denial-of-service attack
Let an agent explain denial-of-service attacks for defence, detection, response and reporting, without giving any help to carry one out.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify
Researched by: Claude
Purpose and description
Let an agent explain denial-of-service attacks for defence, detection, response and reporting, without giving any help to carry one out.
A cyberattack that makes a service, network or machine unavailable to its intended users by overwhelming or exhausting its resources; distributed attacks (DDoS) use many sources at once.
What it is for: Understanding a threat in order to protect services.
It can be prepare defences with providers; detect and mitigate attacks; respond and communicate during incidents; report attacks to authorities or CERTs.
Distinguishing features
Targets availability
Single-source or distributed
Illegal in most jurisdictions
Mitigated by filtering, capacity and scrubbing services
What it looks like
Services slow down or become unreachable; traffic graphs spike.
How it is recognised
Sudden traffic spikes and timeouts
Categories such as volumetric, protocol and application layer
Legitimate traffic surges look similar
Related models
is a kind of - category
targets - security property
is mitigated by - defence
is prohibited by - law
In practice
Families and kinds
volumetric attacks
protocol attacks
application-layer attacks
distributed denial of service
resource exhaustion attacks
Standards and regulation
Council of Europe Budapest Convention
National computer misuse laws
NIS2 incident reporting
NIST SP 800-61 incident handling
Failure modes and hazards
Service outages affecting essential services
Mistaking legitimate surges for attacks
Attacks used as cover for other intrusions
Also called
Where this came from
wikidata · CC0 1.0
Drafted structure
Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.
Detection Is it an attack.
Detection starts response.
Signs
Symptoms.
Signs
Signs.
- Is the outage caused by an attack or a legitimate surge? boundary
- Which monitoring data shows it? provenance
Category
Layer.
Category
Attack category.
- Is it volumetric, protocol or application layer? definition
- Which resources are exhausted? measurement
Mitigation Defence.
Defence needs preparation.
Provider
Upstream help.
Provider
Provider mitigation.
- Does the hosting or network provider offer DDoS protection? action
- How is it activated? action
Architecture
Resilience.
Architecture
Resilient design.
- Which design measures improve resilience? action
- Are they tested? provenance
Response During an incident.
Response limits damage.
Plan
Incident plan.
Plan
Incident plan.
- What does the incident response plan say? action
- Who is on call? provenance
Communication
Users.
Communication
User communication.
- How are users informed? action
- Where is the status page? provenance
Law Reporting and limits.
DoS is a crime.
Reporting
Authorities.
Reporting
Reporting.
- Must the incident be reported, and to whom? boundary
- Within what deadline? measurement
Limits
No facilitation.
Limits
What not to provide.
- Is the request asking how to launch an attack? boundary
- How should the agent respond? action
What the second pass must settle
- Should attack categories be separate entries?
- How should incident reports be linked?
- How should defensive guidance be kept free of offensive detail?