A DoS attack comes from one source. A DDoS attack comes from many sources at once, usually a botnet of compromised devices. Both are denial of service attacks with the same goal: exhaust a resource, such as bandwidth, connection capacity or server processing, until legitimate users cannot get through.
The difference that matters is defensive. A single source can be blocked at your own firewall. A distributed attack cannot, because the traffic has already filled your internet connection before your equipment sees it.
- DoS means one attacking source. DDoS means many, acting together
- Both aim to make a service unavailable, not to steal data
- A single source attack can be blocked locally. A distributed flood has to be filtered upstream
- The office firewall cannot stop a flood that has already filled the line
- Preparation is cheap: a CDN in front of public sites and a phone number at your provider
On this page
DoS attackWhat a DoS attack is
A denial of service attack makes a system unavailable by giving it more work than it can handle, or by triggering a fault that makes it stop. The target can be a website, a mail server, a VPN gateway, a DNS server or the internet connection itself. Nothing is stolen. The damage is the outage.
In a plain DoS attack, the malicious traffic comes from a single source. One machine sends a flood of requests, or sends a small number of crafted packets that exploit a weakness.
The classic example is the SYN flood: the attacker opens TCP connections and never completes the handshake, so the target server fills its connection table with half open entries.
Single source attacks are limited by the attacker's own bandwidth and usually show as one IP address in the logs. So the ones that still work tend to be vulnerability attacks, where one malformed request crashes a service, and not brute floods. Patching removes the first kind. A firewall rule removes the second.
Not every denial of service is an attack. A backup job that saturates the line, a misbehaving script that hammers an API, or a search crawler on a slow web server produces the same symptoms. Rule that out first.
DDoS attackWhat makes a DDoS attack different
A distributed denial of service attack uses multiple machines operating together against one target. CISA describes the usual mechanism: attackers use a botnet, a group of hijacked internet connected devices, and command it to attack one target.
The devices are other people's compromised computers, servers, cameras and routers, and CISA notes that botnets are also rented out to attack for hire services.
Distribution is the whole DoS vs DDoS difference, and it changes three things.
Volume. The attack traffic is the sum of thousands of connections, so it can exceed the capacity of any single office line or server by a wide margin.
Blocking. There is no one IP address to block. The traffic arrives from multiple sources in many networks, and much of it looks like ordinary visitors.
Tracing. The machines sending the traffic belong to victims, not to the attacker, so finding the person behind a DDoS attack is a job for law enforcement and providers.
Some distributed attacks add reflection. The attacker sends small queries with a forged source address to open services on the internet, such as misconfigured DNS servers, and the much larger replies go to the victim. The attacker hides, and the traffic is amplified.
Attack typesThe three categories of attack
CISA, the FBI and MS-ISAC group DDoS attacks into three types in their joint guide. The category tells you which resource is being exhausted, and that decides which defense works.
| Category | What it exhausts | What helps |
|---|---|---|
| Volumetric | Bandwidth of the internet link | Upstream filtering only: provider, CDN, scrubbing |
| Protocol | Connection tables in firewalls, load balancers and servers | Upstream filtering, SYN protections, sane timeouts |
| Application layer | CPU, memory and database capacity of the application | Rate limits, a WAF, caching |
Volumetric attacks aim to consume available bandwidth. Floods of UDP or ICMP traffic and amplified reflection attacks belong here. Size is measured in bits per second.
Protocol attacks exploit weaknesses in network protocols. The SYN flood is the standard case. They are measured in packets per second, and the first thing to fail is often a stateful device, such as the firewall, in front of the server.
Application layer attacks target a specific application or service with requests that look legitimate: repeated searches, logins or page loads that are cheap to send and expensive to answer. They are measured in requests per second and need little bandwidth, which makes them hard to spot.
The limitsWhat a small business cannot do itself
Most articles on DoS vs DDoS close with a list of tips that assume you own a data center. A small business does not, so it helps to be blunt about the limits.
You cannot absorb a volumetric flood. If the office has a one gigabit line and the attack sends more than that, the line is full before any packet reaches your equipment. No firewall setting, appliance or rule on your side of the link changes that. The filtering has to happen upstream.
Your firewall is a target, not a shield. A business firewall tracks every connection, and a flood of new connections fills that table. During a protocol attack the firewall is often the first device to fail.
You cannot find or stop the attacker. Blocking source addresses by hand against a botnet is pointless, and striking back is illegal and hits other victims.
You cannot prepare during the attack. Moving a website behind a protection service while it is under fire, with the DNS and the origin address already known to the attacker, is slow and stressful. On a quiet afternoon it is routine work.
PreparationWhat a small business can do
The good news is that the effective measures are cheap and mostly about where things are hosted.
Put public sites behind a CDN or DDoS protection service. The provider's network takes the traffic, filters it and forwards clean requests. CISA's advice is the same: enroll in a protection service that detects abnormal traffic flows and redirects them away from your network. Keep the origin address private afterward.
Host nothing public on the office line. A website, a customer portal or a mail server on the same connection the staff use means an attack on one takes out the other. Hosted platforms have capacity and mitigation that an office never will.
Use the application layer controls you already have. A web application firewall, rate limits per client, caching, and a load balancer with health checks deal with request floods far better than raw bandwidth does.
Ask your provider now. Find out what the ISP offers: a DDoS mitigation add on, scrubbing, or blackholing, where the provider drops all traffic to the attacked address. Blackholing takes that address offline, and it saves the rest of your network. Write down the number to call.
Keep a second way out. A backup connection from a different provider, even a cellular one, keeps staff working with cloud applications while the main line is unusable.
Do not be part of someone else's attack. Patch routers, cameras and other connected devices, change default passwords, and do not expose services such as DNS resolvers to the internet.
During an attackWhat to do during an attack
Confirm it is an attack. CISA's first step is to check with your network administrator whether the outage is maintenance or an internal issue. Look at interface graphs or NetFlow data: a full inbound line with traffic from many sources to one address is the signature.
Call the provider. Ask whether they see the traffic, whether their own network is affected, and what they can filter or blackhole. This is the step that ends most attacks on small networks.
Watch everything else. CISA warns that attackers use DoS and DDoS attacks to deflect attention from their intended target. Keep an eye on logins, alerts and other systems while the outage has everyone's attention.
Do not pay. Some attacks arrive with an extortion demand. Payment buys nothing enforceable and marks you as someone who pays. Keep the message, record the times and traffic details, and report it to law enforcement.
PitfallsWhere people go wrong
Buying a bigger firewall as DDoS protection. A firewall sits behind the line that is being filled. Its DoS protection settings help against small protocol attacks and do nothing for volume.
Leaving the origin address exposed. A site behind a CDN is only protected if attackers cannot reach the server directly. Old DNS records, mail headers and subdomains often reveal the real address. Restrict the origin to accept traffic from the CDN only.
Treating an outage as an attack without checking. Most sudden slowdowns are internal: a loop, a backup, a failing line. Check the boring causes before announcing an attack.
Having no contact at the provider. During an attack is the wrong time to discover the support line opens at nine and nobody knows the account number.
Focusing only on the website. VPN gateways, remote desktop gateways, DNS and hosted phone systems are all reachable from the internet, and losing them can hurt more than losing a brochure site.
Forgetting the distraction. A flood that stops after twenty minutes with no demand may have been cover for something quieter. Review authentication and firewall logs for the same period.
ComparisonDoS and DDoS attacks, and where the fix for each one lives
| Criterion | DoS attack | DDoS attack |
|---|---|---|
| Source of traffic | A single source | Multiple sources, usually a botnet |
| Volume possible | Limited by one machine and its line | Sum of thousands of devices |
| Typical method today | Exploiting a flaw, or a small flood | Volumetric, protocol or application floods |
| Blocking at your own firewall | Usually works | Does not work for floods |
| Tracing the origin | One address to investigate | Compromised devices of other victims |
| Where the fix lives | Patch, firewall rule, rate limit | Upstream provider, CDN, scrubbing service |
| Who you call | Nobody, you fix it yourself | Your provider or protection service |
| What you see | One address dominating the logs | Many addresses, each looking ordinary |
The row that matters is where the fix lives. In the DoS vs DDoS comparison, everything about a single source attack can be handled with the equipment and skills a small business already has. Almost nothing about a distributed flood can, which is why the preparation is about providers and hosting, not about hardware.
FAQFrequently asked questions
What is the difference between DoS and DDoS?
A DoS attack comes from a single source. A DDoS attack comes from many sources at once, usually a botnet. The goal is the same, making a service unavailable, and the distributed form is larger, harder to block and harder to trace.
What is a DoS attack in simple terms?
An attempt to make a system unavailable by overloading it or crashing it. The attacker sends more traffic or requests than the target can handle, or sends crafted input that triggers a fault, so legitimate users cannot reach the service.
What is a DDoS attack?
A distributed denial of service attack, in which many compromised devices send traffic to one target at the same time. Because the traffic comes from thousands of addresses in many networks, it cannot be stopped by blocking one source.
DDoS vs DoS: which is more dangerous?
DDoS. The combined traffic of a botnet can exceed the capacity of any small network, and there is no single address to block. A single source DoS attack is usually stopped with a patch, a firewall rule or a rate limit.
What are the three types of DDoS attack?
Volumetric attacks fill the bandwidth of the internet link. Protocol attacks exhaust connection tables in firewalls, load balancers and servers. Application layer attacks overload the application itself with requests that look legitimate. Each needs a different defense.
Can a firewall stop a DDoS attack?
Not a volumetric one. The firewall sits behind the internet link, and the link is full before traffic reaches it. Firewalls help against small protocol attacks and single source floods. Large attacks have to be filtered upstream by a provider or protection service.
Is a denial of service attack illegal?
Yes. In the United States, the Computer Fraud and Abuse Act covers intentionally causing damage to a protected computer, and it defines damage to include impairing the availability of a system or data. Most other countries have equivalent computer misuse laws.
How long does a DDoS attack last?
Anywhere from minutes to days. Many attacks on small targets are short bursts, sometimes repeated. Plan for the outage lasting until your provider or protection service filters the traffic, not for the attacker losing interest.
Does a DDoS attack steal data?
No. It only affects availability. It can be used as a distraction while a separate intrusion takes place, so check authentication logs and security alerts for the same period instead of assuming the flood was the whole event.
What is a botnet?
A group of internet connected devices that have been compromised and are controlled together by an attacker. Computers, servers, routers and cameras with weak passwords or missing patches are typical members, and their owners usually do not know.
How do I know if I am under a DDoS attack?
The internet line is saturated with inbound traffic, or a public service slows down and stops while the server itself is healthy. Traffic graphs show a sudden jump, and logs show a large number of source addresses hitting one destination.
Does a small business need DDoS protection?
It needs a plan more than a product. Put public sites behind a CDN or hosted platform with mitigation included, keep public services off the office line, know what the ISP offers, and keep a backup connection for staff.
Does a VPN protect against DDoS attacks?
A VPN hides a user's own address, which helps individuals such as gamers. It does not protect a company's public website or its office line, whose addresses are published by design. Those need upstream filtering.
Keep readingRelated concepts
Read next · Network security What Is a Firewall? What a firewall inspects and decides, and the limits of a box behind the internet line. Open this next14 min- Infrastructure · 12 min What a Load Balancer Does, and the Two Decisions Behind It How a load balancer spreads requests and drops failed servers, which helps against request floods.
- Network security · 14 min What Is a WAF? How a web application firewall filters requests, one of the few defenses against application layer floods.