What is a traffic-flood attack?¶
A traffic flood attempts to exhaust network capacity or connection-handling infrastructure with packets or sessions. Impact depends on bandwidth, protocol, filtering and architecture - not simply the largest number on a graph.
Locate the bottleneck¶
Preserve packet and protocol type, ports, rates, volume, drops, source and destination, provider data and service performance. If the internet link saturates upstream, application logs may show little even while users cannot connect.
Correlate edge, provider and application observations to identify whether failure occurred at a link, firewall, load balancer or another component. Several regions or links may each show only part of the event.
Compare packet behaviour with normal traffic¶
Representative captures can show size, flags, repetition and connection state before mitigation changes the pattern. High bandwidth may instead be backup, replication or content delivery, so align it with baseline and degradation time.
Spoofed and reflected traffic limits source attribution. Preserve the technical flood first and use provider evidence to investigate the initiating route.
Key takeaway
Demonstrate where flood traffic exhausted network capacity using provider, packet and performance evidence; missing application events do not disprove an upstream attack.