
What Is a DDoS Attack? Definition, Examples, and Prevention
You’ve probably seen the headlines: a major website goes dark, taken down by a “DDoS attack.” For a small online shop, the reality is that these attacks can hit anyone and the consequences can be devastating.
Largest recorded attack: 2.3 Tbps (2020 AWS) ·
Average attack duration: 4 hours ·
Percentage of organizations hit: 33% (2023 survey) ·
Most common attack vector: UDP flood (over 50%) ·
Cost per minute for targeted business: $20,000 (est.)
Quick snapshot
- DDoS attacks are illegal in most countries (CISA (U.S. Cybersecurity and Infrastructure Security Agency))
- Botnets are a primary tool for launching DDoS (UK NCSC (National Cyber Security Centre))
- The largest recorded attack reached 2.3 Tbps (Corero (DDoS mitigation vendor))
- Exact total cost of DDoS attacks annually
- True number of unreported attacks
- Effectiveness of all mitigation techniques in real-time
- 1999: First DDoS tools like Trin00 appear (Corero (DDoS mitigation vendor))
- 2016: Mirai botnet DDoS against Dyn DNS provider (Corero (DDoS mitigation vendor))
- 2020: AWS mitigates 2.3 Tbps DDoS attack (Corero (DDoS mitigation vendor))
- Continued rise in application-layer attacks (UK NCSC (National Cyber Security Centre))
Five key facts define the landscape of DDoS attacks, one pattern: the threat is widespread, costly, and increasingly targeting smaller organizations.
| Fact | Value |
|---|---|
| Full name | Distributed Denial of Service |
| First major attack | 1999 (Trin00 tool) |
| Attack vector | Volume, protocol, application layer |
| Primary motivation | Disruption, extortion, hacktivism |
| Legal status | Illegal in most jurisdictions |
What is a DDoS attack?
How does a DDoS attack work?
- It uses multiple compromised systems (CISA (U.S. Cybersecurity and Infrastructure Security Agency))
- Goal is to overwhelm targets with traffic (UK NCSC (National Cyber Security Centre))
- Disrupts normal traffic (Canadian Centre for Cyber Security (government agency))
Think of a DDoS attack like a traffic jam deliberately created by thousands of cars flooding a single highway exit. The attackers take control of many devices — often computers, routers, or IoT gadgets — forming a botnet. Each device sends requests to the target, overwhelming its capacity. The result: legitimate visitors can’t get through.
What makes DDoS particularly tricky is that the traffic often looks identical to normal requests. The Canadian Centre for Cyber Security (government agency) notes that the primary challenge in mitigation is distinguishing legitimate traffic from malicious traffic.
What is the difference between DoS and DDoS?
- DoS (Denial of Service) comes from a single source (UK NCSC (National Cyber Security Centre))
- DDoS comes from many sources (distributed)
- DDoS is harder to block because the traffic arrives from multiple IPs
The table below highlights the key differences between the two attack types.
| Feature | DoS | DDoS |
|---|---|---|
| Source | Single source | Multiple sources (distributed) |
| Traffic origin | Single IP address | Many IP addresses |
| Difficulty to block | Easier to block via IP | Harder to block due to distributed nature |
A DoS attack is like one person blocking a door. A DDoS attack is like a mob. The distributed nature makes DDoS attacks far more potent and difficult to trace. The CISA (U.S. Cybersecurity and Infrastructure Security Agency) emphasizes that organizations should prepare for DDoS incidents specifically because of the scale and complexity.
The pattern: DDoS attacks are a serious threat that can affect any business, regardless of size. Proactive measures are essential.
What can a DDoS attack do?
What are the consequences of a DDoS attack?
- Disrupts normal traffic (UK NCSC (National Cyber Security Centre))
- Can cause financial loss (Corero (DDoS mitigation vendor))
- May lead to reputational damage (A10 Networks (security vendor))
Can a DDoS attack cause data loss?
- DDoS attacks themselves do not typically steal data (CISA (U.S. Cybersecurity and Infrastructure Security Agency))
- But they can expose vulnerabilities used for other attacks
- Secondary data breaches may occur during the chaos
While a DDoS attack is primarily a disruption tool, it can be a smoke screen for more dangerous activities. The Canadian Centre for Cyber Security (government agency) advises organizations to watch for signs of data exfiltration during a DDoS event. The real damage often comes from what attackers do while you’re distracted.
Small businesses face a brutal choice: pay for robust DDoS protection or risk losing everything in a single attack. The Canadian Centre for Cyber Security (government agency) recommends a risk assessment that identifies critical assets and the likely impact of an attack.
Is a DDoS attack illegal?
What are the laws against DDoS attacks?
- DDoS is illegal in most countries (CISA (U.S. Cybersecurity and Infrastructure Security Agency))
- Penalties include fines and imprisonment (UK NCSC (National Cyber Security Centre))
- Botnet herders are prosecuted
In the United States, the Computer Fraud and Abuse Act (CFAA) and similar laws in other countries make DDoS attacks a federal crime. The CIsa (U.S. Cybersecurity and Infrastructure Security Agency) notes that launching a DDoS attack is a serious offense. The UK NCSC (National Cyber Security Centre) confirms that the Computer Misuse Act covers such attacks in the UK.
Can you go to jail for DDoS?
- Yes, perpetrators face prison sentences (UK NCSC (National Cyber Security Centre))
- Sentences vary by country and severity of damage
- Even minor attacks can lead to prosecution
There have been high-profile cases where individuals received multi-year prison sentences for launching DDoS attacks. The CIsa (U.S. Cybersecurity and Infrastructure Security Agency) emphasizes that the consequences are serious, even for “script kiddies” using pre-built tools.
For small business owners, knowing that DDoS is illegal means you have legal recourse if you’re attacked. But it also means you should never consider using a DDoS attack against a competitor, no matter how frustrating the situation. The UK NCSC (National Cyber Security Centre) advises that retaliation is both illegal and counterproductive.
The pattern: DDoS laws are clearly defined, but enforcement is challenging because attacks often originate from botnets spread across multiple countries.
How long do DDoS attacks usually last?
What factors affect attack duration?
- Attack size and complexity
- Mitigation speed and effectiveness (Canadian Centre for Cyber Security (government agency))
- Attacker motivation and resources
The average DDoS attack lasts about 4 hours, according to industry data. But some can stretch for days. The Canadian Centre for Cyber Security (government agency) notes that mitigation speed varies depending on the defenses in place. Organizations with a tested response plan can often stop an attack within minutes, while unprepared businesses may suffer extended downtime.
Can attacks last for days?
- Yes, some attacks last multiple days (Corero (DDoS mitigation vendor))
- Persistent attacks often target critical infrastructure
- Attackers may use new techniques to prolong the assault
In 2020, one attack on a European bank lasted over 200 hours. The UK NCSC (National Cyber Security Centre) advises that the best defense is to have a comprehensive response plan that includes communication with your ISP and a DDoS mitigation service.
What this means: Attack duration depends on preparation, and small businesses should plan for the worst.
Can you stop a DDoS attack?
How to prevent DDoS attacks?
- Use DDoS mitigation services (CISA (U.S. Cybersecurity and Infrastructure Security Agency))
- Implement rate limiting (Canadian Centre for Cyber Security (government agency))
- Monitor traffic anomalies (Canadian Centre for Cyber Security (government agency))
- Prepare an incident response plan (UK NCSC (National Cyber Security Centre))
Stopping a DDoS attack requires a combination of preparation and real-time response. The CISA (U.S. Cybersecurity and Infrastructure Security Agency) says organizations should prepare for DDoS incidents by having a response plan, identifying critical assets, and considering third-party protection services. The Canadian Centre for Cyber Security (government agency) recommends rate limiting, web application firewalls, continuous monitoring, anycast network diffusion, and DDoS response planning as core defenses.
What are DDoS mitigation services?
- Cloud-based services that filter traffic (CISA (U.S. Cybersecurity and Infrastructure Security Agency))
- Can be expensive but some offer free tiers
- Examples: Cloudflare, Akamai, AWS Shield
For small businesses, cost is a major barrier. However, some providers offer free plans that provide basic protection. The UK NCSC (National Cyber Security Centre) advises that even small steps — like using a firewall, keeping software updated, and having a business continuity plan — can significantly reduce the risk.
Small businesses don’t need enterprise budgets to defend against DDoS. The Canadian Centre for Cyber Security (government agency) explicitly recommends using multifactor authentication, keeping devices updated, and using trusted anti-malware tools alongside DDoS-specific controls. A layered approach is affordable and effective.
What this means: You can stop a DDoS attack, but it requires proactive investment. For small businesses, the cheapest defense is a well-prepared response plan and a basic mitigation service.
What are the largest DDoS attacks in history?
What was the 2016 Dyn attack?
- Used IoT botnets (Mirai) (Corero (DDoS mitigation vendor))
- Took down major sites like Twitter, Reddit, Netflix
- Exposed the vulnerability of IoT devices
The 2016 Dyn attack was a turning point. It demonstrated how millions of unsecured IoT devices — cameras, routers, DVRs — could be weaponized into a massive botnet. The attack disrupted internet services across the U.S. and Europe.
How big was the 2020 AWS attack?
- Reached 2.3 Tbps (Corero (DDoS mitigation vendor))
- Mitigated by AWS Shield
- Largest recorded DDoS attack to date
In 2020, Amazon Web Services mitigated a 2.3 Tbps DDoS attack, the largest ever recorded. The attack used a technique called CLDAP reflection. The fact that AWS could absorb such a massive flood shows how powerful cloud-based mitigation has become.
GitHub attack in 2018
- 1.35 Tbps memcached amplification (Corero (DDoS mitigation vendor))
- Lasted about 20 minutes
- Demonstrated the power of amplification attacks
GitHub was hit by a 1.35 Tbps attack in 2018, but it only lasted about 20 minutes thanks to its use of an automated mitigation service. The Corero (DDoS mitigation vendor) notes that the attack exploited memcached servers to amplify traffic by a factor of 50,000.
Timeline of major DDoS events
- 1999: First DDoS tools like Trin00 appear (Corero (DDoS mitigation vendor))
- 2000: Mafiaboy attacks major websites (CNN, Yahoo) (Corero (DDoS mitigation vendor))
- 2016: Mirai botnet DDoS against Dyn DNS provider (Corero (DDoS mitigation vendor))
- 2018: GitHub hit by 1.35 Tbps memcached amplification (Corero (DDoS mitigation vendor))
- 2020: AWS mitigates 2.3 Tbps DDoS attack (Corero (DDoS mitigation vendor))
- 2023: Continued rise in application-layer attacks (UK NCSC (National Cyber Security Centre))
What we know and what we don’t
Confirmed facts
- DDoS attacks are illegal in many countries (CISA (U.S. Cybersecurity and Infrastructure Security Agency))
- The largest recorded attack reached 2.3 Tbps (Corero (DDoS mitigation vendor))
- Botnets are a primary tool for launching DDoS (UK NCSC (National Cyber Security Centre))
What’s unclear
- Exact total cost of DDoS attacks annually
- True number of unreported attacks
- Effectiveness of all mitigation techniques in real-time
- More automated mitigation tools for small businesses
- Increased legal pressure on botnet operators
The implication: Understanding what is known and unknown helps small businesses prioritize their defenses.
Expert perspectives on DDoS
“A DDoS attack is a malicous attempt to disrupt normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic.”
CISA (U.S. Cybersecurity and Infrastructure Security Agency)
“Successful denial-of-service attacks can make a targeted system unreliable or unresponsive to users.”
UK NCSC (National Cyber Security Centre)
“The primary challenge in mitigating DDoS attacks is distinguishing legitimate traffic from malicious traffic.”
Canadian Centre for Cyber Security (government agency)
The pattern: Expert advice consistently emphasizes preparation and layered defenses.
For small businesses, the message is clear: DDoS attacks are a real and growing threat, but you don’t have to be helpless. The UK NCSC (National Cyber Security Centre) advises organizations to understand their service, understand their defences, create a response plan, and test the response. The Canadian Centre for Cyber Security (government agency) adds that a risk assessment that identifies critical assets, relevant threats, vulnerabilities, and the likely impact and likelihood of attack is the foundation of any defense. For the small business owner in any market, the choice is clear: invest in basic DDoS protection now, or risk paying far more in downtime and recovery later.
For more on staying safe online, check out our report on Gmail Passwords Exposed in Data Leak: Act Now.
valuealigners.com, fractionalciso.com, reddit.com, sentinex.com, ico.org.uk, business.comcast.com, a10networks.com
Frequently asked questions
What is the purpose of a DDoS attack?
The purpose is to disrupt the availability of a targeted service, often for extortion, hacktivism, competitive sabotage, or vandalism. The CISA (U.S. Cybersecurity and Infrastructure Security Agency) notes that attackers may also use DDoS as a distraction for other malicous activities.
What is a DDoS attack in cyber security?
In cyber security, a DDoS attack is a type of denial-of-service attack where multiple compromised systems are used to target a single system, causing a denial of service for users of the targeted resource. The UK NCSC (National Cyber Security Centre) defines it as a malicous attempt to make a server or network resource unavailable.
Is a DDoS attack dangerous?
Yes, it can be dangerous. It can cause significant financial loss, reputational damage, and even data loss if used as a distraction. The Canadian Centre for Cyber Security (government agency) warns that a DDoS attack can create cascading consequences including recovery costs.
What is a DDoS attack vs DoS attack?
A DoS attack comes from a single source, while a DDoS attack comes from multiple sources. The UK NCSC (National Cyber Security Centre) explains that DDoS is harder to mitigate because the traffic arrives from many different IP addresses.
Can a DDoS attack be traced?
Tracing a DDoS attack is difficult because the traffic comes from a botnet of compromised devices spread across many countries. The CISA (U.S. Cybersecurity and Infrastructure Security Agency) notes that attribution is complex and often requires cooperation across jurisdictions.
How common is DDoS today?
DDoS attacks are very common. According to a 2023 survey, 33% of organizations reported being hit by a DDoS attack. The UK NCSC (National Cyber Security Centre) reports that the number of attacks continues to rise, especially application-layer attacks.
Why do DDoS attacks exist?
They exist because they are relatively easy to launch and can be very effective. Attackers use them for extortion, hacktivism, competitive sabotage, or simply for fun. The Corero (DDoS mitigation vendor) notes that the rise of botnets-for-hire has made DDoS accessible to anyone with a small amount of money.