Learn more about distributed denial of service (DDoS) attacks, including the different attack types and tips for preventing them.
![[Featured image] A cybersecurity analyst is working with physical servers while holding a laptop.](https://d3njjcbhbojbot.cloudfront.net/api/utilities/v1/imageproxy/https://images.ctfassets.net/wp1lcwdav1p1/4lejbmSQhkopy98pvN3rmk/6720302cb608375d8bd37c6013649e1f/9X-Pw9ox-converted-from-jpeg.webp?w=1500&h=680&q=60&fit=fill&f=faces&fm=jpg&fl=progressive&auto=format%2Ccompress&dpr=1&w=1000)
A distributed denial-of-service (DDoS) attack is a cyber threat that floods an online resource with excessive traffic, disrupting its operation and potentially causing the service to go offline.
To stop a DDoS attack or prevent one, consider using strategies like rate limiting, which caps the number of server requests allowed in a given period.
Another DDoS attack mitigation strategy, web application firewalls, helps prevent application-layer attacks by shielding the server from illegitimate traffic.
An HTTP flood, which overloads an HTTP server with repeated requests, is an example of a DDoS attack. Discover more about DDoS attacks and ways to defend against them in this article.
If you’re ready to get your start in cybersecurity right away, enroll in the Google Cybersecurity Professional Certificate. You’ll have the opportunity to learn how to protect networks, devices, people, and data from unauthorized access and cyberattacks using security information and event management (SIEM) tools.
A DDoS attack is a cyber threat that overwhelms an online resource with traffic, causing the web service to fail to operate normally and possibly even go offline. This threat can cause significant harm to a business, prevent users from accessing sites, or significantly slow the web server to the point where it becomes inaccessible.
Attacks can last for several hours and, in severe cases, prevail for multiple days. Many businesses and organizations rely heavily on their online platforms, so a DDoS attack can come with significant consequences.
Attackers may strategically time DDoS attacks during critical time periods. For example, an online retailer could suffer an attack on a high-volume shopping day such as Black Friday, where its website becomes inaccessible, causing it to lose a considerable amount of business. In some cases, attackers may infiltrate databases during DDoS attacks and gain access to sensitive information due to security vulnerabilities being exploited.
An example of a DDoS attack is an HTTP flood, during which the attackers aim to overwhelm the HTTP server by repeatedly requesting the page, eventually bringing the service down. Cybercriminals carrying out this activity use malicious software to infect many computers to send requests to the websites, making it seem like legitimate internet traffic.
One strategy for preventing DDoS attacks is rate limiting. Rate limiting puts a limit on the number of requests a server will accept over a given period of time. Web application firewalls (WAFs) are especially useful in preventing application-layer attacks by protecting the server from illegitimate traffic. Note that preventing and identifying DDoS attacks can come with challenges, since it may be difficult to differentiate genuine traffic from attack traffic.
The three main types of DDoS attacks are application-layer attacks, protocol attacks, and volumetric attacks. Learn more about each of these attacks below.
Application-layer attacks: Application-layer attacks aim for the software that provides the web service. It typically exhausts the target’s resources, making this type of DDoS attack challenging to defend against.
Protocol attacks: Protocol attacks, also known as state-exhaustion attacks, target firewalls or the device's operating system. This consumes the resources of these network-based devices and servers, causing the inaccessibility of web services.
Volumetric attacks: Volumetric attacks use extreme amounts of traffic to congest the target. This overwhelming flood of traffic consumes all of the available bandwidth, and services become unavailable as a result.
Read more: Types of Firewalls for Cybersecurity
Subscribe to Career Chat on LinkedIn to keep track of popular skills, tools, and certifications. Build or refresh your cybersecurity skills with our other free digital resources:
Watch on YouTube: 4 Cybersecurity Skills You'll Learn in the Google Certificate
Hear from an insider: Meet the IT Support Tech Advancing Toward a Cybersecurity Career
Accelerate your career growth with a Coursera Plus subscription. When you enroll in either the monthly or annual option, you’ll get access to over 10,000 courses.
Editorial Team
Coursera’s editorial team is comprised of highly experienced professional editors, writers, and fact...
This content has been made available for informational purposes only. Learners are advised to conduct additional research to ensure that courses and other credentials pursued meet their personal, professional, and financial goals.