What is a DDoS attack and how does it work?
A DDoS — distributed denial of service — attack overwhelms a service with traffic until it cannot serve legitimate users. The goal is not to steal data or break in; it is simply to make something unavailable.
Why "distributed". A single machine sending traffic is easy to block. A botnet of thousands or millions of compromised devices — often poorly secured IoT cameras, routers and DVRs — sends traffic from countless addresses simultaneously, making it very hard to distinguish attackers from users.
The main categories:
Volumetric attacks simply saturate bandwidth. Amplification is the technique that makes these enormous: the attacker sends small requests to misconfigured public servers — DNS, NTP, memcached — spoofing the victim's address as the sender. Each server replies to the victim with a response many times larger than the request. A modest attacker can generate traffic hundreds of times their own capacity.
Protocol attacks exhaust connection state rather than bandwidth. A SYN flood opens huge numbers of half-finished TCP connections, filling the server's connection table so genuine ones are refused.
Application-layer attacks are the subtlest. They send small volumes of legitimate-looking requests aimed at expensive operations — a complex search query, a login, a report generation. Traffic volume can be trivial while the server is brought down, and these are hardest to filter because each request looks real.
Why they are hard to stop. Blocking traffic requires distinguishing it from real users, and by the time it reaches your server the bandwidth is already consumed.
Defences involve absorbing traffic upstream: CDN and scrubbing services with capacity far exceeding any single origin, rate limiting, and anycast routing that spreads traffic across many locations.
Motivations range from extortion and hacktivism to competitive sabotage and distraction from an intrusion elsewhere. Rentable "booter" services have made launching one cheap.