CloudPe
Security & Compliance

What is a DDoS attack? Types, how it works and how to prevent it

Gautami Teliwadekar 14 min read
What is a DDoS attack? Types, how it works and how to prevent it

A website can suddenly become slow or unavailable. Applications may stop responding. APIs may fail.
One possible cause is a DDoS attack.
A DDoS attack overwhelms a server, application, or network with unwanted traffic. The attacker may not need to access data or compromise the target. Disrupting access can itself be the objective.
Understanding how these attacks work helps organisations prepare for them. This blog explains what a DDoS attack is, how it works, the main types of attacks, and how organisations can prevent and mitigate their impact.

What is a DDoS attack?

DDoS stands for Distributed Denial of Service.
A DDoS attack attempts to disrupt a server, website, application, or network by overwhelming it with traffic from multiple sources.
The traffic can consume available bandwidth or exhaust system resources. As a result, legitimate users may experience slow performance, failed requests, or complete service disruption.
The word distributed is important.
The attack traffic does not come from one computer or IP address. It can come from thousands or even millions of internet-connected devices. Attackers often control these devices together as part of a botnet.

What is the difference between a DoS and DDoS attack?

difference between detecting an attack and allowing all incoming traffic to

A denial-of-service attack and a distributed denial-of-service attack have a similar goal. Both attempt to make a service unavailable.
The main difference is the source of the traffic.
A DoS attack usually originates from a single source. A DDoS attack uses multiple distributed sources.
This makes a DDoS attack harder to block. Blocking one IP address may have little effect when traffic continues from thousands of other devices.

How does a DDoS attack work?

How does a DDoS attack work

A DDoS attack directs a large amount of unwanted traffic towards a target. The target may be a website, application, server, network, or data centre.
The attack usually follows the sequence below:

  • Devices are compromised
    Attackers compromise internet-connected devices using malware or other techniques.
    These devices can include computers, routers, cameras, and other connected systems. The compromised devices can then be controlled remotely.
  • A botnet is formed
    A group of compromised devices controlled together is known as a botnet.
    Each device may generate only a small amount of traffic. The combined traffic, however, can become significant.
  • The target receives unwanted traffic
    The attacker instructs the botnet to send traffic or requests to the target.
    Depending on the attack type, the traffic may consume bandwidth, overwhelm network equipment, or exhaust application resources.
  • Legitimate users are affected
    The infrastructure must now process legitimate and unwanted traffic at the same time.
    As pressure increases, users may experience slow loading times, failed requests, connection errors, or complete service outages.

Why is a DDoS attack dangerous?

A DDoS attack primarily affects availability. It can prevent customers, employees, and systems from accessing important online services.
A website may become inaccessible. An application may stop responding. An API may fail. Critical digital services may also become unavailable. This disruption can then affect business operations.
Service outages may lead to lost transactions, interrupted operations, poor customer experience, and reputational damage.
This makes DDoS protection more than a cybersecurity requirement. It also supports infrastructure availability and business continuity.

Get cloud infrastructure designed with network-level DDoS protection.

Try CloudPe

What are the main types of DDoS attacks?

Most DDoS attacks fall into the three main categories.
Each category targets a different part of the infrastructure. This is also why organisations usually need more than one protection layer. The three main types are:

Volumetric attacks

Volumetric attacks attempt to consume the available bandwidth between the target and the wider internet.
The attacker generates a very large amount of traffic. The goal is to fill the available network capacity.
Once bandwidth becomes saturated, legitimate traffic may struggle to reach the target.
Some volumetric attacks also use amplification techniques. These techniques increase the amount of traffic directed towards the victim.

Protocol attacks

Protocol attacks target network infrastructure and system resources.
They can overwhelm devices such as servers, firewalls, load balancers, and network equipment.
A TCP SYN flood* is a common example. A TCP SYN flood is a type of denial-of-service attack that overwhelms a server by leaving connection requests half-open. It attempts to consume resources associated with handling network connections.
These attacks may use less bandwidth than large volumetric attacks. Instead, they focus on exhausting the resources required to process network traffic.

Application-layer attacks

Application-layer attacks target applications and services directly.
An HTTP flood is a common example. An HTTP flood is an application-layer distributed denial-of-service (DDoS) attack that overwhelms a web server or application with a massive volume of valid HTTP requests to crash the service or make it slow for real users.
The requests can resemble legitimate user traffic. This can make the attack harder to identify.
The goal is to consume application resources such as processing capacity, database connections, or server resources.

Attack typeMain targetMain resource affectedCommon example
Volumetric attackNetwork connectionBandwidthAmplification attack
Protocol attackNetwork infrastructureSystem and connection resourcesSYN flood
Application-layer attackWebsite or applicationApplication resourcesHTTP flood

Some attacks combine more than one method. These are known as multi-vector attacks.

What is a DDoS attack example?

A simple example can be seen with an e-commerce website.
The website receives normal traffic from customers. Thousands of compromised devices then begin sending requests at the same time.
The network and servers must now process both legitimate and unwanted traffic.
If the infrastructure cannot handle the volume, customers may experience slow performance or failed requests.
The attacker does not necessarily need to access customer data or gain control of the website.
The disruption itself can be the objective.

Real-world DDoS attacks

DDoS attacks have affected major online platforms and internet infrastructure for many years.
The 2016 Mirai botnet attack is one well-known example. Compromised IoT devices were used to generate large volumes of traffic against multiple targets.
The incident demonstrated how insecure internet-connected devices could be combined into a large botnet.
Attack sizes have continued to increase. Cloudflare reported that hyper-volumetric DDoS attack sizes grew by more than 700% during 2025. One attack reached 31.4 Tbps and lasted only 35 seconds.
The example shows that an attack does not need to last for hours to create a serious infrastructure challenge.

How can you identify a DDoS attack?

A DDoS attack often creates unusual changes in network or application behaviour.
One common sign is a sudden and unexpected increase in traffic.
Other signs may include:

  • Slow website performance
  • Failed requests
  • Increased latency
  • Network congestion
  • Service unavailability
  • Unusual traffic patterns from a large number of sources

However, a traffic spike does not always indicate an attack.
A marketing campaign, product launch, live event, or viral post can also create a legitimate increase in traffic.
The key is to understand whether the traffic is expected and whether it behaves like normal user traffic.
Modern DDoS protection systems analyse traffic patterns and other network or request characteristics to identify suspicious activity and apply mitigation rules.

Why are modern DDoS attacks becoming harder to manage?

Modern DDoS attacks are not defined only by traffic volume.
Attackers can combine different techniques and change their approach quickly. This increases the need for fast detection and automated mitigation.

Here are reasons why modern DDoS attacks are becoming harder to manage:

Multi-vector attacks increase complexity

A multi-vector attack uses more than one attack technique.
For example, attackers may combine a SYN flood with amplification traffic or application-layer requests.
Each method can place pressure on different parts of the infrastructure.
Cloudflare reported a multi-vector campaign involving SYN floods, Mirai-generated traffic, and SSDP amplification attacks.
This means the protection strategy must address more than one type of attack behaviour.

Short attacks can still have a major impact

A DDoS attack does not need to continue for several hours.
A short and intense attack can overwhelm infrastructure within seconds.
This creates an operational challenge. Manual intervention may take longer than the attack itself.
Automated mitigation becomes increasingly important when attack traffic reaches peak intensity quickly.

Botnets can use a growing range of devices

Botnets are no longer limited to traditional computers.
Internet-connected devices can also become part of large botnets when they are compromised.
The growth of connected devices increases the number of systems attackers may attempt to exploit.
More compromised devices can create more distributed sources of attack traffic.

Low-and-slow attacks can also be difficult to detect

Not every DDoS attack creates a massive traffic spike.
Some attacks use lower traffic volumes and slower requests. The goal is to remain less visible while gradually exhausting available resources.
This shows why traffic volume alone is not enough to identify malicious activity.

AI-Driven attack automation

The rise of AI allows attackers to launch smarter, self-optimizing DDoS attacks.
AI algorithms can analyze a target’s defense mechanisms in real time. Automatically mutating attack patterns to bypass filters.
Additionally, AI-powered botnets can mimic legitimate human behavior at scale, making it significantly harder for security tools to distinguish real users from malicious bots.
This shows that static, human-managed security is no longer enough. Forcing cybersecurity into an “AI vs. AI” arms race where defenses must automate and adapt at machine speed to survive.

How can you prevent and mitigate a DDoS attack?

A DDoS attack cannot always be prevented before traffic reaches an organisation.
Infrastructure can, however, be designed to detect, absorb, filter, and mitigate malicious traffic.
Effective protection usually combines several layers, such as:

  • Monitoring traffic continuously
    Traffic monitoring helps teams identify unusual activity early.
    Teams should understand what normal traffic looks like for their applications and networks.
    A clear baseline makes unexpected changes easier to investigate.
  • Using rate limiting
    Rate limiting controls how frequently certain requests can be made.
    It can reduce the pressure caused by repeated requests directed towards a specific service.
    Rate limiting works best as part of a broader protection strategy.
  • Using a web application firewall
    A web application firewall, or WAF, can help filter suspicious HTTP traffic.
    This is particularly useful for application-layer attacks targeting websites and web applications.
    The protection should match the type of traffic and application being protected.
  • Using distributed infrastructure
    Distributed infrastructure can spread workloads across multiple systems or locations.
    This reduces dependence on a single infrastructure point.
    However, distribution alone does not replace dedicated DDoS mitigation.
  • Using specialised DDoS mitigation services
    Specialised mitigation services analyse incoming traffic and identify attack patterns.
    The mitigation layer can then drop, rate-limit, or otherwise filter malicious traffic based on the attack type.
    This helps reduce the amount of attack traffic that reaches protected infrastructure.
  • Maintaining redundancy
    Critical services should avoid unnecessary single points of failure.
    Redundant infrastructure can provide additional resilience when one component or network path experiences disruption.
  • Test the incident response plan
    Teams should know what actions to take during an attack.
    A documented and tested response plan reduces delays and improves coordination during an incident.

Host your workload with DDoS cloud infrastructure.

Explore CloudPe

Why does network-level DDoS mitigation matter?

ddos-mitigation

Some DDoS attacks create pressure before traffic reaches the application or server.
A large volumetric attack, for example, can consume available network capacity.
If the network link becomes saturated, a local firewall may receive the traffic too late to preserve connectivity.
This creates the need for upstream mitigation.
The mitigation layer receives traffic before it reaches the protected infrastructure. It can identify and filter malicious traffic earlier in the traffic path.
As a result, less unwanted traffic reaches the network, servers, and downstream systems.
This approach is particularly relevant for large volumetric and Layer 3 and Layer 4 attacks.

How does network-level DDoS mitigation work?

Network-level mitigation places a protection layer between the wider internet and the protected infrastructure.
Cloudflare Magic Transit is one example of this architectural approach.
Magic Transit acts as a front door for an IP network. It receives traffic destined for protected IP ranges, processes the packets within Cloudflare’s network, and then forwards permitted traffic towards the origin infrastructure. Cloudflare uses BGP and anycast to ingest traffic across its network.
The architecture can be understood in four steps.

  • Traffic reaches the mitigation network
    Traffic intended for the protected network first reaches the mitigation layer.
    The protection network receives and distributes incoming traffic across its infrastructure.
  • Traffic is inspected for attacks
    The mitigation systems analyse traffic characteristics and patterns.
    Network-layer systems can identify malicious traffic such as Layer 3 and Layer 4 DDoS attacks. Magic Transit also supports multiple mitigation layers, including network-layer managed rulesets, Advanced TCP Protection, and network firewall controls.
  • Malicious traffic is filtered
    Once the mitigation system identifies attack traffic, it can apply the appropriate mitigation action.
    This can prevent a large volume of malicious packets from continuing towards the protected infrastructure.
  • Legitimate traffic is forwarded
    Permitted traffic continues towards the origin network.
    Magic Transit can use GRE or IPsec tunnels to route traffic between Cloudflare’s network and the protected infrastructure.

A real-world implementation of DDoS protection

CloudPe is using Cloudflare Magic Transit for network-level DDoS protection.
In this implementation, Cloudflare protects the given IP prefixes by CloudPe, through its network. Incoming traffic reaches the Cloudflare network first, where it is inspected for malicious activity.
Attack traffic is filtered within the mitigation network. Permitted traffic is then forwarded towards the infrastructure through secure GRE or IPsec tunnels.
A recent 24-hour mitigation report from the CloudPe environment showed:

Mitigation activityRecorded value
Attacks mitigated106
Traffic dropped545.63 GB
Maximum attack rate3.63 Gbps
difference between detecting an attack and incoming traffic to

These figures show the difference between detecting an attack and allowing all incoming traffic to reach the infrastructure.
The mitigation layer identifies malicious traffic first. It then filters that traffic before it continues towards the protected environment.

What should an organisation do during a DDoS attack?

Follow the process below:

  • Confirm the attack: Investigate sudden traffic spikes.
  • Identify affected services: Determine which infrastructure is impacted.
  • Monitor mitigation: Adjust DDoS protection based on attack patterns.
  • Track traffic continuously: Watch for changes in attack behaviour.
  • Prioritise critical services: Protect essential applications and systems first.
  • Review the incident: Assess what happened after mitigation.
  • Identify gaps: Check capacity, detection, configuration, and response procedures.
  • Prepare in advance: Maintain a DDoS response plan before an attack occurs.

DDoS attack prevention checklist

DDoS protection combines detection, mitigation, and response.

Detection

  • Monitor network and application traffic.
  • Establish normal traffic baselines.
  • Identify unusual traffic patterns.
  • Investigate unexpected traffic increases.

Protection

  • Apply rate limiting where appropriate.
  • Protect applications with suitable security controls.
  • Use specialised DDoS mitigation.
  • Maintain distributed and redundant infrastructure.
  • Protect both application and network layers where required.

Response

  • Document the incident response process.
  • Define responsibilities before an attack occurs.
  • Test response procedures.
  • Review security incidents and improve defences.

No single control can protect against every DDoS attack.
Layered protection is more effective because different attacks target different infrastructure resources.

Conclusion

A DDoS attack can disrupt websites, applications, servers, and networks by overwhelming them with unwanted traffic from multiple sources. Modern attacks can also use multiple attack vectors. Some are extremely large, while others are short and highly intense.
Effective protection therefore requires more than one security control.
Traffic monitoring helps identify unusual activity. Application-level controls can protect web services. Network-level mitigation can filter large volumes of malicious traffic before they reach protected infrastructure.
Together, these layers support availability during an attack.
As online services become more important to business operations, protecting service availability remains an essential part of infrastructure planning.

Frequently Asked Questions

Can a DDoS attack be stopped?

A DDoS attack can often be mitigated. DDoS protection systems can identify malicious traffic and filter, rate-limit, or otherwise mitigate it to reduce service disruption.

Can a firewall stop a DDoS attack?

A firewall can be part of a DDoS protection strategy. However, it may not be sufficient on its own. A large volumetric attack can overwhelm available bandwidth before the traffic reaches a local firewall. Effective DDoS protection can therefore combine network filtering, application security, rate limiting, distributed infrastructure, and specialised mitigation services.

Is a DDoS attack illegal?

Launching a DDoS attack against a system without authorisation is illegal in many jurisdictions. Organisations should distinguish between authorised security testing and an actual attack. Security testing should only be performed with clear permission and within an approved scope.

What is a DDoS attack in cyber security?

In cyber security, a DDoS attack is an attack against availability. Its primary goal is to prevent legitimate users from accessing a system, service, website, application, or network. This makes DDoS protection an important part of maintaining service availability.

How long does a DDoS attack last?

A DDoS attack can last from a few minutes to several hours or longer. Some modern attacks are extremely short but highly intense.

Who can be targeted by a DDoS attack?

Any internet-facing service can be targeted. This can include websites, cloud applications, APIs, financial services, government services, enterprise networks, and other online platforms.