Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is a denial-of-service attack?

A denial-of-service attack deliberately makes a service unavailable or materially degraded by exhausting or abusing a resource. An outage alone does not prove attack: failure, maintenance, legitimate demand and defensive containment can produce the same impact.

Identify the failed resource

Establish what became unavailable, when, and whether bandwidth, connections, memory, processor, application workers, database capacity, authentication or a provider quota was exhausted. A few expensive requests can be as disruptive as a large traffic flood.

Firewall, load-balancer, application, provider, performance and response records can connect demand to the resource failure and recovery.

Separate cause, effect and source

Compare the pattern with legitimate explanations and determine whether service recovered when the activity stopped. Where several services failed, map shared dependencies; one identity or network component can create broad downstream impact.

Apparent sources may be botnets, reflectors, proxies or compromised systems and do not identify the controller. Report the technical exhaustion and malicious pattern before personal attribution.

Key takeaway

Prove denial of service by linking deliberate traffic or requests to a specific exhausted resource, while excluding failure, legitimate overload and defensive shutdown.

Reference: CIM-196Cyber Incidents & Offender Methods