Guidance
Denial of Service (DoS) guidance
Guidance to help organisations understand and mitigate DoS attacks.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 6 of 8
You're likely to do better at defending a DoS attack if you have a response plan ready to enact. We recommend your plan includes:
Like any backup or continuity provisions, you should periodically test your plan.
Consider how you will best serve some of the needs of some of your users during an attack. For example, you may:
Prioritise access based on its source (eg limit access to only UK IP addresses)
Disable dynamically generated content (eg site search or customer specific product recommendations which are compute or database intensive)
Restrict dynamically generated content to authenticated users
It is not uncommon for DoS attacks to occur in waves, ie, another attack will occur when you successfully repel the first attack. Each wave may attempt to overwhelm your systems in different ways as the attacker works out what protections you have in place or are able to deploy. Be prepared for follow-on attacks and try to avoid deploying and exhausting all of your staff to deal with the first wave, leaving no one able to deal with further issues.
You should consider how you will manage the service when it’s under attack, and ensure that if it’s managed remotely, your management access is unlikely to be affected by an attack on the service itself. For example, you could provide management access via a different network or subnet and constrain access to an allow list of trusted locations. Take care not to rely on public DNS zones that are also likely to be targeted.
You should ensure that you have backups of configuration files for devices and servers. This includes services you rely on, but are hosted by third parties. For example, DNS configuration files. You should have tested re-deploying your infrastructure from backups to gain confidence that the process works. This is especially important in a destructive DoS attack where an attacker has gained access to your system and tampered with it. However, it can also be necessary in other DoS scenarios where a failure requires you to re-deploy parts of your system.
Consider putting in place alternative mechanisms to support critical services or functions, which might include manual processes. For example supporting the ability for customers to make contact with you when the normal mechanisms may be unavailable.


