Skip to main content
Guidance

Denial of Service (DoS) guidance

Guidance to help organisations understand and mitigate DoS attacks.

Page 8 of 8

Responding to a DoS attack

iStock.com/Pavel Bezkorovainyi

You should design your service, and plan your response to an attack, so that the service can continue to operate, albeit in a degraded fashion.

If you suspect your organisation is experiencing a DoS attack, your priorities are to:  

 

  1. Clarify what is happening
  2. Put in place the right defences
  3. Continually review the situation, communicate and recover

Observed anomalyPossible cause
 
 Non-maliciousDoS attack
Unusually large volumes of traffic that exceed bandwidth capacity, meaning that not all legitimate traffic is reaching its destination.There may be more traffic than normal to your website – for example, an item on it is attracting high interest or your organisation is receiving lots of external attention for some reason.Volumetric attack: an attempt by an attacker to overload the bandwidth (capacity) of a network by sending large volumes of attacker traffic to the target network.
Unusually large processing loads on a router with relatively normal bandwidth use, meaning that not all legitimate traffic is being passed through.An internal network misconfiguration has caused more traffic than intended to route through the router.Protocol attack: an attempt to exceed the capacity of network equipment by exploiting how network protocols legitimately function.
Unusually large volumes of database queries or server load, resulting in significantly slower database response times.A recently updated internal tool has an unintentional coding error, causing the tool to generate large volumes of database transactions.Application attack: an attempt by an attacker to overload the processing resources of servers by sending large volumes of legitimate-looking requests that servers must process.


Published

Reviewed

Version

1.0