Skip to content
CIM-198 Cyber Incidents & Offender Methods

What is a traffic-flood attack?

The practical answer

A traffic-flood attack attempts to overwhelm network capacity or infrastructure with a large volume of packets or connections.

The key evidential caution

The dangerous assumption is that the largest traffic event is always the most harmful or most significant.

Impact depends on:

Key points

  • available bandwidth
  • network design
  • filtering
  • provider capacity
  • protocol
  • packet size
  • connection state
  • target architecture

Evidence to preserve

Investigators should preserve:

Key points

  • traffic volume
  • packet and protocol type
  • source and destination details
  • timestamps
  • ports
  • connection rates
  • dropped traffic
  • provider and mitigation logs
  • service-performance data

A traffic flood may saturate the internet link before traffic reaches the application.

In that case, application logs may show little or nothing even though users cannot connect.

Evidential limits

Do not assume missing application events mean there was no attack.

Likewise, high bandwidth use may result from legitimate backup, replication or content delivery.

Compare the traffic with the normal baseline and the timing of service degradation.

Spoofed or reflected traffic may make source attribution difficult.

Where packet captures are available, preserve representative samples before mitigation changes the traffic. Packet size, flags, protocol behaviour and repetition may help distinguish a flood from ordinary high-volume transfer. Upstream providers may also see the saturation point more clearly than the target organisation.

Traffic may also be fragmented across several links, providers or cloud regions. One local graph may understate the total attack or overstate its effect on a particular service. Correlate edge, provider and application observations to identify where the bottleneck actually occurred.

Operational takeaway

Establish whether traffic exhausted network capacity, preserve provider and packet-level evidence and avoid relying on application logs alone.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.