Get fresh insights, pro tips, and thought starters–only the best of posts for you.
A distributed denial of service (DDoS) attack floods a target server, service, or network with overwhelming traffic from multiple sources, making it unavailable to legitimate users. Unlike a standard denial of service (DoS) attack, which originates from a single source, a DDoS attack uses a network of compromised devices, known as a botnet, to generate traffic from thousands or even millions of distinct sources simultaneously. This distributed nature makes DDoS attacks significantly harder to block using simple IP filtering.
Attackers typically do not need to steal data to succeed. The goal is disruption, taking a service offline long enough to cause financial loss, reputational damage, or to serve as a distraction for other malicious activity.
A DDoS attack generally unfolds in three stages.
Botnets used in DDoS attacks often consist of devices whose owners are unaware their hardware has been compromised.
| Attack Type | Target Layer | Method |
| Volumetric attacks | Network bandwidth | Flooding with massive traffic volume to exhaust bandwidth |
| Protocol attacks | Network and transport layers | Exploiting weaknesses in protocols like TCP/IP to exhaust server resources |
| Application-layer attacks | Application layer (Layer 7) | Overwhelming specific application functions, such as login or search requests |
Attackers frequently combine multiple attack types within a single campaign to bypass layered defenses.
DDoS attacks can take critical services offline for hours or days, directly impacting revenue and customer trust. E-commerce platforms, financial services, and any business dependent on continuous uptime are common targets.
Beyond the immediate outage, unmanaged and poorly secured devices within an organization can unknowingly become part of the problem. Compromised endpoints recruited into a botnet contribute to attacks against other targets, exposing the organization to reputational and legal risk.
Devices infected with botnet malware are frequently the building blocks of DDoS attacks, and unmanaged endpoints are especially vulnerable to this kind of compromise.
Hexnode UEM reduces this risk by enforcing security policies and continuous compliance monitoring across managed devices, including Android and IoT endpoints, and by configuring firewall controls on supported platforms like macOS.
By maintaining visibility and control over the device fleet, Hexnode helps ensure managed devices do not become an unwitting source of attack traffic against other organizations.
No, a DDoS attack by definition relies on distributed traffic sources, typically from a botnet, distinguishing it from a single-source DoS attack.
No, most DDoS attacks aim to disrupt availability rather than steal data, though they can be used as a distraction during a separate breach attempt.
Yes, launching a DDoS attack is a criminal offense in most countries under computer fraud and cybercrime laws.