Categories

No categories

What are Dos and Ddos attack?

June 26, 2025
Eye23
Book7 min
Background

What is DoS attack? It is targeted interference in operation of the online service with the purpose of provoking the failure in operation and inability to correctly accept incoming traffic in the moment. In practice, it looks like this: increased traffic to a site, application, portal is provoked, which leads to complete shutdown or partial blocking of the object of attack.

How does this happen in practice? Objects on the Internet are limited in the number of visits. Let's say in the amount of 1000-2000 visitors at the moment. Hackers who use DoS attacks, initiate increased incoming traffic, increasing visits by tens, hundreds of times. The object of attack suffers from this: it stops working or provides incomplete processing of incoming target requests, which affects the quality and quantity of sales.

Targets of DoS and DDoS attacks

Typically, fraudsters have one or more DoS attack targets:

  1. complete or partial blocking of service operation and damage from unreceived clients and unprocessed requests;
  2. damage to company's business reputation and image due to failure of the main website (application, portal, online shop);
  3. creating the critical vulnerability for the purpose of further malware implementation;
  4. provoking the costs of restoring and reconstructing attacked services, the costs of creating and deploying backup systems, and so on.

The reasons for such attacks can be unfair competition, desire to temporarily take a promising project out of a game, hackers' attack, political or ideological motives, disagreement with information broadcasted on the service, masking the larger-scale intrusion into security loop, diverting the attention of IS forces from the main problem.

Victims of DDoS attacks are often web servers of well-known organisations such as banking, trading and media companies, government and trade organisations, official websites of famous media personalities and experts and so on.

History and statistics

Surprisingly enough, the first DDoS attack was recorded back in 1974 by a thirteen-year-old in the United States. David Dennis discovered the interesting fact that it was possible to make computers at the University of Illinois freeze on the certain command. He tried his discovery on 31 computers at the university, and eventually they stopped working for time.

Another interesting fact: denial-of-service attack can last for a long time. Of course, constant load and ensuring uninterrupted deployment requires a lot of resources, but if taking a competitor out of the game for a day or more is worth it – competing companies can go for it. So it's no surprise that the longest DoS attacks exceeded 329 hours and 509 hours respectively, or over 13 days and over 21 days. That's quite a lot.

By the way, you can track flow of DDoS attacks in the world and their regional distribution in real time. As you can see, most of the sources are located in densely populated developed centres. And the number of attacks being sent at a moment's notice reaches 4,785,000 units.

What is the difference between DoS and DDoS attack?

A DDoS "Distributed Denial of Service attack" is a subcategory of the more general DoS "Denial of Service attack". In DoS attack, a hacker uses a single connection to the network and uses it to make spam inputs. DDoS attacks change scale and use thousands (even millions) of connected devices, often networked together (botnets).

The effectiveness of DoS is currently extremely low. This type of deployment operates on a simple linear 1:1 principle – one threat source and one victim. In addition, single attack is quite noticeable by the contents of the log file and IP, and can be easily bought by the firewall. That's why mass DDoS attacks using botnets have recently become more popular. How do they work?

Botnets

Botnets are the primary way to execute distributed DDoS attacks. An attacker creates controlled peer-to-peer network of devices that perform malicious DDoS attacks on a victim. The number of such machines can vary: from a few dozen to hundreds of thousands. It all depends on the scale of the campaign. Malicious code fragment or malware, called a bot, is installed on a captured computer. Together, the infected computers form network called a botnet. An attacker then instructs botnet to perform simultaneous logins to the victim's device or server. This means a large number of connection requests are sent simultaneously, far exceeding the number available for processing. It's like one attack by all the bees at once (see the diagram below).

The most popular botnets today are: Storm, Zeus, Mariposa, Bredolab, Sality, Fast Flux and others. On this site, you can see the distribution of global botnet sources in real time.

The cost of DDoS attacks in 2025

Botnet service is quite affordable to purchase not only on the Darknet, but also on regular network. Depending on the amount of power purchased, the cost of the service can start at $50 and go up to several tens of thousands. So it is not difficult to use this tool as a source of unfair competition. At the same time, during DDoS attack, every minute of downtime for a small or medium-sized company brings losses that can reach several tens of thousands of dollars (depending on the size), and restoration of services and operations after the attack can cost $70,000-120,000 on average.

In 2025, application-level DDoS attacks caused more damage to online industries than any other type of attack: 131% more than the previous quarter (and 300% year-over-year).

Symptoms of the attack and how to recognise it

DDoS attacks do not have any pronounced symptoms, at the onset of which we can clearly say: "Look, we have DDoS attack". Usually speed of the service loading decreases, a site gives error 502,503,504, or it is impossible to view it, there is increase in spam, unusual content, increase in the number of simultaneous user access to the same site resources, problems with Internet connection, untargeted visitors and communication on distracted topics, and so on. It is also possible to monitor the volume of traffic on connection ports and change in direction of load on RAM and CPU, which increase in times.

Symptoms are ambiguous and do not always correspond to 100% attack on your site, network, application. However, if they appear, you should think about security.

How to deal with DoS and DDoS?

Of course, facing such threat requires defence. And against DoS and DDoS attacks there are several options to ensure Information Security:

Use network traffic monitoring systems

They will provide monitoring of traffic sources and capture abnormal spikes in network.

Firewalls

Firewall is the reverse proxy server that is installed physically between the Internet and company servers. Once installed, firewall applies to all incoming traffic the set of rules that an administrator has established in advance. Therefore, every incident that does not meet these set requirements is automatically denied.

Audit of security systems and possibly procuring white-hat DDoS hacking

Organisations should conduct regular risk assessments and audits of their devices, servers and network. Conduct periodic site response time testing to understand what is normal for you and what is already exceeded and could be triggered by attack. It is also useful to engage a white hat hacker who will trigger an attack at the most unrequested time on a site and highlight weaknesses of the security defences.

Use AI and specialised software

Artificial Intelligence tools are much more adaptive than conventional software, as they have ability to self-learn and act on the latest data. Neural networks are also used in fight against DDoS, test available forms for you. Also, don't ignore software and support services that specialise in defending against this form of exposure. Here, perhaps the best known would be Cloudflare.

Black hole routing

Another form of protection is black hole routing, in which the network administrator (or organisation's ISP) creates a route through black hole and directs traffic there. Using this strategy, all traffic, both good and bad, is directed to route zero and is effectively removed from network. This can be quite extreme as legitimate traffic is also stopped and can result in loss of business.

 

Advertisement

Explore the power of Anexet right now!

Start Free Trial