Itnetic logo Itnetic Technologies
  • Pricing
  • Discord
Game protectionMinecraft serversBot joins, ping floods and connection attacks stopped before they reach your server. No plugin, no mod, nothing for players to install.Explore game protection →

For websites and APIs

  • DDoS ProtectionLayer-7 mitigation for attacks that look like real traffic.
  • Web CDNEdge caching on the network that filters your attacks.
  • PricingFree tier, then plans from €5/month.

How it works

  • The edge pipelineChallenge gate, behavioral signatures, WAF, rate limits and cache.
  • Logs & analyticsPer-request visibility and the exact verdict behind every block.
  • NetworkPoints of presence across Europe, North America and Asia Pacific.

Learn

  • GuidesPlain-English explainers on DDoS, WAFs, rate limiting and CDNs.
  • HTTP header checkGrade any site’s security headers in a few seconds.
  • FAQThe questions we get asked before people sign up.
  • ChangelogWhat shipped, and when.

Compare

  • vs Cloudflare
  • vs DDoS-Guard
  • vs CDN77
  • vs WEDOS
  • Status ↗
Log inStart free
Game protectionDDoS ProtectionWeb CDNPricing
The edge pipelineLogs & analyticsNetwork
GuidesHTTP header checkFAQChangelogvs Cloudflarevs DDoS-Guardvs CDN77vs WEDOSStatus ↗
PricingDiscord
Log inStart free

Learn · DDoS basics

What is a DDoS attack?

A distributed denial-of-service (DDoS) attack overwhelms a website or API with traffic from many machines at once, until real visitors can no longer get through.

Updated July 8, 2026 · Itnetic team — reviewed by Petr Chlíbek, founder

Key takeaways

  • A DDoS attack floods a site with traffic from thousands of hijacked machines (a botnet) until legitimate visitors cannot get through.
  • There are three types: volumetric (saturate bandwidth), protocol (exhaust connections) and application-layer / Layer 7 (mimic real users).
  • Layer 7 attacks are the hardest to detect — every request looks legitimate, so firewalls and volume thresholds wave them through.
  • Mitigation means filtering traffic at the edge before it reaches your server; DNS-based protection typically activates within minutes.

How a DDoS attack works

Every server has limits: bandwidth, connections, CPU, memory. A DDoS attack deliberately exhausts one of those limits. The "distributed" part is what makes it hard to stop — the traffic comes from thousands or millions of different devices (a botnet), so you cannot simply block one address.

Botnets are built from compromised computers, cheap cloud servers, and increasingly from hijacked IoT devices such as cameras and routers. Attack capacity is rented by the hour on underground markets, which is why even small websites get hit: launching an attack costs the attacker a few dollars, while every hour of downtime costs you revenue and trust.

The three main types of DDoS attack

1. Volumetric attacks flood your connection with raw data — UDP floods, DNS amplification, NTP reflection. They are measured in gigabits per second and aim to saturate the network pipe before traffic even reaches your server.

2. Protocol attacks abuse weaknesses in network protocols to exhaust connection state — SYN floods, fragmented-packet attacks, ping of death. They are measured in packets per second and target firewalls and load balancers.

3. Application-layer (Layer 7) attacks send requests that look like legitimate visitors — loading pages, submitting forms, hitting search endpoints. They are measured in requests per second and are the hardest to detect, because each individual request is indistinguishable from a real user. A few thousand requests per second against an expensive endpoint (search, login, checkout) can take down a site that comfortably survives a much larger volumetric flood. Read more in What is a Layer 7 DDoS attack?.

Attack typeOSI layerMeasured inTypical examples
Volumetric3–4Gigabits per secondUDP flood, DNS amplification, NTP reflection
Protocol3–4Packets per secondSYN flood, fragmented packets
Application-layer7Requests per secondHTTP flood, Slowloris, credential stuffing

Warning signs you are under attack

  • The site becomes slow or unreachable with no deploy or infrastructure change.
  • Traffic spikes far above normal, often from unusual countries or networks.
  • A single endpoint (login, search, cart) receives abnormal request volume.
  • Your origin server's CPU or connection count saturates while bandwidth looks normal — a classic Layer 7 signature.

How DDoS mitigation works

Modern protection sits between the internet and your origin server, usually as a reverse proxy you enable by changing DNS records. Clean traffic passes through; attack traffic is filtered at the edge before it can reach you. Volumetric floods are absorbed by large network backbones, protocol attacks are dropped at the network layer, and application-layer attacks are separated from real users with behavioral analysis and lightweight browser challenges.

The practical steps to take during an active attack are covered in How to stop a DDoS attack. If you want protection in place before it happens, Itnetic's DDoS protection goes live with two DNS record changes.

FAQ

Quick answers

How long does a DDoS attack last?

Anywhere from minutes to weeks. Most attacks last under a day, but attackers often return if the first attempt succeeded. Sustained campaigns against a business can continue on and off for months.

Are DDoS attacks illegal?

Yes. Launching a DDoS attack is a criminal offence in most jurisdictions, including the EU ([Directive 2013/40/EU](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32013L0040)) and the US (Computer Fraud and Abuse Act). Being a victim carries no liability — but paying ransom demands is strongly discouraged.

Can a small website be a DDoS target?

Yes, and frequently. Attacks are cheap to rent, so small shops, game servers, community sites and local businesses get hit by competitors, extortionists or disgruntled individuals. Size is no protection.

Does more server capacity stop DDoS attacks?

Rarely. Attackers can rent more capacity faster and cheaper than you can scale servers. Filtering attack traffic at the edge — before it reaches your infrastructure — is the only approach that scales in your favor.

Keep reading

01

What is a Layer 7 DDoS attack?

Layer 7 (application-layer) DDoS attacks imitate legitimate visitors instead of flooding the network — which is exactly why traditional defenses miss them.

02

What is a DNS amplification attack?

A DNS amplification attack forges your IP address on small DNS queries so that thousands of innocent servers answer with far larger replies — all of them aimed at you.

03

How to stop a DDoS attack on your website.

A practical, ordered checklist for the moment your site goes down — and for making sure the next attack never reaches it.

04

What is DDoS mitigation?

DDoS mitigation is the process of spotting attack traffic and dropping it before it reaches the resource an attacker is trying to exhaust — bandwidth, connections, or your application itself.

05

WAF vs DDoS protection: what is the difference?

Both sit in front of your website, both block traffic, and vendors sell them side by side — which is exactly why teams buy one and assume they are covered for the other. They answer two different questions.

06

Ransom DDoS: what to do about an extortion email

A ransom DDoS (RDoS) attack starts with an email, not an outage: pay cryptocurrency before a deadline, or your site goes down. Most of these threats are bluffs — but the ones that are not give you hours, not days.

Protect my website freeHow our protection works
Itnetic logo Itnetic Technologies

Advanced DDoS mitigation and web performance solutions for modern businesses. Protect your infrastructure across multiple regions.

Find us on GoogleAdd as preferred source

Product

  • DDoS Mitigation
  • Web CDN
  • Game Protection
  • Network
  • Pricing

Resources

  • Learn
  • HTTP header check
  • Changelog
  • FAQ
  • Status
  • Discord

Legal

  • Acceptable Use
  • SLA
  • Security
  • Abuse
  • Sub-processors
  • Data Retention
  • Incident Response

Company

  • Founder
  • Contact
Petr ChlíbekIČO: 21210756Neplátce DPH
© 2026 Itnetic Technologies. All rights reserved.
Terms of ServicePrivacy PolicyCookie PolicyDPAIP geolocation by DB-IP (CC BY 4.0)Powered by Startup FastLiftOff launch badgeFeatured on IndieHunt