Back to glossaryCyber

DDoS attack (Distributed Denial of Service)

Attack aimed at exhausting a target system's resources by deploying a network of compromised machines, rendering the service unavailable.

Definition

A Distributed Denial of Service (DDoS) attack seeks to render a service, website or infrastructure unavailable by overwhelming it with requests or network traffic generated by a large number of compromised machines, a botnet. The distributed nature of the attack distinguishes it from a simple denial of service, as the multiplicity of sources makes filtering and blocking far more difficult. Several categories of DDoS attacks are distinguished by their mechanism. Volumetric attacks saturate the target's bandwidth with raw traffic volume, often amplified by UDP protocols such as DNS or NTP that respond with packets far larger than the initial request. Application-layer attacks target the server's software resources, for instance by generating complex HTTP requests to exhaust processing capacity. State-exhaustion attacks saturate the session tables of network devices. From an insurance perspective, DDoS attacks are covered by cyber business-interruption cover when they cause service downtime, but quantifying the duration of interruption and the lost revenue often requires both technical and accounting expertise. In triple-extortion attacks, DDoS is used as an additional pressure lever simultaneously with ransomware.

Example

During the Paris Olympics in 2024, pro-Russian hacktivist groups launched waves of DDoS attacks against French institutional and media websites. Some operators suffered outages measured in hours, triggering their cyber business-interruption cover.

Related terms
Also known as

DDoS, Distributed Denial of Service, déni de service distribué, attaque volumétrique