What is a DDoS attack?
A DDoS attack floods a website or online service from many devices at once until real users cannot get through. How it works and how to prepare.
A denial-of-service (DoS) attack floods a website or other online service with traffic until it slows down or stops, so that real users cannot get through. A distributed denial-of-service (DDoS) attack is the same thing done from many devices at once.
How it works
Every online service can handle only so much: so many connections, so much data, so much processing. An attacker sends more data, connections or requests than the service can cope with. Genuine visitors are then stuck behind the junk.
Spreading the attack across many sources produces more traffic. It also makes the attack harder to block, because the unwanted traffic is difficult to tell apart from real visitors.
Where the traffic comes from
Usually from a botnet, which is a group of internet-connected devices that an attacker has taken over. Many are household and office gadgets such as smart TVs, security systems and routers, often still on their default passwords. The owners rarely know.
The Australian Signals Directorate (ASD) reports that people who build botnets may rent or sell them to others. Carrying out an attack therefore takes little skill.
What it does to a business
The target can be a website, email, or the DNS service that tells the internet where your website and email live. ASD says most attacks are carried out to cost an organisation productivity and money, or to gain public attention for a cause.
The harm is lost availability. An online shop cannot take orders and staff cannot use the systems they need. You may also be caught by an attack on someone else: if your internet provider or cloud host is the target, your service goes down with theirs.
From the inside, an attack looks like an ordinary fault: a slow network, or a website that will not load. Monitoring that alerts someone when traffic is far above normal is how you tell the difference.
How to prepare
ASD is plain that an organisation cannot avoid being targeted, and that responding without preparation is difficult and less effective. Its guidance starts with a business question, then moves to the practical steps.
- Decide which online services must stay up during an attack, and which could be offline for a while.
- Ask your web host and internet provider what protection they include, whether it works automatically, what it costs during an attack and how to reach them after hours.
- Put a content delivery network or a DoS mitigation service in front of an important website. These absorb and filter traffic before it reaches your server.
- Keep a simple, static version of the website ready to switch to.
- Set up monitoring and alerts for availability and traffic.
- Add DoS attacks to your incident response plan, with contact details that work when email is down.
Do not be part of someone else’s attack
Your own devices can be recruited into a botnet. Change default passwords on routers, cameras and other connected equipment, and keep them updated. When should you replace your business router? explains what to do when the maker stops updating one.
If the website went down tomorrow, How much downtime could your business afford? helps you put a number on it. Putting the protection in place is part of our firewall and network security service.