Distributed Denial of Service — coordinated attack that floods a target service with traffic from many sources, overwhelming capacity until legitimate users can't connect.
DDoS attacks come in three layers: volumetric (sheer bandwidth saturation, often via amplification techniques like DNS reflection), protocol (exhaust connection state via SYN floods, malformed packets), and application layer (HTTP floods that look like real users). Defenses include traffic scrubbing services (Cloudflare, AWS Shield), rate limiting, anycast routing to distribute load, and CDN absorption. The attack surface is increasingly low-cost; defense remains an expensive arms race.
Cloudflare absorbing a 3.8 Tbps DDoS on a customer site that would have been unrecoverable on origin servers.
DDoS is the most common attack on public services because it's cheap and hard to fully prevent — every internet-facing system needs at minimum a CDN/WAF layer that can absorb volumetric attacks.
Need help implementing this in your business?
Get Started