Back to glossaryCyber

Distributed denial of service (DDoS)

An attack that saturates an online service under a massive flow of requests from many machines, in order to render it unavailable.

Definition

A distributed denial of service consists of overwhelming an online service, a website, a payment interface or an application server, under a volume of requests so high that it can no longer respond to legitimate users. The term distributed reflects the fact that the attack comes simultaneously from a large number of machines, often grouped into a network of bots, or botnet, made up of devices compromised without their owners' knowledge. Unlike many attacks, the DDoS seeks neither to steal data nor to penetrate the system, but simply to paralyze it, which makes it formidable for activities that depend on their online availability. Its power has become commonplace with the emergence of rental services, which allow an attack to be ordered for a few dozen euros, and it sometimes serves as a diversion or an instrument of blackmail. For insurance, the DDoS translates above all into business interruption linked to unavailability, the scale of which depends on the duration and on the effectiveness of the mitigation measures, such as traffic filtering, that the insured has managed to deploy.

Example

An online retail site suffers, at the height of the sales period, a distributed denial of service attack that makes it inaccessible for several hours. The lost turnover during that unavailability falls under the business-interruption cover of its cyber policy.

Related terms
Also known as

DDoS, déni de service, attaque par saturation