Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is an application-layer denial-of-service attack?

An application-layer attack abuses service functions so processing becomes unavailable or slow. Low traffic volume can cause high impact when each request triggers expensive login, search, report, API or database work.

Preserve request path, parameters, account or session, rate, responses, server errors, worker and database activity, latency and resource consumption. Individual requests may be valid; automation, repetition, sequence or deliberate selection of an expensive function can create the abuse.

Authenticated requests are not automatically legitimate. Retain tokens, rate-limit and challenge events that show how the application treated them.

Exclude defects and normal demand

Poor code, database failure and configuration can cause the same symptoms. Compare requests with normal behaviour and establish whether the targeted function, rather than a general fault, exhausted the resource.

Provider and application telemetry should connect the request sequence to failure and recovery. State whether the evidence proves abusive use, a vulnerable design or both.

Key takeaway

Prove application-layer denial by connecting repeated or crafted requests to the specific backend resource failure, not by traffic volume alone.

Reference: CIM-199Cyber Incidents & Offender Methods