What are DDoS attacks and how can businesses protect themselves from them?


What is a DDoS attack?
A DDoS attack is an attack by malicious actors aimed at disrupting a company's infrastructure and customer services. Attackers artificially create an avalanche of requests to an online resource to increase the load and disable it.

 

By comparison, a "natural DDoS" attack can occur during seasonal sales, when online stores experience an influx of customers, are unable to cope with the load, and ultimately the service becomes intermittent or completely unavailable.

All organizations that interact with users and consumers through web resources are susceptible to such attacks: online retail and marketplaces, the financial sector, government services, telecom, online education, delivery services, social media, instant messaging, and video conferencing.

In addition to websites, hackers can attack, for example, phone numbers. In this case, the phone will receive a large number of spam calls, keeping the line busy for regular users. This type of attack is typical for small businesses involved in online food delivery, taxi services, and so on.

How DDoS attacks occur
Any equipment has a limited bandwidth and the number of requests it can process. Attacks are carried out using so-called "botnets"—computer networks running bots on devices, controlled remotely by hackers. Cybercriminals use these bots to trigger requests, which then access the targeted victim's website. Botnets can consist of infected user devices (for example, computers with viruses activated, which hackers exploit without the user's knowledge) or, for example, IoT devices: smart speakers, vacuum cleaners, and so on. A botnet can range in size from tens to hundreds of thousands of devices.

"Each computer initiates connections that are no different from the actions of legitimate clients. Taken together, all these actions can create a load that exceeds the design," adds the head of the Technical Information Security Department.

According to Vadim Solovyov, Senior Information Security Analyst at Positive Technologies, the DDoS attack service can be ordered on the darknet. It will cost around $50 per day.

What's the difference between a DoS and a DDoS?
Cybercriminals also have another type of denial-of-service attack in their arsenal: a DoS attack. Its main difference from a DDoS attack is that only a single device, not a network, is used to send requests to a website.

How to recognize a DDoS attack
Here are some signs that can help detect a DDoS attack:

suspicious traffic volumes from one or more IP addresses;

a large flow of traffic from users with a common behavioral profile, such as device type, geolocation, or web browser version;

an unexplained surge in requests for a particular page;

unusual traffic, such as a sharp increase at night.

Methods that can be used to recognize a DDoS attack include:

using a network monitoring and traffic analysis system to spot unusual patterns;

Analyzing traffic sources to determine whether it comes from regular or suspicious addresses;

Using software to automatically detect anomalies and suspicious behavior on the network.

What are the dangers of a DDoS attack?
Hackers use DDoS attacks for several reasons:

To disrupt a service, for example, to disrupt online classes or exams.
For extortion. "Hackers are sending ransom letters in bitcoin to organizations around the world and threatening a powerful and prolonged DDoS attack if they don't pay," said Alexey Kiselev, project manager at Kaspersky DDoS Protection.
As a tool to combat competitors. They are most often ordered by owners of illegal businesses, since their competitors won't report them to the police, as well as by small, niche, legitimate businesses looking to slightly improve their market position.
To distract attention, so that during an attack they can inject ransomware and/or steal corporate information.
The attackers' goal is to disable an online resource and make it inaccessible to the end user.

These actions pose two threats to the commercial sector:

loss of profits;
reputational damage.

How to Protect Against DDoS Attacks
The primary protection method is filtering traffic based on its content, IP addresses, and other parameters. This can be implemented in two ways:

Install your own server and software. This approach allows you to be independent of third parties and fully control your infrastructure, customizing everything to your needs. "The installed equipment allows you to analyze all network requests to the service and filter out suspicious requests," explains Tsypko.
Purchase DDoS protection as a service from a third-party company. This approach allows you to reduce the cost of maintaining your own equipment and eliminates the need to hire specialized security specialists in-house. External anti-DDoS services can be activated or deactivated at any time. This protection method has become increasingly popular over the past five years. Such services are offered, for example, by most providers (hosting, internet) or specialized organizations.
Attacks can occur due to vulnerabilities in an organization's system components, so it is essential to regularly update your system.

Companies also need to ensure that their corporate websites and IT resources are capable of handling large volumes of traffic.


Go back
19-09-2025, 06:00