Itnetic logo Itnetic Technologies
PlatformLogsNetworkPricing
Log inStart free
PlatformLogsNetworkPricing
Log inStart free

Learn · DDoS basics

What is a DDoS attack?

A distributed denial-of-service (DDoS) attack overwhelms a website or API with traffic from many machines at once, until real visitors can no longer get through.

Updated July 8, 2026 · Itnetic team — reviewed by Petr Chlíbek, founder

Key takeaways

  • A DDoS attack floods a site with traffic from thousands of hijacked machines (a botnet) until legitimate visitors cannot get through.
  • There are three types: volumetric (saturate bandwidth), protocol (exhaust connections) and application-layer / Layer 7 (mimic real users).
  • Layer 7 attacks are the hardest to detect — every request looks legitimate, so firewalls and volume thresholds wave them through.
  • Mitigation means filtering traffic at the edge before it reaches your server; DNS-based protection typically activates within minutes.

How a DDoS attack works

Every server has limits: bandwidth, connections, CPU, memory. A DDoS attack deliberately exhausts one of those limits. The "distributed" part is what makes it hard to stop — the traffic comes from thousands or millions of different devices (a botnet), so you cannot simply block one address.

Botnets are built from compromised computers, cheap cloud servers, and increasingly from hijacked IoT devices such as cameras and routers. Attack capacity is rented by the hour on underground markets, which is why even small websites get hit: launching an attack costs the attacker a few dollars, while every hour of downtime costs you revenue and trust.

The three main types of DDoS attack

1. Volumetric attacks flood your connection with raw data — UDP floods, DNS amplification, NTP reflection. They are measured in gigabits per second and aim to saturate the network pipe before traffic even reaches your server.

2. Protocol attacks abuse weaknesses in network protocols to exhaust connection state — SYN floods, fragmented-packet attacks, ping of death. They are measured in packets per second and target firewalls and load balancers.

3. Application-layer (Layer 7) attacks send requests that look like legitimate visitors — loading pages, submitting forms, hitting search endpoints. They are measured in requests per second and are the hardest to detect, because each individual request is indistinguishable from a real user. A few thousand requests per second against an expensive endpoint (search, login, checkout) can take down a site that comfortably survives a much larger volumetric flood. Read more in What is a Layer 7 DDoS attack?.

Attack typeOSI layerMeasured inTypical examples
Volumetric3–4Gigabits per secondUDP flood, DNS amplification, NTP reflection
Protocol3–4Packets per secondSYN flood, fragmented packets
Application-layer7Requests per secondHTTP flood, Slowloris, credential stuffing

Warning signs you are under attack

  • The site becomes slow or unreachable with no deploy or infrastructure change.
  • Traffic spikes far above normal, often from unusual countries or networks.
  • A single endpoint (login, search, cart) receives abnormal request volume.
  • Your origin server's CPU or connection count saturates while bandwidth looks normal — a classic Layer 7 signature.

How DDoS mitigation works

Modern protection sits between the internet and your origin server, usually as a reverse proxy you enable by changing DNS records. Clean traffic passes through; attack traffic is filtered at the edge before it can reach you. Volumetric floods are absorbed by large network backbones, protocol attacks are dropped at the network layer, and application-layer attacks are separated from real users with behavioral analysis and lightweight browser challenges.

The practical steps to take during an active attack are covered in How to stop a DDoS attack. If you want protection in place before it happens, Itnetic's DDoS protection goes live with two DNS record changes.

FAQ

Quick answers

How long does a DDoS attack last?

Anywhere from minutes to weeks. Most attacks last under a day, but attackers often return if the first attempt succeeded. Sustained campaigns against a business can continue on and off for months.

Are DDoS attacks illegal?

Yes. Launching a DDoS attack is a criminal offence in most jurisdictions, including the EU ([Directive 2013/40/EU](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32013L0040)) and the US (Computer Fraud and Abuse Act). Being a victim carries no liability — but paying ransom demands is strongly discouraged.

Can a small website be a DDoS target?

Yes, and frequently. Attacks are cheap to rent, so small shops, game servers, community sites and local businesses get hit by competitors, extortionists or disgruntled individuals. Size is no protection.

Does more server capacity stop DDoS attacks?

Rarely. Attackers can rent more capacity faster and cheaper than you can scale servers. Filtering attack traffic at the edge — before it reaches your infrastructure — is the only approach that scales in your favor.

Keep reading

01

What is a Layer 7 DDoS attack?

Layer 7 (application-layer) DDoS attacks imitate legitimate visitors instead of flooding the network — which is exactly why traditional defenses miss them.

02

How to stop a DDoS attack on your website.

A practical, ordered checklist for the moment your site goes down — and for making sure the next attack never reaches it.

03

What is a CDN?

A content delivery network (CDN) stores copies of your website on servers around the world, so every visitor is served from the location nearest to them.

Protect my website freeHow our protection works
Itnetic logo Itnetic Technologies

Advanced DDoS mitigation and web performance solutions for modern businesses. Protect your infrastructure across multiple regions.

Product

  • DDoS Mitigation
  • Web CDN
  • Network
  • Pricing

Resources

  • Learn
  • Changelog
  • FAQ
  • Status

Company

  • Founder
  • Contact
Petr ChlíbekIČO: 21210756Neplátce DPH
© 2026 Itnetic Technologies. All rights reserved.
Terms of ServicePrivacy PolicyCookie PolicyDPA

We use essential cookies to run and secure the site. With your consent we also use Google Analytics to understand usage. Cookie Policy