Differences between DDoS and DDOS attacks
The development of DDoS attacks was preceded by DOS: a simplified version of the attack that blocks user access to a resource by generating an excessive number of requests.
The first recorded DOS attack occurred almost half a century ago, in 1974. It was initiated by high school student David Dennis. Using a vulnerability he discovered in terminals to the EXT command, he disabled 31 terminals at the University of Illinois Computing Laboratory.
For nearly half a century, DOS attacks have ceased to be a threat due to their weak characteristics:
The attack is carried out from a single network, most often from a single host.
A DOS attack is easy to detect; its contents are revealed by log file content.
DOS attacks are not only easy to detect, but also to suppress. To protect against DOS attacks, it is sufficient to block a single source.
For these reasons, DOS attacks are practically never encountered in the wild. Resisting them requires little knowledge or technical resources. However, they are also present in educational systems, as part of training in the basics of DDoS and denial of service issues in general.
DDoS attacks have replaced denial-of-service (DoS) attacks: they offer the same advantages, but are much more difficult to block. The main difference is the ability to involve a larger number of devices and users. Such a decentralized attack is more difficult both to detect and to counter.
DDoS: General Trend
This year, the geopolitical crisis has significantly impacted hacker activity. First and foremost, it's worth noting the increase in the number of cyberattacks. For example, according to Kaspersky Lab, the number of attacks in March was eight times higher than the number during the same period last year.
Another important trend is the increasing "weight" of attacks, or their power. In mid-August, Google reported repelling the most powerful attack in history. To understand its scale, just look at the graph of incoming requests.
Attacks of this scale became possible thanks to the development of botnets. A botnet is a network of infected devices that attackers use in DDoS attacks. However, detecting a device's infection is quite difficult: the malware only manifests itself during a cyberattack and remains dormant the rest of the time, having virtually no impact on the computer's performance.
Hacker activism has also become unprecedentedly widespread this year. For example, the KillNet and NoName057(16) groups carried out a series of cyberattacks on Estonian companies and government agencies in response to calls from several local politicians to restrict entry of Russians into EU countries.
Moreover, as recent experience has shown, hackers themselves can also become victims of DDoS attacks. Hackers from the LockBit group began blackmailing the company Entrust after a successful attack. However, instead of receiving money, they received a powerful DDoS attack on their own resources.
The attack logs contained calls for hackers to delete data related to Entrust. The effectiveness of such countermeasures is difficult to predict at this time, as much will depend on further developments. However, the very fact of using a DDoS attack to combat hackers is a precedent.

Spain
Portugal


