• Blackhat Pakistan — Ethical Hacking, Hacking Tools & Cybersecurity Tutorials

DDoS Attack Basics

Blackhatpakistan

Administrator
Staff member
Joined
Dec 30, 2024
Messages
396
Reaction score
208
Points
62
Website
blackhatpakistan.net
Points
1,108
USD
1,108
A DDoS attack is a denial-of-service assault launched from many distributed sources at once - thousands of compromised hosts, IoT devices, or rented nodes hammering one target until legitimate traffic cannot get through. The mechanics split into three families: volumetric floods that saturate bandwidth, protocol attacks that exhaust connection tables and state, and application-layer attacks that exhaust the server's own resources. Mitigation works by filtering at the layer being attacked, which is why understanding which family you face matters more than any single tool.

TL;DR - Three families: volumetric (bandwidth saturation, bps), protocol (state exhaustion, pps), application (server resource exhaustion, rps). Amplification (DNS, NTP, memcached) multiplies small requests into large responses pointed at the victim. Defense is layered: upstream scrubbing for volume, anycast and CDN distribution for absorption, rate limiting and challenge-response for L7. Detection starts with the signature - which resource is exhausted tells you which family you are in.

es33hx.png


THE THREE FAMILIES

Volumetric - raw traffic volume: UDP floods, DNS/NTP amplification, carpet-bombing across subnets. Measured in bits or packets per second. The target's pipe fills; everything behind it starves including management traffic.

Protocol - connection-state exhaustion: SYN floods filling the half-open table, fragmented packet reassembly buffers, slowloris holding sockets open for minutes. Measured in pps or concurrent connections. The bandwidth looks fine while the service collapses under state it can never complete.

Application (L7) - HTTP-level resource exhaustion: requests that are individually cheap and collectively ruinous (search endpoints, expensive API calls, login POSTs), or randomized paths that defeat caching. Measured in requests per second. The wire has headroom; the database does not.











asd8pf.png


AMPLIFICATION - THE MULTIPLIER


- DNS and NTP reflection - a tiny query with a spoofed source address, answered with a response tens to hundreds of times larger, directed at the victim.

- Memcached over UDP (the historical 50,000x case) - unauthenticated amplifiers exposed to the internet; mostly patched away by now, but the pattern recurs in new protocols.

- chargen, SSDP, CharGEN-class legacy services - old protocols that answer anything and never got hardened because nobody uses them anymore.

- Botnet floods - Mirai-lineage IoT armies and residential proxy networks delivering application-layer volume from real ISP ranges that blocklists struggle to cut.

Spoofed reflection needs a network that still forwards packets with forged source addresses (BCP38 violations); botnets do not care and produce clean-source floods that look like real users, which is exactly why L7 botnet traffic is the hardest family to filter.

MEASUREMENT - WHAT THE NUMBERS MEAN

Bandwidth floods are rated in Gbps (a 2024-era event on record exceeded 5 Tbps peak across the observed DDoS landscape; the largest application-layer events run in millions of requests per second). Protocol attacks rate in pps and concurrent-connection counts. L7 attacks rate in rps against a specific endpoint - and the comparison that matters is rps against YOUR provisioned capacity, not against some internet-wide record. A 50k rps flood on a single origin with no CDN is a total outage; the same flood against an anycasted edge is noise.











a55l4i.png


MITIGATION BY LAYER


- Upstream scrubbing / ISP blackhole - volumetric attacks go to the transit provider, because filtering at the victim means the pipe is already full. RTBH (remote triggered black hole) sacrifices the target prefix to save the rest of the network.

- Anycast and CDN absorption - distribute the load across the provider's global edge; the attack gets split until each node's share fits its capacity.

- SYN cookies, connection limits, and tuned timeout tables - protocol-layer state exhaustion fixes are configuration, not hardware.

- Rate limiting per IP and per session - blunt but effective for L7; the sophistication lives in choosing what to count (requests, expensive endpoints, login attempts).

- Challenge-response and JS/TLS fingerprinting at the edge - separates browsers from scripted clients; botnets increasingly solve these, which is why it is a layer and not a wall.

- Application-level defense - caching expensive endpoints, precomputing search suggestions, moving cost off the request path entirely. An endpoint that costs nothing cannot be exhausted.











fty6g2.png


DETECTION AND VERIFICATION


Confirm it is an attack and not organic load: traffic shape (source distribution, request-path distribution, header and TLS fingerprint spread), correlation with the resource under pressure (bandwidth, connection table, app CPU, DB queries), and comparison against the same hour last week. Synthetic monitoring from outside the affected path tells you whether the site is down for everyone or just degraded for some. Once family is identified, the mitigation list above narrows to the matching layer - and the measurement continues, because attackers probe defenses by shifting family mid-attack (volumetric first, L7 after the scrubbing gets tuned).

FAQ

Q: Is a DDoS attack traceable to the attacker?

A: Reflection traffic traces to innocent amplifiers; botnet traffic traces to compromised devices; the coordination layer (C2, rental panels) is where attribution effort actually goes. Individual sources are rarely the point.

Q: Does more bandwidth solve DDoS?

A: It solves volumetric attacks below the new ceiling and nothing else. Protocol and L7 attacks do not care about pipe size - they target state and application cost, which is why providers sell scrubbing, not just bandwidth.

Q: What does mitigation cost at small scale?

A: A CDN with DDoS protection covers most L7 and a large slice of volumetric for free tiers upward; transit-provider scrubbing is the volumetric answer when you have transit; the application-side work (rate limits, caching, cost reduction) is engineering time, always available, never optional.

Q: How do defenders tell a DDoS from a flash crowd?

A: Request quality: a flash crowd lands on content with normal headers, referrers, and navigation patterns; a flood shows header uniformity, path randomization or repetition, missing browser fingerprints, and no page-depth progression. Source spread across ASNs versus concentration in proxy ranges is the second tell.

RELATED ON BLACKHAT PAKISTAN

Nmap Cheat Sheet 2026 - traffic and service enumeration before capacity planning.

SQL Injection Tutorial - the L7 attack surface these floods aim at.

Burp Suite Tutorial for Beginners 2026 - request-level analysis of application traffic.

Metasploit Tutorial - related infrastructure for authorized testing engagements.
 
Last edited:
Threads
1,082Threads
Messages
2,148Messages
Members
3,708Members
Latest member
marsmarsmarsLatest member
Top