS scenario is described with roles, contacts and communication. Rehearse the scenario once, and the plan is suddenly worth more than the paper.
How MI Support IT helps
MI Support IT helps assess your exposure, get the right protection in front of your critical services and write the DDoS scenario into an IT contingency plan that holds up in practice, as part of the overall IT security effort. Contact us, preferably before the traffic comes flooding in.