Understanding DDoS attacks: How cybercriminals overload websites
A Distributed Denial of Service (DDoS) attack is a relatively simple form of cyber-attack, but it is also one which can have a significant impact on any organisation targeted by one.
A DDoS attack overloads a website or online service with large amounts of web traffic. The goal is to disrupt the service, either by slowing it down, or flooding it to such an extent, the service is inaccessible to its users.
How a DDoS attack works
A DDoS attack uses an army of internet connected machines, known as a botnet, to direct web overwhelming traffic towards the intended target.
The botnet of computers and other internet connected devices are controlled by the attacker in some capacity, without the legitimate owner of the device knowing that this is the case.
These devices are commonly compromised after being secretly infected with malware which allows cybercriminals to give commands to the device.
Alternatively, the machines are compromised by attackers who have broken into them because the device has a common, default or otherwise weak password. As they are simply logging into the device, the device believes that access is legitimate.
No matter how the device is infected, it becomes part of a botnet which could consist of millions of similarly compromised devices.
It’s common for these botnets to be owned by cybercriminals who have formed dark web businesses to supply DDoS attacks. These can be run by individuals or by specialist criminal syndicates.
Either way, a user can pay a one-off fee or subscribe to a DDoS attack service which can be used to direct an overwhelming amount of web traffic to a specific IP address or an entire online service in order to disrupt it or take it offline entirely.
The attacks can be highly targeted. For example, it’s known for individuals with malicious intent to direct a DDoS attack at a specific individual, such as an online gaming rival.
Meanwhile, a large-scale DDoS attack can be used to severely disrupt even the largest online businesses and services. And in doing so, they slow down or deny the service to legitimate users.
The impact of a DDoS attack on businesses
A successful DDoS attack disrupts or completely knocks out an online service. Depending on the attack, the timescale of this can range from minutes to days or even weeks.
For users, a DDoS attack is irritating because they are unable to access the service they want to use. This could range from their online streaming or gaming services being down, not being able to buy tickets for a popular event like a concert, or in more severe scenarios, unable to access vital services they need, such as their online banking services.
For organisations, DDoS attacks are a problem because users being unable to access services could result in loss of income, as well as reputational damage.
If an enterprise is reliant on a cloud-based service which is disrupted by a large-scale DDoS attack, it will result in a substantial lack of productivity.
A significant DDoS attack can cost an organisation income. This is not only from a lack of sales or services provided during the period of the DDoS attack, but also because, in some cases, they might need to refund users who subscribe to an online service who can’t access it for the duration of the attack.
For example, video game developers which have seen their servers for online games taken out by malicious DDoS attacks lasting days, sometimes attempt to ‘refund’ players for the time they’ve lost, which ultimately costs the publisher money.
DDoS attacks are relatively low-level and simple to carry out, but the impact they can have can result in significant financial losses for organisations which are hit, especially if the attack is sustained over an ongoing period.
In the worst-case scenario for an online service provider, if the service is regularly disrupted by DDoS attacks, users might lose trust and cancel their subscription to the it, costing the provider in the long run.
Register your interest for Europe’s leading cybersecurity event
Be the first to hear more about Infosecurity Europe 2027, 8-10 June at London Excel.
How to protect against DDoS attacks
DDoS attacks are unpredictable nature. Almost any wannabe cybercriminal who wishes to cause disruption can hire a DDoS attack service strike without warning. However, there are steps which organisations and service providers can take to help defend against DDoS attacks. These include:
- Investing in a DDoS mitigation service solution
- Avoid unnecessary public disclosure of your origin web server’s IP address
- Use a diverse range of servers to ensure that all web connectivity is not reliant on one
- Implement measures to detect DoS attacks, such as real-time monitoring and alerting of system availability, network traffic, computer processing resources, and associated costs
ADVERTISEMENT
Enjoyed this article? Make sure to share it!
Latest articles
Keep up to date with the latest infosecurity news and trends in our latest articles.
Stay in the know
Receive updates about key events, news and recent insights from Infosecurity Europe.
Looking for something else?
