Guidance
Denial of Service (DoS) guidance
Guidance to help organisations understand and mitigate DoS attacks.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 1 of 8

This guidance helps organisations understand and manage the risk of denial of service (DoS) attacks against a network, system or service, by setting out four essential practices:
It focuses on DoS attacks that originate online. Physical DoS attacks, such as power supply disruption or radio frequency interference, are out of scope. These types of attack should be assessed and managed using business continuity and resilience processes.
A denial of service (DoS) attack is an attempt to overload a website or network, with the aim of degrading its performance or even making it completely inaccessible.
Typically a successful DoS attack will result in loss of availability of part, or all, of a system, and consume time and money to analyse, defend and recover from.
DDoS attacks
A distributed denial of service (DDoS) attack is a form of DoS attack that originates from more than one source. DDoS attacks are typically more effective than attacks from a single source because they usually generate more attacking traffic. The fact that traffic is spread across many sources also makes it harder to distinguish attacker traffic from legitimate traffic.
Where this guidance refers to DoS, it also includes DDoS attacks.
DoS attacks can easily be targeted against your network, system or service and remain a credible and prevalent threat.
Different types of DoS attack target different parts of a system – for instance, a DoS attack can target a network's capacity to send and receive traffic (its bandwidth), or the processor limitations of servers. The overall impact depends on what is targeted, how long the attack lasts and the effectiveness of your organisational response plan.
Whatever the type of attack, if successful, it will cause the targeted system to become unreliable or unresponsive to a user trying to access it.
For an organisation, an unavailable public-facing website can have a significant impact on an organisation’s productivity if it affects business-critical functions. This could include loss of sales, or employees unable to work. This is the case even if an attack is temporary, with no effect on data confidentiality or integrity.


