DDoS attacks: what they are and how to protect yourself from them


Hackers intentionally disable online services using DDoS attacks. This can affect companies of any size, causing irreparable consequences—loss of money, customers, and reputational damage. Cyberattacks can be especially devastating for online stores and media outlets. We explore how cybercriminals use virus-infected computers to attack online resources and how to protect against hackers in 2025.

 

What is a DDoS attack in simple terms?
DDoS stands for Distributed Denial of Service. This is a situation in which a server or online resource is overloaded with artificial traffic from multiple devices. As a result, the site becomes unavailable. This is precisely what scammers are after. Such attacks can be paid for or carried out to obtain payment for terminating fake requests.

A website can also be taken down unintentionally if it suddenly attracts a large number of users. This can occur when a link to a website is published on a popular resource, causing a slashdot effect. This quickly collapses the system if the server isn't designed to handle such volumes of traffic.

However, DDoS attacks are most often malicious.

History of DDoS Attacks
DDoS attacks have become popular since 2011, when the hacker group Anonymous began using DDoS attacks to target businesses and governments. One well-known example was an attack on the US government and companies such as PayPal and MasterCard in protest at the blocking of payments to WikiLeaks.

DoS and DDoS: Key Differences
A DoS (Denial of Service) attack originates from a single device. It is easy to detect and mitigate. A DDoS attack, however, originates from multiple infected devices, making it more difficult to mitigate.

How DDoS attacks work
Attackers create botnets—networks of infected devices, including PCs, smartphones, and IoT devices. These devices become part of a network of "zombie computers." Users may not even be aware that they are participating. A case in point is the 2016 incident involving the exploitation of a vulnerability in Mirai routers. At that time, 500,000 devices were involved in the scheme. Massive attacks were carried out on Twitter, Reddit, and other websites.

Types of DDoS attacks

Volume attacks, or UDP floods, overload a network with a large number of requests, causing the server to be unable to handle them. In 2020, an attack on Amazon Web Services (AWS) servers reached 2.3 Tbps—the largest DDoS attack to date.

Protocol attacks, such as TCP SYN floods, exploit vulnerabilities in network protocols. An attacker sends a server multiple requests with the SYN flag, forcing it to wait for a final acknowledgement, which never arrives. In 2018, such an attack on GitHub servers resulted in performance degradation, but the service recovered within nine minutes.

Application-layer attacks (HTTP requests) mimic legitimate traffic by generating numerous fake requests. In 2015, Telegram was subjected to an HTTP flood attack, which rendered the service unavailable to users in some regions.
Consequences of DDoS attacks
— Financial losses. Every minute of downtime results in significant losses. In 2016, an attack on the Dyn platform disrupted major services, including Amazon and Netflix. The companies likely lost hundreds of thousands of dollars.

— Deteriorating reputation. Decreasing user trust. In 2020, Zoom faced problems due to cyberattacks. This inevitably impacted trust among corporate clients.

— Data theft. Blocking resources may be the lesser of two evils. This is often used by hackers to divert attention from more serious crimes, such as the illegal acquisition of bank card data.

DDoS Protection Methods

Network-level protection. CDN and WAF technologies help filter malicious traffic and block anomalies.
A CDN (content delivery network) operates as a network of servers located around the world. When a user visits a website, the CDN sends a copy of the content from the closest server, rather than the main one. This helps reduce the load on the main server and can block suspicious traffic.

A WAF (web application firewall) is a system that inspects all requests coming to a website, analyzing whether these requests contain malicious code or attempted attacks.

Traffic monitoring. Tools like Nagios or Zabbix allow you to quickly identify anomalies and record request statistics.

Backup communication channels. In the event of an attack, traffic can be redirected to backup servers to redistribute the load.

Software updates. Regular software updates include up-to-date protection against hackers.

Using cloud-based DDoS protection services. Many companies now prefer to outsource DDoS protection to cloud providers such as Cloudflare or Akamai. These services provide scalable protection, which is especially important in the event of major incidents.

Geoblocking. In some cases, when the threat originates in a single country or region, it is possible to block traffic from these zones. However, this method is not always effective, as attackers can use VPNs and proxy servers to mask their location.

Automatic resource scaling. This allows you to quickly increase infrastructure capacity and cope with unexpected traffic increases.
DDoS Attack Trends
DDoS attacks are becoming more complex and widespread. In 2023, the number of multi-protocol attacks, combining different types, such as volumetric and protocol-based attacks, will increase. This increases the flow of traffic and makes attacks more powerful.

Attackers use such attacks not only for extortion but also for manipulation, such as extorting money to stop attacks or causing problems for competitors.

Hackers are increasingly turning to cloud resources to conduct attacks. Cloud services allow traffic to be generated from different regions, making them more difficult to block.

Predictions for 2025 suggest a continued evolution of DDoS attacks. Attacks on weakly protected devices, such as smart cameras and routers, which can easily be turned into zombie devices, are expected to increase.

Conclusions
1. DDoS attacks can be a serious problem for businesses, causing losses and reputational damage.

2. Botnets make DDoS attacks particularly dangerous because they consist of multiple infected devices operating simultaneously under the hacker's control. These devices can be computers, smartphones, smart devices, and even household appliances.

3. The variety of attack types requires specialized protection methods, such as CDNs, WAFs, software monitoring, and updating.

4. It is important for every website owner to have a DDoS attack response plan. It is recommended to consult with cybersecurity specialists and consider activating relevant services with your hosting provider.


Go back
19-09-2025, 07:07