Schema eines DDoS-Angriffs: Links ein Angreifer, der Befehle an ein Botnetz aus vielen infizierten Geräten wie Routern und Kameras sendet. Von dort laufen zahlreiche Anfragepfeile über einen Filterdienst zum Zielserver, der überlastet ist, während ein einzelner normaler Nutzer nicht mehr durchkommt.

DDoS

A DDoS attack deliberately overwhelms a website or online service with a flood of requests from thousands of sources until normal users can no longer get through. The attacker doesn't break into anything or steal data, they simply make the service unreachable.

Every website runs on a computer that answers requests from the internet. Such a machine can only handle a certain number of requests per second. In a DDoS attack, someone deliberately sends so many requests that this limit is far exceeded. The site then becomes agonizingly slow or stops responding altogether. Genuine customers find themselves in front of a locked door, even though technically nothing is broken. The abbreviation stands for Distributed Denial of Service, meaning roughly: a distributed refusal of service. “Distributed” means the requests don’t come from a single computer, but from thousands at the same time.

Why a reachable website is worth money

For many companies, the website is the business. An online shop that’s unreachable for an hour sells nothing during that hour. At a bank, customers can’t get to their accounts; at an exchange, orders go nowhere. The damage isn’t caused by lost data, but by lost time and damaged trust.

That’s exactly why DDoS attacks are a tool of extortion. Attackers demand money and threaten to take the service down again otherwise. Other attacks are politically motivated and target authorities, media outlets, or political parties. There are even providers online who carry out attacks for a fee, billed by the hour.

A common misconception: a DDoS attack isn’t a hack in the proper sense. No passwords are cracked and no customer data is copied. Sometimes, however, the overload serves as a distraction while an actual break-in happens elsewhere.

How thousands of other people’s devices become a weapon

A single attacker with a laptop can’t produce the necessary volume of requests. That’s why they use a botnet: a network of devices belonging to other people, infected with malware and obeying commands. This includes poorly secured routers, surveillance cameras, or smart home devices. The owners usually notice nothing.

On command, all these devices query the same website simultaneously. To the server, each individual request looks harmless, coming from a normal internet address. It’s only the sheer volume that constitutes the attack. That’s the real trick: an attack and a normal visit are barely distinguishable.

Some variants don’t rely on volume but on leverage. The attacker sends small requests to other people’s servers while spoofing the sender address. The responses are much larger than the request and all land on the victim. As a defense, companies place large filtering services in front of their servers. These distribute traffic across many data centers and filter out suspicious requests before they arrive.

DDoS in the news and on your own network

DDoS attacks regularly appear in the news when bank websites, airports, or government portals suddenly go down for hours. The 2016 Mirai case became famous: a botnet made up of cameras and video recorders temporarily knocked out Twitter, Spotify, and Netflix via a central internet service. Such incidents also move stock prices, because they show how dependent entire industries are on just a few providers.

In everyday life, people encounter the topic indirectly. The security prompts with checkboxes to click or image puzzles are meant, among other things, to slow down automated floods of requests. Messages like “too many requests, please try again later” are also part of this protective mechanism.

And you can become part of an attack without meaning to. Anyone who never updates their router or never changes a camera’s default password may be supplying a device for a botnet. Updates and unique passwords are therefore not a mere formality. They help determine just how large such attacks can ultimately become.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.