TERM · SECURITY

DDoS attack

What is a DDoS attack?

A DDoS attack tries to take a site down by having thousands of machines flood it with requests until the server stops answering real visitors. It steals nothing; it stops sales. Network-level floods fill the pipe with volume, while application-level ones imitate ordinary people on the most expensive pages: search, filters, basket, login. The defence has to be arranged in advance, because during an attack it is too late.

Example

A shop sells about €1,200 a day, roughly €50 an hour. On a Thursday afternoon the site stops opening. The logs show some 20,000 different addresses requesting the search page six times a minute each: around 2,000 requests a second against a server that handles twenty on a busy day. The site is unreachable for six hours, which is about €300 of lost sales plus the advertising that kept running and kept being charged.

The two kinds look different on the invoice:

  • Network flood. It fills the pipe with volume and has to be stopped before your server, by the host or by the network in front of it.
  • Application flood. Small in volume, expensive per request. A thousand search queries a second cost more than a million requests for one cached image.

On shared hosting a third thing usually happens as well: the provider suspends your account to protect the other sites on the server. Changing your defences mid-attack does not help either, since moving a domain alone takes hours.

Why it matters for a business

Attacks arrive at the most visible moment: a campaign, Black Friday, a television slot. Extortion emails come with them, usually after a short demonstration; paying does not stop the next wave and often orders it. The difference between six hours and six minutes is preparation: anonymous traffic served from cache, rate limits on the expensive pages, and a network in front of the site that can absorb volume. Several content delivery networks include that protection on every plan.

What to ask

  • What does the host cover during an attack, and at what point does it suspend your account?
  • Is the server’s real address visible, and does it accept requests from outside the network in front of it?
  • How much of the site is served from cache without waking the application and the database?
  • Are there rate limits on search, login, basket and the API?
  • Who switches on the heightened protection at two in the morning, and on which phone number?

The weak end is usually visible in advance, through website security testing and a stress test that shows how many requests a second the site takes before it starts refusing them.

A term you do not recognise? Write to us and we will add it.

The glossary grows with the questions we are asked.