What Is a DDoS Attack? Explained Simply
How flooding a website with traffic knocks it offline, why it's hard to stop, and how sites defend against it.
What a DDoS attack is
A DDoS attack, short for distributed denial-of-service, is an attempt to make a website or online service unavailable by overwhelming it with a flood of traffic. Every server has a limit to how many requests it can handle; a DDoS attack deliberately exceeds that limit, so the service slows to a crawl or crashes entirely, denying access to legitimate users. It is one of the most common ways attackers disrupt online services, and unlike a data breach, the goal is not to steal information but to take a service down.
The 'distributed' part
The 'distributed' in DDoS is what makes it powerful and hard to stop. Rather than attacking from a single computer (which could be easily blocked), the attack comes from many sources at once, often thousands or millions of devices spread around the world. This flood from countless different addresses simultaneously is far harder to filter, because you cannot simply block one origin. The distributed nature is precisely what gives these attacks their scale and resilience.
Botnets: the attack army
Where do all those attacking devices come from? Often from a 'botnet', a network of internet-connected devices that have been infected with malware and are secretly controlled by the attacker. These can include not just computers but poorly secured smart-home gadgets and other Internet of Things devices. The owners usually have no idea their device is participating. When the attacker commands the botnet, all these hijacked devices flood the target at once, providing the massive, distributed firepower a DDoS attack needs.
Why it's hard to stop
DDoS attacks are difficult to defend against for several reasons. The traffic comes from a huge number of legitimate-looking sources, so telling attack traffic from real users is genuinely hard. The sheer volume can overwhelm not just the target but the network infrastructure around it. And attackers constantly vary their methods. Simply adding more server capacity is often not enough against a large, determined attack. This combination of scale, disguise, and adaptability makes DDoS a persistent challenge.
How services defend
Defending against DDoS typically means using specialized services and infrastructure built to absorb and filter huge traffic volumes. These systems sit in front of a website, detecting attack patterns and filtering out malicious traffic while letting real users through, often distributing traffic across many servers and locations so no single point is overwhelmed. Large content-delivery and security providers offer this protection at scale. For most websites, relying on such a provider is the practical defense, since fighting a large DDoS alone is beyond most individual servers.
Why it matters
DDoS attacks affect everyone indirectly: they are used to disrupt businesses, extort ransoms (pay or stay offline), silence websites, and cause chaos. They are also a reason your smart devices' security matters, an unsecured gadget can be conscripted into a botnet used to attack others. Understanding DDoS explains a common category of internet outage and underscores why keeping your own devices updated and secured is not just about protecting yourself, but about not becoming an unwitting part of someone else's attack.
Related on Skillo
See also: What is a firewall? Network security explained, What is the Internet of Things (IoT) explained.
Sources
Published date reflects the original event date (2025-01-28). This article is original Skillo editorial written from the sources above; facts were verified in September 2026.
Written by
Skillo Staff
0 Comments
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.