Skip to main content

CNiC Solutions

Network security analyst monitoring a traffic surge in a security operations center during a DDoS attack

A DDoS attack works like a deliberate traffic jam aimed at your business. Instead of one attacker knocking on your door, thousands or millions of hijacked devices all request your website at the same instant, until your server slows to a crawl or collapses and real customers cannot get through. These attacks are not rare or shrinking: Cloudflare mitigated 47.1 million DDoS attacks in 2025, a 121% jump over the previous year, and the largest single attack on record peaked at a staggering 31.4 terabits per second. This guide explains what a DDoS attack is, how one actually works, the main types, how big they have gotten, and, most important, how to stop them.

Key Takeaways

  • A DDoS attack floods a target with junk traffic from many sources at once to force it offline. It denies access rather than stealing data.
  • The power comes from a botnet: an army of malware-infected computers, servers, and IoT devices controlled remotely and pointed at one victim.
  • There are three main types: volumetric (raw bandwidth), protocol (exhausting network resources), and application-layer (targeting the app itself).
  • Attacks are surging in scale: Cloudflare mitigated 47.1 million attacks in 2025 (up 121% year over year), with a record peak of 31.4 Tbps.
  • You cannot block your way out live. Real protection is layered and put in place first: a mitigation or scrubbing service, WAF, rate limiting, a CDN, and a response plan.

What’s in This Guide

What a DDoS Attack Is

DDoS stands for distributed denial-of-service. Break the name down and it explains itself. “Denial of service” means the goal is to deny legitimate users access to a service, whether that is your website, your customer portal, your email, or an application your staff depends on. “Distributed” means the attack does not come from one place; it is spread across many machines firing at the same target simultaneously.

The distinction that matters is between a DoS attack and a DDoS attack. A plain DoS (denial-of-service) attack comes from a single source, so a defender can often stop it by identifying and blocking that one address. A DDoS attack comes from hundreds, thousands, or even millions of sources at once. That difference is everything: you cannot simply block one address when the traffic is arriving from everywhere, and the combined firepower of many machines is vastly greater than any single computer could produce.

It is worth being clear about what a DDoS attack is not. Unlike a data breach or ransomware, a classic DDoS attack does not break in and steal or encrypt your information. Its weapon is disruption. The damage is downtime: lost sales while your storefront is unreachable, staff unable to work, missed service commitments, and the reputational hit of customers finding your business offline. Attackers increasingly use that disruption for extortion, threatening or launching an attack and demanding payment to make it stop.

How a DDoS Attack Works

Almost every large DDoS attack is powered by a botnet. A botnet is a network of internet-connected devices, home computers, servers, and increasingly Internet of Things gadgets like cameras, routers, and thermostats, that have been infected with malware and can be controlled remotely without their owners’ knowledge. The attacker who controls them is often called a bot-herder, and the infected devices are sometimes called zombies.

Here is the sequence in plain terms:

  • Build the army. The attacker infects large numbers of devices with malware, usually by exploiting unpatched software or tricking users into installing it. Each compromised device quietly joins the botnet.
  • Give the order. Through a command-and-control server, the attacker tells every device in the botnet to send requests to one target at the same moment.
  • Flood the target. Thousands or millions of devices hammer the victim’s server, network, or application with traffic all at once, far more than it was built to handle.
  • Deny the service. The target’s capacity is exhausted. It slows to a crawl or crashes, and legitimate users are turned away because their requests are lost in the flood.

The reason this is so effective is that the malicious traffic is designed to look like ordinary traffic, and it arrives from countless different addresses spread around the world. The server cannot easily tell which requests are real customers and which are the attack, so blunt filtering risks blocking your actual users along with the flood. There is also a second lesson hiding here: any unpatched device on your own network, an old PC or a forgotten smart camera, can be conscripted into a botnet and used to attack someone else, which is one more reason endpoint security and patching matter.

 

 

Diagram showing an attacker controlling a botnet through a C2 server to flood and overwhelm a target server
A botnet of infected devices, directed through a command-and-control server, floods one target until it goes offline.

 

 

If you want to go deeper on the machinery behind these attacks, our explainer on how bots and botnets operate breaks down the good-versus-bad split and how devices get recruited in the first place.

Source: Cloudflare’s DDoS learning center

The Three Main Types of DDoS Attacks

Not all DDoS attacks work the same way. CISA, the FBI, and the MS-ISAC group them into three categories in their joint guidance, based on which part of your infrastructure the attack tries to exhaust. Understanding the categories matters because each one calls for a different defense, and sophisticated attackers often combine several at once.

1. Volumetric attacks

These are the brute-force floods most people picture. The attacker aims to consume all of your available bandwidth by sending an enormous volume of traffic, so much that the pipe to your network is simply full and nothing else gets through. Volumetric attacks are measured in bits per second, and the record-breaking multi-terabit attacks in the news are almost always this type. Amplification techniques, which trick other servers into sending large responses to your address, let attackers generate far more traffic than their own devices could alone.

2. Protocol attacks

Instead of filling your bandwidth, protocol attacks exhaust the resources of network equipment such as firewalls and load balancers by abusing the way network protocols work. A classic example is the SYN flood, which opens huge numbers of half-finished connections that tie up the server’s connection table until it can accept no new legitimate connections. These attacks are measured in packets per second and can take down infrastructure with far less raw bandwidth than a volumetric flood.

3. Application-layer attacks

The most targeted type aims at the application itself, the actual website or service, rather than the network around it. By sending requests that look legitimate but are deliberately expensive for the server to answer, such as repeatedly hitting a search function or login page, an attacker can bring a site down with a relatively small amount of traffic. Because each request resembles a normal user action, these attacks are among the hardest to detect and filter.

 

 

Infographic comparing volumetric, protocol, and application-layer DDoS attacks by what they target and how they are measured
The three DDoS categories – volumetric, protocol, and application-layer – each hit a different part of your infrastructure.

 

 

Source: CISA, FBI, and MS-ISAC joint DDoS guidance

How Big DDoS Attacks Have Gotten

DDoS attacks are not a fringe threat, and they are growing quickly in both number and size. The scale is worth seeing plainly, because it explains why do-it-yourself defenses no longer hold up.

47.1M
DDoS attacks Cloudflare mitigated in 2025
121%
increase in attacks over the prior year
31.4 Tbps
largest single attack on record (2025)
8M+
attacks logged in just the second half of 2025 (NETSCOUT)

To put that in perspective, Cloudflare reported averaging 5,376 attacks mitigated every hour across 2025. Attack sizes have escalated so fast that records now fall within weeks of each other, driven by powerful new IoT botnets. The chart below shows how the largest recorded attack has climbed, measured in terabits per second (Tbps):

Record DDoS Attack Size Over Time (peak Tbps)

GitHub, 2018
1.35

Cloudflare, May 2025
7.3

Cloudflare, Sep 2025
22.2

Cloudflare, late 2025
31.4

The historical anchors are just as telling. In October 2016, the Mirai botnet, built largely from insecure IoT devices, attacked the DNS provider Dyn and knocked major sites including Twitter, Netflix, Reddit, and Spotify offline for much of the eastern United States. In February 2018, GitHub was hit by what was then the largest attack ever recorded at 1.35 Tbps, using a memcached amplification technique. Those once-shocking numbers are now dwarfed by the multi-terabit attacks of today, which is exactly why protection has had to move upstream to networks built to absorb that kind of volume.

Source: Cloudflare 2025 Q4 DDoS threat report | NETSCOUT DDoS Threat Intelligence Report

 

CNiC Solutions — Cybersecurity

 

How to Stop a DDoS Attack

The single most important thing to understand about stopping a DDoS attack is that the real work happens before one ever arrives. Once a distributed flood is underway, you cannot simply block the source, because the traffic is coming from everywhere at once, and trying to filter it by hand usually blocks real customers too. Effective defense is layered, and most of it is set up in advance. Here is what actually protects a business, roughly in order of impact:

  • Put a DDoS mitigation or scrubbing service in front of your infrastructure. This is the foundation. A specialized provider absorbs incoming traffic across a massive global network, filters out the attack, and passes only clean traffic to you. Because the filtering happens upstream, the flood never reaches your own server. For any business that depends on being online, this is the highest-value control.
  • Use a content delivery network (CDN). A CDN spreads your content across many servers worldwide, which both improves speed for real users and distributes attack traffic so no single location is overwhelmed. Most CDN providers include DDoS protection as part of the service.
  • Deploy a web application firewall (WAF) and rate limiting. A WAF inspects incoming requests and blocks patterns typical of attacks before they reach your application, which is especially important against application-layer attacks. Rate limiting caps how many requests a single source can make in a given window, blunting many floods automatically.
  • Build in capacity and redundancy. Extra bandwidth headroom and redundant servers or data centers give you room to absorb a surge and keep running if one path is saturated. Capacity alone will not defeat a multi-terabit attack, but it buys time and resilience.
  • Harden your network and your own devices. Correctly configured firewalls and load balancers resist protocol attacks, and keeping every device patched keeps your own equipment out of the botnets that launch these attacks in the first place.
  • Have a written response plan. Know in advance who to call, how to reach your mitigation provider, and how to communicate with customers. A plan turns a chaotic outage into a managed incident.

The through-line is that these controls work together. A scrubbing service and CDN absorb the volume, a WAF and rate limiting catch the cleverer application-layer attacks, and capacity plus a response plan keep you standing while it all plays out. For most businesses, DDoS protection is one layer of a broader security posture rather than a standalone product, which is why it usually lives inside professionally managed network services rather than a single tool you install and forget.

 

 

Infographic of the layered DDoS defense stack filtering attack traffic from real users before it reaches the server
No single tool stops a DDoS attack – layered defenses filter the flood upstream so only real traffic gets through.

 

 

What to Do During an Attack

Even with defenses in place, it helps to recognize an attack in progress and respond calmly. CISA notes that the classic symptoms are unusually slow network or website performance and a service becoming unavailable, though a slowdown can have innocent causes too, so it takes confirmation.

  • Confirm it is an attack. Rule out ordinary causes like a traffic spike from a marketing campaign or a hardware failure. Check your traffic logs for a sudden, abnormal surge from many unfamiliar addresses.
  • Engage your provider immediately. Contact your hosting provider, ISP, or DDoS mitigation service. They have tools to absorb and filter attack traffic that you do not have on your own, and getting them involved fast shortens the outage.
  • Do not try to fight it by hand. Manually blocking addresses rarely works against a distributed attack and often blocks real customers. Lean on automated, upstream filtering instead.
  • Preserve evidence and communicate. Keep logs for later analysis, and keep customers informed through a status page or social channel so the silence itself does not do further damage.

The myth that gets businesses hurt

A common and costly belief is that you can stop a DDoS attack the same way you would stop a single intruder, by finding the bad address and blocking it. That works for a single-source DoS attack. It does not work for a distributed one, where the traffic is coming from thousands or millions of addresses at once and many of them are ordinary, innocent devices that were hijacked. Chasing individual addresses during a live DDoS attack wastes the minutes that matter and often knocks your real users offline in the process. The reliable answer is upstream filtering that was arranged before the attack, not manual firefighting during it.

Source: CISA, FBI, and MS-ISAC joint DDoS guidance

When to Call a Professional

Talk to CNiC about protecting your business from DDoS and other attacks

What This Means for Your Business

DDoS attacks have crossed a threshold. They are more frequent, dramatically larger, and increasingly automated, and they no longer skip small and midsize companies. At the same time, the defenses that work, upstream scrubbing, a CDN, a tuned WAF, capacity, and a practiced response plan, are well understood and available. The gap for most businesses is not knowing what to do; it is having the layered setup and the people to run it in place before an attack, rather than scrambling during one.

CNiC Solutions helps Texas businesses build that resilience. Our cybersecurity services combine DDoS mitigation, firewalls, monitoring, and endpoint protection into one layered defense, and because staying online through an attack is also about being able to recover quickly, it pairs with disaster recovery as a service (DRaaS) so a disruption does not become a lasting outage.

Explore managed networking and traffic protection for your business

Frequently Asked Questions

What is a DDoS attack?

A DDoS (distributed denial-of-service) attack is an attempt to knock a website, application, or network offline by flooding it with more traffic than it can handle. The traffic comes from many machines at once, usually a botnet of malware-infected devices, so the target cannot separate real users from the flood and legitimate visitors are locked out.

What is the difference between a DoS and a DDoS attack?

A DoS (denial-of-service) attack comes from a single source, so it is easier to block by cutting off that one address. A DDoS (distributed denial-of-service) attack comes from many sources at once, often thousands or millions of hijacked devices, which makes it far harder to filter and far more powerful. Nearly all serious attacks today are distributed.

How long does a DDoS attack last?

It varies widely. Many modern attacks are short bursts that last only a few minutes but hit at enormous scale; the record 31.4 Tbps attack Cloudflare mitigated in 2025 lasted just 35 seconds. Others are sustained and run for hours or days, or arrive in repeated waves designed to wear down defenders. Short does not mean harmless, because even a brief outage can cost sales and trust.

Can a small business be hit by a DDoS attack?

Yes. Attackers do not only target large corporations. Small and midsize businesses are hit by extortion demands, by competitors, or simply because automated tools found an unprotected server. Because botnets attack at machine scale, the size of your business does not protect you, and a smaller company often has fewer defenses in place to absorb the traffic.

How do you stop a DDoS attack?

You cannot usually stop a live distributed attack by blocking a single address, because the traffic comes from everywhere at once. Effective protection is put in place before an attack: a DDoS mitigation or scrubbing service that absorbs and filters traffic upstream, a web application firewall and rate limiting, a content delivery network to spread load, and an incident response plan. During an attack, engage your provider or a security team rather than trying to fight it manually.

About This Guide and Sources

The definitions and framework in this guide, what a DDoS attack is, the DoS-versus-DDoS distinction, the botnet and command-and-control model, the three attack categories (volumetric, protocol, and application-layer), the detection signs, and the layered defenses, reflect standard characterizations that are consistent across authoritative cybersecurity sources. The three-category framework and the response and symptom guidance follow the joint “Understanding and Responding to Distributed Denial-of-Service Attacks” guidance from CISA, the FBI, and the MS-ISAC. Attack-volume figures (47.1 million attacks mitigated in 2025, a 121% year-over-year increase, an average of 5,376 attacks per hour, and the record 31.4 Tbps peak) come from Cloudflare’s 2025 Q4 DDoS threat report; the figure of more than 8 million attacks in the second half of 2025 comes from NETSCOUT’s DDoS Threat Intelligence Report. The historical Mirai/Dyn (October 2016) and GitHub (February 2018, 1.35 Tbps) attacks are widely documented public events. Businesses should assess their own exposure and defenses against their specific systems and risk profile.

 

author avatar
David McFarlene Founder & CEO
David McFarlene is the owner and founder of CNiC Solutions, a trusted IT services and cybersecurity company serving the Houston, TX area. With over 20 years of experience in managed IT, infrastructure design, cloud solutions, and data security, David helps businesses and homeowners stay protected and productive through dependable, personalized technology support. He leads the CNiC Solutions team with a focus on reliability, transparency, and long-term relationships, ensuring clients always have a knowledgeable expert they can trust.
back to blog