A DDoS attack (distributed denial-of-service attack) is an attempt to take a website, application, or network offline by flooding it with far more traffic than it can handle. The flood comes from many machines at once, usually a botnet of malware-infected devices, so the target cannot tell real visitors from the attack and legitimate users are shut out. The goal is not to steal data but to deny access, causing downtime, lost revenue, and reputational damage.
A DDoS attack works like a deliberate traffic jam aimed at your business. Instead of one attacker knocking on your door, thousands or millions of hijacked devices all request your website at the same instant, until your server slows to a crawl or collapses and real customers cannot get through. These attacks are not rare or shrinking: Cloudflare mitigated 47.1 million DDoS attacks in 2025, a 121% jump over the previous year, and the largest single attack on record peaked at a staggering 31.4 terabits per second. This guide explains what a DDoS attack is, how one actually works, the main types, how big they have gotten, and, most important, how to stop them.
DDoS stands for distributed denial-of-service. Break the name down and it explains itself. “Denial of service” means the goal is to deny legitimate users access to a service, whether that is your website, your customer portal, your email, or an application your staff depends on. “Distributed” means the attack does not come from one place; it is spread across many machines firing at the same target simultaneously.
The distinction that matters is between a DoS attack and a DDoS attack. A plain DoS (denial-of-service) attack comes from a single source, so a defender can often stop it by identifying and blocking that one address. A DDoS attack comes from hundreds, thousands, or even millions of sources at once. That difference is everything: you cannot simply block one address when the traffic is arriving from everywhere, and the combined firepower of many machines is vastly greater than any single computer could produce.
It is worth being clear about what a DDoS attack is not. Unlike a data breach or ransomware, a classic DDoS attack does not break in and steal or encrypt your information. Its weapon is disruption. The damage is downtime: lost sales while your storefront is unreachable, staff unable to work, missed service commitments, and the reputational hit of customers finding your business offline. Attackers increasingly use that disruption for extortion, threatening or launching an attack and demanding payment to make it stop.
Almost every large DDoS attack is powered by a botnet. A botnet is a network of internet-connected devices, home computers, servers, and increasingly Internet of Things gadgets like cameras, routers, and thermostats, that have been infected with malware and can be controlled remotely without their owners’ knowledge. The attacker who controls them is often called a bot-herder, and the infected devices are sometimes called zombies.
Here is the sequence in plain terms:
The reason this is so effective is that the malicious traffic is designed to look like ordinary traffic, and it arrives from countless different addresses spread around the world. The server cannot easily tell which requests are real customers and which are the attack, so blunt filtering risks blocking your actual users along with the flood. There is also a second lesson hiding here: any unpatched device on your own network, an old PC or a forgotten smart camera, can be conscripted into a botnet and used to attack someone else, which is one more reason endpoint security and patching matter.

If you want to go deeper on the machinery behind these attacks, our explainer on how bots and botnets operate breaks down the good-versus-bad split and how devices get recruited in the first place.
Source: Cloudflare’s DDoS learning center
Not all DDoS attacks work the same way. CISA, the FBI, and the MS-ISAC group them into three categories in their joint guidance, based on which part of your infrastructure the attack tries to exhaust. Understanding the categories matters because each one calls for a different defense, and sophisticated attackers often combine several at once.
These are the brute-force floods most people picture. The attacker aims to consume all of your available bandwidth by sending an enormous volume of traffic, so much that the pipe to your network is simply full and nothing else gets through. Volumetric attacks are measured in bits per second, and the record-breaking multi-terabit attacks in the news are almost always this type. Amplification techniques, which trick other servers into sending large responses to your address, let attackers generate far more traffic than their own devices could alone.
Instead of filling your bandwidth, protocol attacks exhaust the resources of network equipment such as firewalls and load balancers by abusing the way network protocols work. A classic example is the SYN flood, which opens huge numbers of half-finished connections that tie up the server’s connection table until it can accept no new legitimate connections. These attacks are measured in packets per second and can take down infrastructure with far less raw bandwidth than a volumetric flood.
The most targeted type aims at the application itself, the actual website or service, rather than the network around it. By sending requests that look legitimate but are deliberately expensive for the server to answer, such as repeatedly hitting a search function or login page, an attacker can bring a site down with a relatively small amount of traffic. Because each request resembles a normal user action, these attacks are among the hardest to detect and filter.

Source: CISA, FBI, and MS-ISAC joint DDoS guidance
DDoS attacks are not a fringe threat, and they are growing quickly in both number and size. The scale is worth seeing plainly, because it explains why do-it-yourself defenses no longer hold up.
To put that in perspective, Cloudflare reported averaging 5,376 attacks mitigated every hour across 2025. Attack sizes have escalated so fast that records now fall within weeks of each other, driven by powerful new IoT botnets. The chart below shows how the largest recorded attack has climbed, measured in terabits per second (Tbps):
Record DDoS Attack Size Over Time (peak Tbps)
The historical anchors are just as telling. In October 2016, the Mirai botnet, built largely from insecure IoT devices, attacked the DNS provider Dyn and knocked major sites including Twitter, Netflix, Reddit, and Spotify offline for much of the eastern United States. In February 2018, GitHub was hit by what was then the largest attack ever recorded at 1.35 Tbps, using a memcached amplification technique. Those once-shocking numbers are now dwarfed by the multi-terabit attacks of today, which is exactly why protection has had to move upstream to networks built to absorb that kind of volume.
Source: Cloudflare 2025 Q4 DDoS threat report | NETSCOUT DDoS Threat Intelligence Report
The single most important thing to understand about stopping a DDoS attack is that the real work happens before one ever arrives. Once a distributed flood is underway, you cannot simply block the source, because the traffic is coming from everywhere at once, and trying to filter it by hand usually blocks real customers too. Effective defense is layered, and most of it is set up in advance. Here is what actually protects a business, roughly in order of impact:
The through-line is that these controls work together. A scrubbing service and CDN absorb the volume, a WAF and rate limiting catch the cleverer application-layer attacks, and capacity plus a response plan keep you standing while it all plays out. For most businesses, DDoS protection is one layer of a broader security posture rather than a standalone product, which is why it usually lives inside professionally managed network services rather than a single tool you install and forget.

Even with defenses in place, it helps to recognize an attack in progress and respond calmly. CISA notes that the classic symptoms are unusually slow network or website performance and a service becoming unavailable, though a slowdown can have innocent causes too, so it takes confirmation.
A common and costly belief is that you can stop a DDoS attack the same way you would stop a single intruder, by finding the bad address and blocking it. That works for a single-source DoS attack. It does not work for a distributed one, where the traffic is coming from thousands or millions of addresses at once and many of them are ordinary, innocent devices that were hijacked. Chasing individual addresses during a live DDoS attack wastes the minutes that matter and often knocks your real users offline in the process. The reliable answer is upstream filtering that was arranged before the attack, not manual firefighting during it.
Source: CISA, FBI, and MS-ISAC joint DDoS guidance
If your business relies on its website, portal, or applications being available, and for most businesses today that is a yes, DDoS protection is not a place to improvise. The moment you cannot confidently answer “who absorbs the traffic if we get hit, and how fast,” it is time to bring in help. That is doubly true if you are already seeing repeated slowdowns, extortion threats, or attacks that keep coming back in waves.
A managed security or IT provider sets up the upstream mitigation, tunes the WAF and rate limiting to your traffic, builds the redundancy and response plan, and monitors for attacks around the clock so someone is watching when one starts at 2 a.m. Because DDoS resilience overlaps with keeping your whole environment patched, monitored, and recoverable, it fits naturally into ongoing managed IT services rather than a one-time purchase.
Talk to CNiC about protecting your business from DDoS and other attacks
DDoS attacks have crossed a threshold. They are more frequent, dramatically larger, and increasingly automated, and they no longer skip small and midsize companies. At the same time, the defenses that work, upstream scrubbing, a CDN, a tuned WAF, capacity, and a practiced response plan, are well understood and available. The gap for most businesses is not knowing what to do; it is having the layered setup and the people to run it in place before an attack, rather than scrambling during one.
CNiC Solutions helps Texas businesses build that resilience. Our cybersecurity services combine DDoS mitigation, firewalls, monitoring, and endpoint protection into one layered defense, and because staying online through an attack is also about being able to recover quickly, it pairs with disaster recovery as a service (DRaaS) so a disruption does not become a lasting outage.
Explore managed networking and traffic protection for your business
The definitions and framework in this guide, what a DDoS attack is, the DoS-versus-DDoS distinction, the botnet and command-and-control model, the three attack categories (volumetric, protocol, and application-layer), the detection signs, and the layered defenses, reflect standard characterizations that are consistent across authoritative cybersecurity sources. The three-category framework and the response and symptom guidance follow the joint “Understanding and Responding to Distributed Denial-of-Service Attacks” guidance from CISA, the FBI, and the MS-ISAC. Attack-volume figures (47.1 million attacks mitigated in 2025, a 121% year-over-year increase, an average of 5,376 attacks per hour, and the record 31.4 Tbps peak) come from Cloudflare’s 2025 Q4 DDoS threat report; the figure of more than 8 million attacks in the second half of 2025 comes from NETSCOUT’s DDoS Threat Intelligence Report. The historical Mirai/Dyn (October 2016) and GitHub (February 2018, 1.35 Tbps) attacks are widely documented public events. Businesses should assess their own exposure and defenses against their specific systems and risk profile.
A data center is a physical facility that houses the servers, storage, and networking equipment a…
A checksum is a small value calculated from a block of digital data, used to detect…
A brute force attack is a trial-and-error method for cracking a password, PIN, or encryption key…
TTPs, short for tactics, techniques, and procedures, describe how a cyber attacker behaves: the goal they…