Distributed Denial of Service

DDoS Distributed denial of service DDoS attack

Glossary

A DDoS attack (distributed denial of service) is a malicious attempt to overwhelm a server, service or network resource with a large volume of simultaneous requests from many distributed sources. The goal is to disrupt the target’s availability so that legitimate users can no longer reach the website or service. Unlike a simple DoS attack, DDoS traffic doesn’t come from a single source but simultaneously from thousands to millions of devices, usually a botnet of hijacked, often unknowingly infected computers and IoT devices.

How does a DDoS attack work?

Attackers first build a botnet by gaining control over a large number of devices via malware, from classic PCs to poorly secured IoT devices such as routers, cameras or smart home systems. On command, all devices send requests to the target simultaneously. Because the traffic comes from so many different, real IP addresses, it can’t simply be stopped by blocking a single source – the individual requests often look completely legitimate. Only their sheer volume turns them into an attack.

The main attack types at a glance

Attack typeTargetsExamplesEffect
Volume-basedNetwork bandwidthUDP flood, DNS amplificationCompletely exhausts available bandwidth
Protocol attacksServer/network resourcesSYN flood, ping of deathOverloads firewalls, load balancers and server connection tables
Application layer (layer 7)The web application itselfHTTP flood, SlowlorisLooks like normal user traffic, making it particularly hard to detect

Application-layer attacks are especially insidious for website operators: they need comparatively little bandwidth but specifically target resource-intensive functions such as search forms, login pages or cart processes, often invisible to classic network firewalls.

Why are websites attacked at all?

  • Extortion (ransom DDoS): attackers demand ransom to stop an ongoing or threatened attack.
  • Competitor sabotage: targeted disruption during important sales phases to damage rivals.
  • Hacktivism: politically or ideologically motivated attacks against companies or organisations.
  • Diversion: a DDoS attack ties up the IT team while the real data theft runs in the background.
  • Cyber vandalism: attacks without a concrete motive, often with rented “DDoS as a service” offerings from the darknet.

The 2026 trend: bigger, AI-assisted attacks

DDoS attacks have grown massively in size and frequency in recent years. Hypervolumetric attacks reached new records in the terabit range at the end of 2025, driven by huge botnets of hundreds of thousands of hijacked IoT and Android devices. Generative AI additionally lowers the entry barrier: where deep technical knowledge used to be required, complex attacks can now be automated and adapted to target systems more easily. The consequence: no longer just large corporations, but increasingly small and mid-sized companies come into the crosshairs, often as part of automated extortion attempts.

Signs of a DDoS attack

  • Website or service suddenly very slow or completely unreachable
  • Unusually high server load without an apparent reason
  • Sharp traffic increase from a few IP ranges, countries or with similar user behaviour
  • Conspicuously many requests to a single URL or function, such as login or search forms
  • Server errors such as HTTP 503 (Service Unavailable) that don’t occur under normal load

Effective protection measures

  • CDN with DDoS protection: a content delivery network distributes traffic across many locations and filters malicious requests before they reach the actual server – by far the most effective first line of defence for most websites.
  • Web application firewall (WAF): detects and blocks suspicious patterns at the application level, e.g. in layer-7 attacks.
  • Rate limiting: limits how many requests a single source may make in a short time.
  • Redundant infrastructure & load balancing: distributes load across multiple servers so a single bottleneck doesn’t paralyse the whole website.
  • Monitoring & an incident response plan: early detection of unusual traffic patterns and a clear action plan shorten the reaction time considerably in an emergency.

At aceArt, these measures belong to the standard repertoire of our cyber security services.

DDoS attacks and SEO: underestimated collateral damage

A DDoS attack isn’t just a technical and economic problem — it also damages your visibility on Google. If a website is unreachable during a crawl attempt, the web crawler counts that as an error and, in the worst case, permanently reduces the crawl frequency. Repeated outages also negatively affect user signals and Core Web Vitals such as Largest Contentful Paint – both flow directly or indirectly into the ranking. If you regularly notice outages or unusual traffic patterns, have that checked technically as part of a website audit, and find support within our SEO services.

Conclusion

DDoS attacks stopped being a niche risk for large corporations a long time ago. Today they threaten websites of every size, with direct consequences for revenue, reputation and search engine visibility. Effective protection doesn’t have to be complicated: a well-configured CDN, a web application firewall and a well-thought-out monitoring concept already reduce the risk considerably. We can help you secure your website or infrastructure, as part of our cyber security services or directly in a no-obligation consultation.

Häufige Fragen

What's the difference between DoS and DDoS?
A DoS attack (denial of service) comes from a single source and can usually be blocked simply by banning that one IP address. A DDoS attack (distributed denial of service), on the other hand, uses thousands to millions of distributed sources simultaneously, usually a botnet of hijacked devices. That makes it considerably harder to fend off, because legitimate and malicious traffic can barely be told apart.
How long does a typical DDoS attack last?
Anywhere from a few minutes to several days. Short, intense attacks (“hit and run”) often just test the defences or serve as a diversion for a parallel data theft. Longer-lasting attacks usually aim at maximum economic damage or extortion.
Is a DDoS attack a criminal offence?
Yes. In Germany, a DDoS attack constitutes computer sabotage under Section 303b of the Criminal Code and can be punished with imprisonment of up to three years, in particularly serious cases up to ten years. That also applies to operating or renting a botnet (“DDoS as a service”).
Can I prevent a DDoS attack completely?
It can never be ruled out entirely, but its damage can be drastically limited. A CDN with DDoS protection, a web application firewall, rate limiting and an incident response plan in practice prevent an attack from penetrating to your own infrastructure or overwhelming it in the first place.
How do I recognise that my website is being attacked right now?
Typical signs are a suddenly very slow or completely unreachable website, unusually high server load without an apparent reason, a sharp rise in traffic from a few IP ranges or countries, and unusually many requests to a single URL or function (e.g. the login or search form).
Are small companies also affected by DDoS attacks?
Yes, increasingly so. While the focus used to be mainly on large corporations and public authorities, automated, AI-supported attacks today also target smaller online shops and websites, often as part of extortion attempts or competitor sabotage, because the entry barrier for attackers has dropped sharply.
← Back to glossary
HOMEGLOSSARYDISTRIBUTED-DENIAL-OF-SERVICE