Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a traffic-flood attack?

A traffic flood attempts to exhaust network capacity or connection-handling infrastructure with packets or sessions. Impact depends on bandwidth, protocol, filtering and architecture - not simply the largest number on a graph.

Locate the bottleneck

Preserve packet and protocol type, ports, rates, volume, drops, source and destination, provider data and service performance. If the internet link saturates upstream, application logs may show little even while users cannot connect.

Correlate edge, provider and application observations to identify whether failure occurred at a link, firewall, load balancer or another component. Several regions or links may each show only part of the event.

Compare packet behaviour with normal traffic

Representative captures can show size, flags, repetition and connection state before mitigation changes the pattern. High bandwidth may instead be backup, replication or content delivery, so align it with baseline and degradation time.

Spoofed and reflected traffic limits source attribution. Preserve the technical flood first and use provider evidence to investigate the initiating route.

Key takeaway

Demonstrate where flood traffic exhausted network capacity using provider, packet and performance evidence; missing application events do not disprove an upstream attack.

Reference: CIM-198Cyber Incidents & Offender Methods