DDoS Attack
An attack that overwhelms a service with traffic from many sources at once so legitimate users cannot reach it.
Definition
A distributed denial-of-service (DDoS) attack floods a website, application or network with traffic from many compromised machines simultaneously, exhausting its capacity so that legitimate requests cannot be served.
The word distributed is the important part. A single machine sending excessive requests is easy to identify and block. A DDoS attack sends traffic from thousands of sources at once, often a botnet of compromised devices, which makes filtering far harder because there is no single origin to cut off.
Attacks operate at different layers. Volumetric attacks simply consume bandwidth. Protocol attacks exhaust connection state on servers or load balancers. Application-layer attacks send requests that look legitimate but are expensive to serve, such as repeated searches, and these are the hardest to distinguish from real users.
DDoS is frequently confused with phishing, and the two are entirely different. DDoS attacks availability: it stops people reaching a service. Phishing attacks people: it deceives them into handing over credentials or money. A DDoS attack does not steal data, though it is sometimes used as a distraction while another intrusion proceeds.
At a glance
- Severity
- High for availability, low for confidentiality
- Prevalence
- Very common against public-facing services
- Primary targets
- Public websites, APIs, payment gateways, government portals
How it works
- 1
Build or rent capacity: the attacker assembles a botnet of compromised devices, or pays for access to one
- 2
Select a target and layer: bandwidth, protocol state, or an expensive application endpoint
- 3
Amplify where possible: misconfigured third-party services are abused to multiply traffic volume
- 4
Launch simultaneously so that capacity is exhausted faster than defences can adapt
- 5
Sustain or pulse: some attacks run continuously, others come in short bursts to evade automatic mitigation
Warning signs
- A sudden traffic spike with no matching business event or campaign
- Traffic concentrated on one expensive endpoint rather than spread across the site
- Requests from a wide spread of geographies that does not match your normal user base
- An extortion message demanding payment to stop or prevent an attack
- Unusual support or IT calls during the outage, which may be social engineering exploiting the confusion
How to defend
- Put a DDoS mitigation or CDN layer in front of public services rather than absorbing traffic at origin
- Rate-limit and cache expensive endpoints so application-layer floods are cheaper to serve
- Keep a runbook that names who declares an incident and who contacts the provider
- Rehearse the outage scenario, including how staff verify identity when normal systems are unavailable
- Never pay an extortion demand; it funds the next attack and does not guarantee it stops
Real-world example
An Indonesian bank's mobile banking gateway is flooded during a payroll weekend, with traffic aimed at the login endpoint. While the operations team works on mitigation, a caller reaches a branch employee claiming to be from the platform vendor and asks them to disable a control to help recovery. The outage was real; the call was the actual attack.
How Claro helps
Claro does not mitigate DDoS, which is a network and infrastructure control. It addresses the adjacent human risk: attackers often pair a disruption with social engineering, calling staff during an outage while posing as IT or a vendor, because people are more willing to bypass process when systems are already broken.
Frequently asked questions
What is a DDoS attack?
A distributed denial-of-service attack floods a service with traffic from many compromised machines at once, exhausting its capacity so legitimate users cannot reach it. The distributed nature is what makes it hard to filter.
What is the difference between DDoS and phishing?
They target different things. DDoS attacks availability by making a service unreachable. Phishing attacks people by deceiving them into giving up credentials or money. DDoS does not steal data, although it is sometimes used as a distraction during another intrusion.
What is the difference between DoS and DDoS?
A DoS attack comes from a single source and is relatively easy to block. A DDoS attack is distributed across many sources simultaneously, so there is no single origin to cut off.
Can staff awareness training prevent DDoS?
Not directly, because DDoS mitigation is an infrastructure control. Awareness matters for the adjacent risk: attackers frequently use the confusion of an outage to social-engineer staff into bypassing normal verification.
Related terms
Botnet
A network of compromised devices controlled remotely by an attacker and used to carry out attacks at scale.
Malware
Any software intentionally designed to damage, disrupt, or gain unauthorized access to a device or network.
Incident Response
The structured process an organization follows to detect, contain, investigate, and recover from a security incident.
Business Continuity Plan
A documented plan for keeping essential operations running during and after a disruption.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo