← Back to catalogue
Research draft

denial-of-service attack

vr.tr.denial-of-service-attack · XCT.TME

Let an agent explain denial-of-service attacks for defence, detection, response and reporting, without giving any help to carry one out.

Thing Registry Cross-cutting context

Research draft, second pass

A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.

written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify

Researched by: Claude

Purpose and description

Let an agent explain denial-of-service attacks for defence, detection, response and reporting, without giving any help to carry one out.

A cyberattack that makes a service, network or machine unavailable to its intended users by overwhelming or exhausting its resources; distributed attacks (DDoS) use many sources at once.

What it is for: Understanding a threat in order to protect services.

It can be prepare defences with providers; detect and mitigate attacks; respond and communicate during incidents; report attacks to authorities or CERTs.

Distinguishing features

Targets availability

Single-source or distributed

Illegal in most jurisdictions

Mitigated by filtering, capacity and scrubbing services

What it looks like

Services slow down or become unreachable; traffic graphs spike.

How it is recognised

Sudden traffic spikes and timeouts

Categories such as volumetric, protocol and application layer

Legitimate traffic surges look similar

Related models

is a kind of - category

cyberattack

targets - security property

availability

is mitigated by - defence

network security

is prohibited by - law

computer misuse law

In practice

Families and kinds

volumetric attacks

protocol attacks

application-layer attacks

distributed denial of service

resource exhaustion attacks

Standards and regulation

Council of Europe Budapest Convention

National computer misuse laws

NIS2 incident reporting

NIST SP 800-61 incident handling

Failure modes and hazards

Service outages affecting essential services

Mistaking legitimate surges for attacks

Attacks used as cover for other intrusions

Also called

resource exhaustion attackdistributed denial-of-service attackTeardrop attackping of deathHTTP Floodpacket drop attackUDP flood attackbillion laughs attackemail bombChristmas tree packetfork bombfloodingINVITE of DeathSmurf attackping floodInternet Relay Chat floodSYN floodHTTP POST flood

Where this came from

wikidata · CC0 1.0

Drafted structure

Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.

Detection Is it an attack.

Detection starts response.

Signs

Symptoms.

Signs

Signs.

  1. Is the outage caused by an attack or a legitimate surge? boundary
  2. Which monitoring data shows it? provenance

Category

Layer.

Category

Attack category.

  1. Is it volumetric, protocol or application layer? definition
  2. Which resources are exhausted? measurement
Mitigation Defence.

Defence needs preparation.

Provider

Upstream help.

Provider

Provider mitigation.

  1. Does the hosting or network provider offer DDoS protection? action
  2. How is it activated? action

Architecture

Resilience.

Architecture

Resilient design.

  1. Which design measures improve resilience? action
  2. Are they tested? provenance
Response During an incident.

Response limits damage.

Plan

Incident plan.

Plan

Incident plan.

  1. What does the incident response plan say? action
  2. Who is on call? provenance

Communication

Users.

Communication

User communication.

  1. How are users informed? action
  2. Where is the status page? provenance
Law Reporting and limits.

DoS is a crime.

Reporting

Authorities.

Reporting

Reporting.

  1. Must the incident be reported, and to whom? boundary
  2. Within what deadline? measurement

Limits

No facilitation.

Limits

What not to provide.

  1. Is the request asking how to launch an attack? boundary
  2. How should the agent respond? action

What the second pass must settle

  • Should attack categories be separate entries?
  • How should incident reports be linked?
  • How should defensive guidance be kept free of offensive detail?