Security · Concept · 10 min read

DoS vs DDoS, and What a Small Business Can Actually Do About Either

The difference between one source and many decides where the defense lives. A single source attack is yours to block. A distributed flood fills the line before your firewall sees it, so the fix is upstream.

Written by Marko Ristic, Editor Updated Sep 18, 2026
1Source behind a DoS attack, which is why a firewall rule can stop it
3Attack categories in the CISA, FBI and MS-ISAC guide: volumetric, protocol, application
0Office firewalls that can clear a flood which has already filled the internet line
1Phone number to write down before an attack: your provider's
Short answer

A DoS attack comes from one source. A DDoS attack comes from many sources at once, usually a botnet of compromised devices. Both are denial of service attacks with the same goal: exhaust a resource, such as bandwidth, connection capacity or server processing, until legitimate users cannot get through.

The difference that matters is defensive. A single source can be blocked at your own firewall. A distributed attack cannot, because the traffic has already filled your internet connection before your equipment sees it.

  • DoS means one attacking source. DDoS means many, acting together
  • Both aim to make a service unavailable, not to steal data
  • A single source attack can be blocked locally. A distributed flood has to be filtered upstream
  • The office firewall cannot stop a flood that has already filled the line
  • Preparation is cheap: a CDN in front of public sites and a phone number at your provider
On this page

DoS attackWhat a DoS attack is

A denial of service attack makes a system unavailable by giving it more work than it can handle, or by triggering a fault that makes it stop. The target can be a website, a mail server, a VPN gateway, a DNS server or the internet connection itself. Nothing is stolen. The damage is the outage.

In a plain DoS attack, the malicious traffic comes from a single source. One machine sends a flood of requests, or sends a small number of crafted packets that exploit a weakness.

The classic example is the SYN flood: the attacker opens TCP connections and never completes the handshake, so the target server fills its connection table with half open entries.

Single source attacks are limited by the attacker's own bandwidth and usually show as one IP address in the logs. So the ones that still work tend to be vulnerability attacks, where one malformed request crashes a service, and not brute floods. Patching removes the first kind. A firewall rule removes the second.

Not every denial of service is an attack. A backup job that saturates the line, a misbehaving script that hammers an API, or a search crawler on a slow web server produces the same symptoms. Rule that out first.

DDoS attackWhat makes a DDoS attack different

A distributed denial of service attack uses multiple machines operating together against one target. CISA describes the usual mechanism: attackers use a botnet, a group of hijacked internet connected devices, and command it to attack one target.

The devices are other people's compromised computers, servers, cameras and routers, and CISA notes that botnets are also rented out to attack for hire services.

Distribution is the whole DoS vs DDoS difference, and it changes three things.

Volume. The attack traffic is the sum of thousands of connections, so it can exceed the capacity of any single office line or server by a wide margin.

Blocking. There is no one IP address to block. The traffic arrives from multiple sources in many networks, and much of it looks like ordinary visitors.

Tracing. The machines sending the traffic belong to victims, not to the attacker, so finding the person behind a DDoS attack is a job for law enforcement and providers.

Some distributed attacks add reflection. The attacker sends small queries with a forged source address to open services on the internet, such as misconfigured DNS servers, and the much larger replies go to the victim. The attacker hides, and the traffic is amplified.

Attack typesThe three categories of attack

CISA, the FBI and MS-ISAC group DDoS attacks into three types in their joint guide. The category tells you which resource is being exhausted, and that decides which defense works.

CategoryWhat it exhaustsWhat helps
VolumetricBandwidth of the internet linkUpstream filtering only: provider, CDN, scrubbing
ProtocolConnection tables in firewalls, load balancers and serversUpstream filtering, SYN protections, sane timeouts
Application layerCPU, memory and database capacity of the applicationRate limits, a WAF, caching

Volumetric attacks aim to consume available bandwidth. Floods of UDP or ICMP traffic and amplified reflection attacks belong here. Size is measured in bits per second.

Protocol attacks exploit weaknesses in network protocols. The SYN flood is the standard case. They are measured in packets per second, and the first thing to fail is often a stateful device, such as the firewall, in front of the server.

Application layer attacks target a specific application or service with requests that look legitimate: repeated searches, logins or page loads that are cheap to send and expensive to answer. They are measured in requests per second and need little bandwidth, which makes them hard to spot.

The limitsWhat a small business cannot do itself

Most articles on DoS vs DDoS close with a list of tips that assume you own a data center. A small business does not, so it helps to be blunt about the limits.

You cannot absorb a volumetric flood. If the office has a one gigabit line and the attack sends more than that, the line is full before any packet reaches your equipment. No firewall setting, appliance or rule on your side of the link changes that. The filtering has to happen upstream.

Your firewall is a target, not a shield. A business firewall tracks every connection, and a flood of new connections fills that table. During a protocol attack the firewall is often the first device to fail.

You cannot find or stop the attacker. Blocking source addresses by hand against a botnet is pointless, and striking back is illegal and hits other victims.

You cannot prepare during the attack. Moving a website behind a protection service while it is under fire, with the DNS and the origin address already known to the attacker, is slow and stressful. On a quiet afternoon it is routine work.

PreparationWhat a small business can do

The good news is that the effective measures are cheap and mostly about where things are hosted.

Put public sites behind a CDN or DDoS protection service. The provider's network takes the traffic, filters it and forwards clean requests. CISA's advice is the same: enroll in a protection service that detects abnormal traffic flows and redirects them away from your network. Keep the origin address private afterward.

Host nothing public on the office line. A website, a customer portal or a mail server on the same connection the staff use means an attack on one takes out the other. Hosted platforms have capacity and mitigation that an office never will.

Use the application layer controls you already have. A web application firewall, rate limits per client, caching, and a load balancer with health checks deal with request floods far better than raw bandwidth does.

Ask your provider now. Find out what the ISP offers: a DDoS mitigation add on, scrubbing, or blackholing, where the provider drops all traffic to the attacked address. Blackholing takes that address offline, and it saves the rest of your network. Write down the number to call.

Keep a second way out. A backup connection from a different provider, even a cellular one, keeps staff working with cloud applications while the main line is unusable.

Do not be part of someone else's attack. Patch routers, cameras and other connected devices, change default passwords, and do not expose services such as DNS resolvers to the internet.

During an attackWhat to do during an attack

Confirm it is an attack. CISA's first step is to check with your network administrator whether the outage is maintenance or an internal issue. Look at interface graphs or NetFlow data: a full inbound line with traffic from many sources to one address is the signature.

Call the provider. Ask whether they see the traffic, whether their own network is affected, and what they can filter or blackhole. This is the step that ends most attacks on small networks.

Watch everything else. CISA warns that attackers use DoS and DDoS attacks to deflect attention from their intended target. Keep an eye on logins, alerts and other systems while the outage has everyone's attention.

Do not pay. Some attacks arrive with an extortion demand. Payment buys nothing enforceable and marks you as someone who pays. Keep the message, record the times and traffic details, and report it to law enforcement.

PitfallsWhere people go wrong

Buying a bigger firewall as DDoS protection. A firewall sits behind the line that is being filled. Its DoS protection settings help against small protocol attacks and do nothing for volume.

Leaving the origin address exposed. A site behind a CDN is only protected if attackers cannot reach the server directly. Old DNS records, mail headers and subdomains often reveal the real address. Restrict the origin to accept traffic from the CDN only.

Treating an outage as an attack without checking. Most sudden slowdowns are internal: a loop, a backup, a failing line. Check the boring causes before announcing an attack.

Having no contact at the provider. During an attack is the wrong time to discover the support line opens at nine and nobody knows the account number.

Focusing only on the website. VPN gateways, remote desktop gateways, DNS and hosted phone systems are all reachable from the internet, and losing them can hurt more than losing a brochure site.

Forgetting the distraction. A flood that stops after twenty minutes with no demand may have been cover for something quieter. Review authentication and firewall logs for the same period.

ComparisonDoS and DDoS attacks, and where the fix for each one lives

CriterionDoS attackDDoS attack
Source of trafficA single sourceMultiple sources, usually a botnet
Volume possibleLimited by one machine and its lineSum of thousands of devices
Typical method todayExploiting a flaw, or a small floodVolumetric, protocol or application floods
Blocking at your own firewallUsually worksDoes not work for floods
Tracing the originOne address to investigateCompromised devices of other victims
Where the fix livesPatch, firewall rule, rate limitUpstream provider, CDN, scrubbing service
Who you callNobody, you fix it yourselfYour provider or protection service
What you seeOne address dominating the logsMany addresses, each looking ordinary

The row that matters is where the fix lives. In the DoS vs DDoS comparison, everything about a single source attack can be handled with the equipment and skills a small business already has. Almost nothing about a distributed flood can, which is why the preparation is about providers and hosting, not about hardware.

FAQFrequently asked questions

What is the difference between DoS and DDoS?

A DoS attack comes from a single source. A DDoS attack comes from many sources at once, usually a botnet. The goal is the same, making a service unavailable, and the distributed form is larger, harder to block and harder to trace.

What is a DoS attack in simple terms?

An attempt to make a system unavailable by overloading it or crashing it. The attacker sends more traffic or requests than the target can handle, or sends crafted input that triggers a fault, so legitimate users cannot reach the service.

What is a DDoS attack?

A distributed denial of service attack, in which many compromised devices send traffic to one target at the same time. Because the traffic comes from thousands of addresses in many networks, it cannot be stopped by blocking one source.

DDoS vs DoS: which is more dangerous?

DDoS. The combined traffic of a botnet can exceed the capacity of any small network, and there is no single address to block. A single source DoS attack is usually stopped with a patch, a firewall rule or a rate limit.

What are the three types of DDoS attack?

Volumetric attacks fill the bandwidth of the internet link. Protocol attacks exhaust connection tables in firewalls, load balancers and servers. Application layer attacks overload the application itself with requests that look legitimate. Each needs a different defense.

Can a firewall stop a DDoS attack?

Not a volumetric one. The firewall sits behind the internet link, and the link is full before traffic reaches it. Firewalls help against small protocol attacks and single source floods. Large attacks have to be filtered upstream by a provider or protection service.

Is a denial of service attack illegal?

Yes. In the United States, the Computer Fraud and Abuse Act covers intentionally causing damage to a protected computer, and it defines damage to include impairing the availability of a system or data. Most other countries have equivalent computer misuse laws.

How long does a DDoS attack last?

Anywhere from minutes to days. Many attacks on small targets are short bursts, sometimes repeated. Plan for the outage lasting until your provider or protection service filters the traffic, not for the attacker losing interest.

Does a DDoS attack steal data?

No. It only affects availability. It can be used as a distraction while a separate intrusion takes place, so check authentication logs and security alerts for the same period instead of assuming the flood was the whole event.

What is a botnet?

A group of internet connected devices that have been compromised and are controlled together by an attacker. Computers, servers, routers and cameras with weak passwords or missing patches are typical members, and their owners usually do not know.

How do I know if I am under a DDoS attack?

The internet line is saturated with inbound traffic, or a public service slows down and stops while the server itself is healthy. Traffic graphs show a sudden jump, and logs show a large number of source addresses hitting one destination.

Does a small business need DDoS protection?

It needs a plan more than a product. Put public sites behind a CDN or hosted platform with mitigation included, keep public services off the office line, know what the ISP offers, and keep a backup connection for staff.

Does a VPN protect against DDoS attacks?

A VPN hides a user's own address, which helps individuals such as gamers. It does not protect a company's public website or its office line, whose addresses are published by design. Those need upstream filtering.

Read next · Network security What Is a Firewall? What a firewall inspects and decides, and the limits of a box behind the internet line. Open this next14 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.