Distributed denial-of-service (DDoS) attacks have become one of the most frequent and devastating threats in today's cybersecurity landscape. According to the latest industry reports, the volume of DDoS attacks has grown by more than 300% over the past five years, and they no longer target only large corporations: SMEs, online shops, hospitals and public administrations are regular targets.
A DDoS attack can take down a website, an API or an entire infrastructure for hours or days, causing direct financial losses, reputational damage and, in critical sectors, serious operational consequences. The good news is that, with a proper defence architecture, the vast majority of DDoS attacks can be effectively mitigated.
In this article we explain what a DDoS attack is, what types exist, which have been the most notable incidents, how they impact businesses depending on their size and which mitigation techniques are most effective. We also analyse the security policy and the layers of protection that EasyDataHost implements for its customers.
What Is a DDoS Attack
A DDoS (Distributed Denial of Service) attack consists of flooding a server, network or service with such a high volume of malicious traffic that the target's resources become saturated and stop responding to legitimate requests. Unlike a simple DoS attack (from a single source), a DDoS is launched from thousands or millions of compromised devices forming a botnet, making it extremely difficult to block the attacking traffic without affecting real traffic.
Attackers rent botnets on the dark web for prices that can be as low as 50 dollars per hour, which democratises this type of threat and puts it within reach of unfair competitors, hacktivists or extortion groups. The objective can be financial (demanding a ransom to stop the attack), competitive (taking down a rival's service), ideological or simply destructive.
To understand how to protect yourself, it is essential to know the different types of DDoS attacks and at which layer of the OSI model they operate, since each type requires a different mitigation strategy. Cloudflare provides a comprehensive technical reference on this topic.
Types of DDoS Attacks
DDoS attacks are classified into three broad categories based on the OSI model layer they exploit:
- flood Volumetric attacks (layer 3/4): their goal is to saturate the target's bandwidth by sending massive amounts of data. They include UDP flood, ICMP flood and amplification attacks (DNS amplification, NTP amplification, memcached). A DNS amplification attack can multiply traffic by 50x: the attacker sends small requests with the victim's IP as the sender, and DNS servers respond with much larger packets directly to the victim.
- swap_vert Protocol attacks (layer 3/4): these exploit weaknesses in network protocols to exhaust the resources of intermediary devices (firewalls, load balancers, servers). The best known is the SYN flood, which sends millions of SYN packets without completing the TCP handshake, filling the server's connection table. They also include Ping of Death, Smurf attack and IP fragmentation attacks.
- language Application layer attacks (layer 7): these are the most sophisticated and hardest to detect because they mimic legitimate traffic. HTTP flood sends thousands of HTTP GET or POST requests that appear normal but saturate the web server's or database's processing capacity. Slowloris keeps thousands of HTTP connections open by sending incomplete headers. These attacks consume less bandwidth but are devastating in terms of CPU and memory load.
Key concept:
Modern attacks often combine multiple vectors simultaneously (multi-vector DDoS), launching volumetric attacks to saturate bandwidth while executing layer 7 attacks to overload the application. An effective defence must cover all layers.
Famous DDoS Incidents
The history of DDoS attacks is marked by incidents that have highlighted the vulnerability of infrastructures thought to be invulnerable:
- warning Dyn attack (2016): the Mirai botnet, composed of compromised IoT devices, launched a massive attack against DNS provider Dyn that left services such as Twitter, Netflix, Spotify and Reddit inaccessible for hours. It demonstrated that unpatched IoT devices are a critical attack vector.
- warning GitHub (2018): suffered a 1.35 Tbps memcached amplification attack, the largest recorded at the time. The attack was mitigated in under 20 minutes thanks to automated DDoS protection.
- warning AWS (2020): Amazon reported mitigating a 2.3 Tbps CLDAP reflection attack, setting a new record. The scale of these attacks continues to grow year on year.
- warning Google (2023): Google Cloud mitigated an HTTP/2 Rapid Reset attack of 398 million requests per second, the largest documented layer 7 attack. It demonstrated that protocol vulnerabilities can dramatically amplify application-layer attacks.
Impact by Company Size
The impact of a DDoS attack varies significantly depending on the size and nature of the affected organisation:
| Size | Estimated loss/hour | Primary impact | Average recovery time |
|---|---|---|---|
| SME / Startup | 500 - 5,000 EUR | Lost online sales, disproportionate reputational damage | 4 - 24 hours |
| Mid-size company | 5,000 - 50,000 EUR | Operations disruption, breached client SLAs | 2 - 12 hours |
| Large enterprise | 50,000 - 500,000 EUR | Massive revenue loss, stock market impact, regulatory fines | 1 - 6 hours |
| Critical infrastructure | Incalculable | Public health risk, national security, essential services | Variable |
DDoS Mitigation Techniques
There is no single solution to mitigate all types of DDoS attacks. An effective strategy combines multiple techniques operating at different layers:
- filter_alt Rate limiting: restricts the number of requests a source can send within a time interval. Effective against simple layer 7 attacks, but insufficient on its own against distributed attacks with many source IPs.
- dns Anycast and CDN: distributes traffic across multiple geographic points of presence (PoPs). An attack that would overwhelm a single server is diluted across dozens of nodes. Additionally, malicious traffic is absorbed at the edge, far from the origin server.
- cleaning_services Scrubbing centres: traffic cleaning centres that analyse all incoming traffic, filter out malicious packets and forward only legitimate traffic to the destination server. They are the primary defence against large-scale volumetric attacks.
- shield WAF (Web Application Firewall): inspects HTTP/HTTPS traffic at the application level and blocks known attack patterns. Essential against HTTP flood, Slowloris and attacks exploiting specific application vulnerabilities.
- block Blackholing and BGP flowspec: in extreme attacks, traffic to the targeted IP is redirected to a "black hole" (null route) at the network level. BGP flowspec allows granular filters to be applied directly on upstream routers without affecting the rest of the infrastructure.
Layers of Defence: Defence-in-Depth Model
DDoS defence must be implemented across multiple layers, following the defence in depth principle. Each layer filters a percentage of malicious traffic, so that if one layer fails or becomes saturated, the next absorbs the impact:
- looks_one Layer 1 - Upstream network (ISP/transit): traffic filtering at the backbone level using ACLs, BGP flowspec and selective blackholing. Stops volumetric attacks before they reach the datacentre network.
- looks_two Layer 2 - Edge / Scrubbing: cleaning centres or cloud DDoS services that analyse, classify and filter traffic before forwarding it to the origin server. They operate with absorption capacities of hundreds of Gbps or Tbps.
- looks_3 Layer 3 - Perimeter firewall: stateful network firewalls with rate limiting per IP/subnet, protocol anomaly detection (SYN cookies, TCP validation) and real-time updated IP reputation lists.
- looks_4 Layer 4 - Application (WAF + rate limiting): deep HTTP/S traffic inspection, challenge-response (CAPTCHA, JS challenge), per-session rate limiting and blocking of layer 7 attack patterns.
On-Premise vs Cloud Mitigation
Organisations can implement DDoS mitigation with their own equipment (on-premise) or through cloud services. Each approach has advantages and drawbacks:
On-premise mitigation uses physical appliances (high-performance firewalls, IPS/IDS) installed in the datacentre. It offers full control over configuration and low latency for legitimate traffic, but has an absorption capacity limited to the bandwidth of the network links. Against volumetric attacks that exceed the link capacity (10 Gbps, 100 Gbps), on-premise equipment is ineffective because the traffic saturates the connection before reaching the appliance.
Cloud mitigation redirects traffic through a global network of scrubbing centres with absorption capacity of several Tbps. It is the only viable defence against large-scale volumetric attacks, but it adds latency to legitimate traffic and creates dependency on an external provider. The hybrid approach combines both: on-premise appliances for routine filtering and automatic escalation to cloud scrubbing when an attack is detected that exceeds local capacity.
Practical recommendation:
For most businesses, a hybrid model with DDoS protection integrated into the infrastructure provider and WAF at the application level offers the best balance between cost, latency and absorption capacity. This is the approach EasyDataHost implements by default.
DDoS Protection Architecture
A robust DDoS protection architecture combines prevention, detection and automated response. Key components include:
- monitoring Continuous monitoring: 24/7 monitoring systems that analyse traffic patterns in real time, establish normal behaviour baselines and detect anomalies indicative of an incipient attack before it reaches its peak.
- autorenew Automated response: automated runbooks that activate defences in stages according to attack severity. From dynamic rate limiting to cloud scrubbing activation, without human intervention for attacks with known patterns.
- diversity_3 Network redundancy: multiple transit providers, multiple uplinks and the ability to redirect traffic through alternative routes. If one link becomes saturated, legitimate traffic is routed through another provider automatically.
- description Incident response plan: documented procedures that define roles, communication channels, escalation criteria and remediation steps. Response time during a DDoS depends directly on how well prepared the team is.
Common Mistakes in DDoS Protection
Many organisations believe they are protected against DDoS attacks when in reality they have critical gaps in their defence. These are the most frequent mistakes:
- error Relying solely on the firewall: a conventional firewall is not designed to absorb volumetric attacks. In fact, the firewall itself can become the bottleneck if its session table is saturated.
- error Having no response plan: discovering you have no DDoS protection in the middle of an attack is too late. Activating emergency mitigation services can take hours, during which the service remains down.
- error Ignoring the application layer: many companies protect against volumetric attacks but do not implement WAF or rate limiting at the HTTP level. Layer 7 attacks are increasingly common and can take down a server with little bandwidth. Directly related to the risks explained in our article on ransomware dangers.
- error Not testing defences: controlled DDoS attack simulations allow you to verify that protection layers work correctly and that the team knows how to react. Without regular testing, defences may fail when they are needed most.
DDoS Protection at EasyDataHost
EasyDataHost integrates DDoS protection as a fundamental part of its network infrastructure, not as an additional service at extra cost. All dedicated servers, cloud and managed services include DDoS protection enabled by default with the following layers:
- check_circle Automatic upstream filtering: real-time anomaly detection at the backbone level with automatic scrubbing activation against known attack patterns.
- check_circle Multiple transit providers: connectivity redundancy that allows traffic redirection and attack vector isolation without affecting service.
- check_circle 24/7 monitoring: a managed services team with continuous vigilance that identifies and responds to attacks in minutes, not hours.
- check_circle Availability SLA: our service level agreement covers network availability even during active DDoS attacks.
Conclusion
DDoS attacks are a real, growing threat that is increasingly accessible to attackers. No organisation connected to the Internet is exempt from being a target. However, with a defence-in-depth architecture, continuous monitoring and an infrastructure provider that integrates native DDoS protection, the impact can be drastically reduced or completely neutralised.
- arrow_right DDoS attacks saturate resources through massive traffic from distributed botnets.
- arrow_right There are three main types: volumetric, protocol and application layer.
- arrow_right Effective defence requires multiple layers: upstream, scrubbing, firewall and WAF.
- arrow_right The hybrid model (on-premise + cloud) offers the best cost/protection balance.
- arrow_right EasyDataHost includes native DDoS protection across its entire infrastructure with 24/7 monitoring.
If you need professional DDoS protection for your infrastructure, contact our team to design the mitigation strategy that best fits your requirements.