Skip to content
CIM-196 Cyber Incidents & Offender Methods

What is a denial-of-service attack?

The practical answer

A denial-of-service attack is activity intended to make a system, service or network unavailable or significantly degraded.

The key evidential caution

The dangerous assumption is that every outage or slowdown proves deliberate attack.

It may not.

Service disruption can also result from:

Key points

  • configuration error
  • software failure
  • hardware failure
  • overloaded legitimate demand
  • dependency failure
  • expired certificates
  • capacity limits
  • maintenance
  • defensive containment

A denial-of-service attack may attempt to exhaust:

  • bandwidth
  • connections
  • memory
  • processor time
  • application threads
  • database resources
  • authentication systems
  • provider limits

What investigators should establish

Investigators should establish:

Key points

  • what became unavailable
  • when degradation began
  • which resource was exhausted
  • what traffic or requests were involved
  • whether the pattern was deliberate or automated
  • whether the service recovered when the activity stopped
  • what legitimate explanations remain

A large traffic spike may support an attack hypothesis, but volume alone is not enough.

A small number of expensive application requests may also cause major disruption.

Relevant evidence

Relevant evidence may include firewall logs, load balancer records, application logs, provider telemetry, network captures, performance monitoring and incident-response actions.

Evidential limits

Do not assume the apparent source identifies the offender. Attack traffic may come through botnets, reflectors, proxies or compromised systems.

Where several services fail together, identify whether they share one dependency, network path or identity service. A single exhausted component can create a much wider outage than the number of directly attacked systems suggests. Preserve dependency and failover records so the true cause of the operational impact is not overstated.

Operational takeaway

Prove the specific resource exhaustion and malicious traffic pattern, and distinguish deliberate denial of service from failure, overload and defensive shutdown.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.