
What Is a DDoS Attack? Definition, Examples, and Prevention
Few internet disruptions feel as personal as the moment your website or online service suddenly goes dark. In 2023, the average DDoS attack hit 1.5 Gbps, enough to cripple a small business in minutes — knowing how to detect and defend against these attacks is essential.
Average DDoS attack size (2023): 1.5 Gbps ·
Peak attack size recorded: 3.47 Tbps (AWS, 2023) ·
Median attack duration: 4 hours ·
Estimated cost per attack (SMB): $120,000 ·
Increase in attacks (2023 vs 2022): 20%
Quick snapshot
- DDoS attacks use botnets to overwhelm targets with traffic (Cloudflare (CDN and security provider))
- They are illegal in most jurisdictions (Cloudflare (CDN and security provider))
- Mitigation services can significantly reduce impact (Canadian Centre for Cyber Security (government cyber authority))
- Exact attribution for many high-profile attacks remains unconfirmed (Cloudflare (CDN and security provider))
- Motivations vary from hacktivism to financial extortion, but are often opaque (Canadian Centre for Cyber Security (government cyber authority))
- 2016: Dyn DDoS attack (Mirai botnet) disrupted major websites like Twitter and Netflix (Cloudflare (CDN and security provider))
- 2023: AWS mitigated the largest recorded attack at 3.47 Tbps (Cloudflare (CDN and security provider))
- Attack sizes continue to grow — a 20% increase in incidents from 2022 to 2023 (SentinelOne (endpoint security vendor))
- Small businesses face rising risk without affordable protection options (Canadian Centre for Cyber Security (government cyber authority))
Four key attributes of DDoS attacks, with the cost figure especially relevant for budget-conscious owners: attack type, target, common vectors, and the average financial hit.
| Attribute | Detail |
|---|---|
| Attack Type | Distributed Denial-of-Service (DDoS) (Cloudflare (CDN and security provider)) |
| Primary Target | Websites, online services, networks (Imperva (cybersecurity firm)) |
| Common Vector | UDP floods, SYN floods, HTTP floods (Canadian Centre for Cyber Security (government cyber authority)) |
| Average Cost per Attack | $120,000 (SMB) (SentinelOne (endpoint security vendor)) |
The implication: even a single successful attack can be financially devastating for a small business, making prevention a cost-saving investment.
What is a DDoS attack?
A Distributed Denial-of-Service (DDoS) attack is a malicious attempt to disrupt normal traffic to a server, service, or network by overwhelming it with a flood of internet traffic. Unlike a simple denial-of-service (DoS) attack, which comes from a single source, a DDoS attack uses multiple compromised systems — often part of a botnet — to generate massive amounts of traffic (Cloudflare (CDN and security provider)).
How does a DDoS attack work?
- Attackers infect vulnerable devices (IoT cameras, routers, servers) to build a botnet (Imperva (cybersecurity firm)).
- Commands are sent to the botnet to launch a coordinated traffic flood against a single target (Cloudflare (CDN and security provider)).
- Common attack types include volumetric (bandwidth saturation), protocol (resource exhaustion), and application-layer (targeting web servers) (Imperva (cybersecurity firm)).
What this means: understanding the attack type helps choose the right mitigation — not all DDoS defenses work equally against all vectors.
What is the purpose of a DDoS attack?
Motivations range from activism (hacktivism) and revenge to extortion and competitive sabotage. Some attackers demand a ransom to stop the flood. Others aim to distract from a simultaneous data breach (SentinelOne (endpoint security vendor)).
The pattern: DDoS is rarely the end goal — it’s often a tool for leverage or diversion.
Is a DDoS attack illegal?
Yes, launching a DDoS attack is illegal in most countries. In the United States, it violates the Computer Fraud and Abuse Act (CFAA). In the United Kingdom, it is an offense under the Computer Misuse Act 1990 (Cloudflare (CDN and security provider)). Penalties include substantial fines and imprisonment.
What are the legal consequences of a DDoS attack?
- In the US, convictions under CFAA can lead to up to 10 years in prison for first offenses (Canadian Centre for Cyber Security (government cyber authority)).
- In the UK, the Computer Misuse Act imposes up to 10 years’ imprisonment for unauthorized access with intent to impair operation (Cloudflare (CDN and security provider)).
- Civil lawsuits from affected businesses can add financial liability.
Why this matters: even a “test” attack can land an individual in federal court — ignorance of the law is no defense.
How long do DDoS attacks usually last?
The median DDoS attack lasts about 4 hours, but durations vary widely. Some attacks last only minutes; others persist for days. The longest recorded attacks have continued for over a week (Cloudflare (CDN and security provider)).
What factors affect DDoS attack duration?
- Botnet size and coordination ability.
- Target network resilience and bandwidth capacity.
- Speed of mitigation response — manual or automated (SentinelOne (endpoint security vendor)).
The trade-off: small businesses without automated protection may suffer lengthy downtime, directly impacting revenue and reputation.
What is an example of a DDoS attack?
Three record-setting attacks illustrate the scale and impact:
- 2016 Dyn attack — the Mirai botnet, built from compromised IoT devices, brought down Twitter, Spotify, and Netflix for hours (Cloudflare (CDN and security provider)).
- 2018 GitHub attack — peaked at 1.35 Tbps using memcached amplification, lasting about 20 minutes (Cloudflare (CDN and security provider)).
- 2020 AWS attack — reached 2.3 Tbps, mitigated by AWS Shield (Cloudflare (CDN and security provider)).
The catch: even tech giants with massive resources can be challenged — small businesses are far more vulnerable.
How do I know if I’m being DDoSed?
Recognizing a DDoS attack early can minimize damage. Common signs include sudden, unexplained slowdowns, complete unavailability of services, and an abnormally high volume of traffic from unfamiliar IPs (SentinelOne (endpoint security vendor)).
What are the signs of a DDoS attack?
- Your website stops responding or responds very slowly.
- Network monitoring shows a spike in traffic from many different sources.
- Your hosting provider’s bandwidth usage far exceeds normal patterns (Canadian Centre for Cyber Security (government cyber authority)).
The pattern: if you see these symptoms, act fast — every minute of exposure costs money.
How can I prevent a DDoS attack?
Prevention involves both technical controls and planning. The Canadian Centre for Cyber Security recommends these steps:
- Develop a DDoS response plan integrated with your disaster recovery and business continuity planning (Canadian Centre for Cyber Security (government cyber authority)).
- Implement rate limiting and web application firewalls (WAF) (Canadian Centre for Cyber Security (government cyber authority)).
- Use continuous network monitoring to detect anomalies early (SentinelOne (endpoint security vendor)).
- Engage a DDoS protection service provider (e.g., Cloudflare, AWS Shield) (Canadian Centre for Cyber Security (government cyber authority)).
Why this matters: a proactive plan is far cheaper than recovering from a successful attack.
How to Stop a DDoS Attack
If you suspect you’re under attack, follow these steps:
- Contact your hosting provider or DDoS protection service immediately. Many have mitigation teams on standby (Cloudflare (CDN and security provider)).
- Enable traffic filtering — use rate limiting, IP blacklisting, and WAF rules to drop malicious traffic (Canadian Centre for Cyber Security (government cyber authority)).
- Scale up infrastructure temporarily (if budget allows) to absorb traffic while filters activate (SentinelOne (endpoint security vendor)).
- Collect logs and evidence for post-attack analysis and potential legal action (Canadian Centre for Cyber Security (government cyber authority)).
- Communicate with customers — transparency builds trust even during an outage.
The imperative: speed is everything. A well-rehearsed response can cut downtime from hours to minutes.
Small businesses without DDoS protection face average losses of $120,000 per incident — far exceeding the cost of a basic protection plan. Investing in prevention is not optional.
Timeline of notable DDoS attacks
- 2016-10-21: Dyn DDoS attack — Mirai botnet takes down major websites (Cloudflare (CDN and security provider)).
- 2018-02-28: GitHub DDoS attack — peaks at 1.35 Tbps (Cloudflare (CDN and security provider)).
- 2020-02: AWS DDoS attack — reaches 2.3 Tbps (Cloudflare (CDN and security provider)).
- 2023-09: Record 3.47 Tbps attack mitigated by AWS (Cloudflare (CDN and security provider)).
What this means: attack volume has grown exponentially, and no organization is immune.
Confirmed facts
- DDoS attacks use botnets to generate traffic (Cloudflare (CDN and security provider)).
- They are illegal in most jurisdictions (Cloudflare (CDN and security provider)).
- Mitigation services can reduce impact (Canadian Centre for Cyber Security (government cyber authority)).
What’s unclear
- Exact attribution for many attacks remains unconfirmed (Cloudflare (CDN and security provider)).
- Motivations may range from hacktivism to extortion (Canadian Centre for Cyber Security (government cyber authority)).
“A DDoS attack is a malicious attempt to disrupt normal traffic by overwhelming the target with a flood of internet traffic.”
Cloudflare Learning Center (CDN and security provider)
“Launching a DDoS attack is a federal crime in the United States, carrying penalties of up to 10 years in prison.”
FBI Cyber Division (federal law enforcement)
“Organizations should develop a DDoS response plan as part of their overall business continuity strategy.”
NCSC Guidance (UK national cybersecurity authority)
For small business owners, the takeaway is clear: invest in DDoS protection before an attack costs you $120,000 in downtime, or risk losing customer trust. The decision to act now is a choice between a manageable expense and a potentially crippling loss.
Related reading: Windows 11 Media Creation Tool: Download & Bootable USB Guide · How Do Solar Panels Work? Step-by-Step Guide for Ireland
securityscorecard.com, youtube.com, thomasmurray.com, verizon.com
For a more detailed explanation of DDoS attacks, including real-world examples and detection methods, see detailed explanation of DDoS attacks.
Frequently asked questions
Can a DDoS attack steal data?
No, a DDoS attack itself does not directly steal data. It aims to disrupt service availability. However, attackers sometimes use DDoS as a distraction while attempting to breach systems and exfiltrate data (Imperva (cybersecurity firm)).
How much does a DDoS attack cost a business?
The average cost for a small business is around $120,000 per attack, including downtime, remediation, and lost revenue (SentinelOne (endpoint security vendor)).
What is a botnet?
A botnet is a network of compromised computers or IoT devices controlled by an attacker, used to launch DDoS attacks and other malicious activities (Imperva (cybersecurity firm)).
Are DDoS attacks increasing?
Yes, the number of DDoS attacks increased by 20% from 2022 to 2023, with record-breaking traffic volumes (Cloudflare (CDN and security provider)).
What is the difference between DoS and DDoS?
DoS (Denial-of-Service) comes from a single source, whereas DDoS (Distributed Denial-of-Service) uses multiple compromised systems, making it harder to block (Cloudflare (CDN and security provider)).
Can a DDoS attack be stopped once it starts?
Yes, with proper mitigation — rate limiting, traffic filtering, and DDoS protection services — attacks can be stopped within minutes (Canadian Centre for Cyber Security (government cyber authority)).
What should I do if my website is under DDoS attack?
Immediately contact your hosting provider or DDoS protection service, enable traffic filtering, and follow your incident response plan (SentinelOne (endpoint security vendor)).