7.2 Denial of Service (DoS/DDoS) Attack Mechanisms and Traffic Mitigation

Key Takeaways

  • Volumetric DDoS attacks overwhelm physical network link capacity using amplification protocols (DNS, NTP, SSDP, Memcached) that leverage UDP spoofing to produce response payloads tens to thousands of times larger than initial queries.

  • Protocol and state-exhaustion attacks saturate state-tracking tables on firewalls, load balancers, and operating system kernels via TCP SYN floods, TCP reset storms, or legacy Smurf ICMP broadcast amplification.

  • Application-layer (Layer 7) attacks—such as Slowloris, Slow POST (RUDY), and HTTP GET floods—consume server thread pools with minimal bandwidth by transmitting requests at agonizingly slow rates or sending incomplete HTTP headers.

  • Upstream Remotely Triggered Black Hole (RTBH) filtering uses BGP communities to drop traffic at the ISP border, where destination-based RTBH sacrifices the target IP to protect the transit network, and source-based RTBH (uRPF) drops malicious sender prefixes.

  • Modern DDoS resilience integrates BGP Anycast routing to distribute volumetric traffic globally across scrubbing centers, hardware-accelerated SYN cookies to mitigate SYN-backlog state exhaustion, and Web Application Firewalls (WAF) to inspect Layer 7 anomalies.

Last updated: October 2026

Denial of Service (DoS/DDoS) Attack Mechanisms and Traffic Mitigation

Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks represent severe operational threats to enterprise availability. Unlike confidentiality or integrity breaches that seek unauthorized access or data theft, denial-of-service campaigns aim to degrade, disrupt, or sever access to critical infrastructure, digital services, and network paths. For incident handlers, rapid vector identification, comprehension of underlying protocol abuses, and swift execution of mitigation playbooks are critical to preserving continuity.

DoS and DDoS Taxonomy: Volumetric, Protocol, and Application-Layer Attacks

Denial-of-service attacks span three primary operational tiers based on the targeted architectural layer:

1. Volumetric Attacks

Volumetric attacks saturate the physical bandwidth of the victim's internet transit uplinks, consuming network pipe capacity through sheer traffic volume:

  • UDP and ICMP Floods: Adversaries transmit continuous streams of User Datagram Protocol (UDP) or ICMP Echo Request packets toward victim IPs. The destination expends cycles inspecting ports and generating unreachable replies, while intermediate transit circuits saturate.
  • Reflection and Amplification Attacks: Adversaries exploit connectionless protocols (primarily UDP) that lack source address validation. By spoofing the victim's IP address as the packet source, attackers dispatch small request payloads to third-party public reflector servers, which return substantially larger response payloads directed at the victim.
    • DNS Amplification: Querying open recursive DNS resolvers for large resource records (e.g., ANY or TXT queries with EDNS0 enabled) yields an amplification factor of 50x to 70x relative to query size.
    • NTP Amplification: Exploiting legacy Network Time Protocol servers supporting the monlist diagnostic query (returning the last 600 client IPs synchronized with the server) achieves reflection factors exceeding 550x.
    • SSDP Amplification: Abusing the Simple Service Discovery Protocol (UDP 1900) on consumer UPnP devices delivers amplification factors of approximately 30x.
    • Memcached Amplification: Targeting Memcached caching daemons exposed on UDP port 11211 without authentication. Attackers pre-load large data blocks and request them via minimal get queries, generating amplification factors between 10,000x and 50,000x to produce terabit-scale floods.

2. Protocol and State-Exhaustion Attacks

Protocol attacks consume state-tracking resources in firewalls, load balancers, and operating system connection tables:

  • TCP SYN Flood: Attackers flood target servers with TCP SYN segments carrying spoofed or randomized source IP addresses. The server responds with SYN-ACK and allocates memory in its Transmission Control Block (TCB) backlog queue. Waiting in the SYN_RECEIVED state for a concluding ACK that never arrives, the server exhausts its embryonic connection table, rejecting legitimate connection requests.
  • TCP Reset (RST) Attacks: Attackers inject forged TCP RST segments matching active session five-tuples (source/destination IP and port, protocol) with anticipated sequence numbers, abruptly tearing down established sessions.
  • Smurf Attacks: A legacy amplification attack where attackers broadcast ICMP Echo Requests with a spoofed victim source IP to an IP broadcast address, prompting all subnet hosts to flood the victim simultaneously. Fraggle attacks execute an identical broadcast flood using UDP echo packets.

3. Application-Layer (Layer 7) Attacks

Layer 7 attacks target application server threads, CPU, and database resources with low-bandwidth, highly targeted HTTP traffic:

  • HTTP GET/POST Floods: High volumes of legitimate-looking HTTP requests targeting resource-intensive operations, such as database searches or complex cryptographic operations.
  • Slowloris: Exploits thread-based HTTP servers (such as Apache). The attacker opens numerous TCP connections and transmits partial HTTP request headers (e.g., User-Agent: Mozilla/5.0\r\n), followed by slow, periodic header fragments (e.g., X-a: b\r\n) every 10 to 15 seconds. The connection remains open indefinitely without timing out, exhausting the server's thread pool (MaxRequestWorkers) with minimal bandwidth.
  • Slow POST / R-U-Dead-Yet (RUDY): Transmits legitimate HTTP POST requests declaring large Content-Length headers (e.g., 100,000 bytes), but injects body data byte-by-byte at lengthy intervals, tying up web application server worker threads.

DDoS Architecture: Botnets, Handlers, and Amplifiers

Distributed DoS attacks require tiered operational infrastructure:

  • Botmasters and Handlers: The human threat actor controls master Command-and-Control (C2) servers or handlers. Commands are distributed via encrypted channels, IRC, web APIs, or decentralized Peer-to-Peer (P2P) topologies.
  • Bots / Zombies: Thousands of compromised endpoints (such as IoT devices running Mirai-derived malware, routers, or vulnerable servers) that receive execution orders from handlers and transmit flood traffic.
  • Reflection and Amplification Infrastructure: External third-party servers (open DNS resolvers, NTP daemons, Memcached instances) that unwittingly reflect and magnify traffic toward the victim without requiring infection.

Containment and Mitigation Strategies

Defending against modern multi-vector DDoS attacks demands multi-tiered perimeter, upstream, and host-level defenses:

  • Remotely Triggered Black Hole (RTBH) Filtering: BGP-based routing coordination between an enterprise and upstream ISPs:
    • Destination-Based RTBH: When an enterprise link saturates, the organization announces a /32 BGP host route for the targeted victim IP tagged with a community string. Upstream ISP border routers set the next-hop to a Null0 discard interface, dropping traffic before it enters the enterprise transit link. This sacrifices the victim IP to protect remaining enterprise infrastructure.
    • Source-Based RTBH: Combined with Unicast Reverse Path Forwarding (uRPF), ISP edge routers drop traffic originating from identified attacking source IP prefixes.
  • BGP Anycast Routing: Enterprises announce the same IP prefix from multiple geographically distributed Points of Presence (PoPs). Inbound flood traffic naturally routes to the topologically closest PoP, dispersing volumetric loads globally rather than overwhelming a single data center link.
  • Cloud DDoS Scrubbing Centers: Cloud providers (Cloudflare, Akamai Prolexic, AWS Shield) ingest traffic via BGP Anycast or DNS proxying. High-capacity scrubbing engines inspect packets in real time, dropping volumetric UDP floods, validating TCP handshakes, and filtering Layer 7 anomalies before passing clean traffic to origin servers via GRE tunnels or private cross-connects.
  • Host and Network Hardening:
    • SYN Cookies (net.ipv4.tcp_syncookies = 1): Mitigates SYN-backlog exhaustion by encoding connection state cryptographically into the Initial Sequence Number (ISN) of the SYN-ACK, allocating kernel memory only when the client returns a valid ACK.
    • Rate Limiting and WAF: Enforcing connection rate limits via iptables/nftables and configuring Web Application Firewalls (WAF) to drop incomplete headers and enforce minimum HTTP body transfer speeds to neutralize Slowloris and RUDY attacks.
Loading diagram...
DDoS Reflection Amplification and Cloud Scrubbing Pipeline
Test Your Knowledge

A major SaaS provider suffers an unprecedented volumetric denial-of-service attack generating over 1.2 terabits per second of ingress traffic. Packet captures reveal that the incoming stream consists of massive UDP packets originating from source port 11211. Analysts determine that external servers responded to small spoofed key-value requests by returning cached payloads with an amplification factor exceeding 10,000 to 1. Which protocol was weaponized to execute this reflection attack?

A

Simple Service Discovery Protocol (SSDP)

B

Network Time Protocol (NTP) monlist

C

Domain Name System (DNS) EDNS0

D

Memcached UDP caching daemon

Test Your Knowledge

A web application server running Apache suddenly stops servicing inbound user connections. The system administrator observes that network bandwidth utilization is under 2 Mbps and CPU load is below 5%. However, netstat telemetry indicates that hundreds of HTTP connections from external IP addresses remain in the ESTABLISHED state, and the web server has reached its MaxRequestWorkers limit. Log inspection reveals that the external clients transmit partial HTTP headers followed by single header lines every 15 seconds without ever sending the terminating carriage-return line-feed (\r\n\r\n) sequence. Which application-layer attack is taking place?

A

A Slowloris attack designed to hold server worker threads open indefinitely by sending slow, periodic header fragments

B

A TCP SYN flood saturating the operating system's embryonic socket backlog queue

C

A Smurf attack broadcasting ICMP Echo requests across the local subnet

D

A Slow POST (RUDY) attack injecting partial SQL statements into form parameters

Test Your Knowledge

During an overwhelming 400 Gbps volumetric DDoS attack that is saturating an enterprise's physical internet uplinks and degrading service for all hosted clients, the network engineering team decides to implement Remotely Triggered Black Hole (RTBH) filtering via BGP. The team advertises a /32 host route for the targeted public web server IP with a specific BGP community string to their upstream ISP. What is the operational effect of this action?

A

The upstream ISP encapsulates all traffic destined for the victim IP inside GRE tunnels and routes it to an off-site forensic sandbox

B

The upstream ISP sets the next-hop for the victim IP to a Null0 discard interface, dropping all traffic destined for that server at the ISP boundary to protect the enterprise's transit bandwidth

C

The upstream ISP activates SYN cookies on the victim web server's local operating system kernel

D

The upstream ISP rewrites the destination IP of incoming packets to an active honeypot on an alternate autonomous system

Sections you finish are checked off in the contents.