What is a distributed denial-of-service attack?¶
A distributed denial-of-service attack uses many sources or intermediaries to disrupt a target. Many source addresses do not mean many offenders; one campaign can coordinate compromised devices, reflectors, proxies or cloud systems.
Characterise each attack phase¶
Preserve target, start and end, protocol, request pattern, source distribution, volume, affected resource and mitigation. Native provider flows and packet features may show traffic blocked before reaching the organisation.
If the method changes, report phases separately rather than one average. Source count can be distorted by spoofing and reflection and should not be used as a device or actor count.
Exclude legitimate distributed demand¶
Global users, content delivery, popular events and failed software updates can create sudden multi-source traffic. Compare request content, timing, geography and impact with the service's real baseline.
Source systems may be innocent victims. Attribute participating infrastructure, coordination and personal direction as separate layers, using control-channel or provider evidence for the latter.
Key takeaway
Establish a coordinated distributed disruption pattern and its resource impact, without equating source addresses with offenders or every traffic surge with attack.