What Is a DDoS Attack? How It Works and How to Stay Safe

⚠️ Affiliate Disclosure: This article contains affiliate links. If you purchase through them we may earn a commission at no extra cost to you. Read our full disclosure.

A DDoS attack (Distributed Denial of Service) floods a target with more traffic than it can handle, until legitimate users can’t get through. The “distributed” part is what makes it hard to stop: the flood arrives from thousands of different machines at once, so there’s no single source to block.

Nothing is broken into. No data is stolen. A DDoS attack doesn’t compromise a server — it exhausts it. Think of a shop with one door and ten thousand people crowding the entrance: the lock still works, but no real customer is getting inside.

Key Takeaway:
DDoS is not hacking. It’s a traffic problem, not a security breach. If your home connection is hit, nobody is “in” your network or your accounts — your line is simply full.


DoS vs DDoS: The Difference

A plain DoS attack comes from one machine. It’s easy to stop — identify the source IP, block it, done.

A DDoS attack comes from thousands of machines spread across the world, most of them belonging to people who have no idea they’re involved. You can’t block your way out of it, because blocking each address individually is slower than the attack is.

How a DDoS Attack Actually Works

  1. An attacker builds or rents a botnet. This is a network of compromised machines — increasingly cheap IoT devices like cameras and routers with default passwords still set.
  2. A target is chosen. An IP address or domain: a game server, a website, or a single home connection.
  3. The command goes out. Every machine in the botnet starts sending traffic to that target simultaneously.
  4. The target’s capacity fills. Either its bandwidth, or its ability to track connections, or its capacity to process requests.
  5. Real users are locked out. The site times out, the game disconnects, the connection dies.

The 2016 Mirai botnet demonstrated the modern version of this. It spread by scanning the internet for devices still using factory default logins, assembled hundreds of thousands of them, and used them to knock major internet services offline. The devices weren’t valuable individually — they were valuable in bulk.

The Three Main Types

TypeWhat It ExhaustsExamples
VolumetricRaw bandwidth — fills the pipeUDP floods, DNS & NTP amplification
ProtocolConnection tracking in servers and firewallsSYN floods, ping of death
Application layerServer processing — CPU, database queriesHTTP floods on search or login pages

Application-layer attacks are the sneakiest. They need far less bandwidth, because each request is cheap to send but expensive to answer. A few thousand requests per second against a slow database query can take down a site that would shrug off a much larger raw flood.

Why These Attacks Got So Easy

Two things changed the landscape.

The first is amplification. Certain internet services reply with far more data than you send them. An attacker forges the source address on a small request — see IP spoofing — so the much larger reply gets delivered to the victim instead. A modest amount of attacker bandwidth turns into an enormous flood. A 2018 attack against GitHub used this technique to reach roughly 1.35 terabits per second, and records have been broken repeatedly since.

The second is commercialisation. So-called “booter” or “stresser” services sell attacks by the minute, marketed with a thin pretence of being legitimate load-testing tools. They’ve made DDoS available to people with no technical skill whatsoever, which is why petty disputes now escalate into attacks. Law enforcement agencies periodically seize and shut them down, but new ones appear.

Can Your Home Connection Be DDoSed?

Yes — and this is the version that affects ordinary people, particularly gamers.

If someone knows your IP address, they can point a flood at it. Home connections are far easier targets than websites, because you have a fraction of the capacity and none of the protection a hosting provider would have. It doesn’t take a serious botnet to saturate a residential line.

The usual route is gaming. Some titles connect players peer-to-peer, which exposes your IP to everyone in the lobby. Voice chat platforms, modded servers and third-party tools have all leaked addresses at various points. Someone loses a match, pulls your IP, and pays a booter service a few dollars.

What it looks like: your connection dies completely, or slows to unusable, usually for minutes rather than hours. Every device in the house is affected at once, because the bottleneck is your router’s connection to the internet — not any single device. For more on how exposed your address is, see what someone can do with your IP address.

What to Do If You’re Being Attacked Right Now

You can’t filter a flood from your side — by the time it reaches your router, it has already used up the bandwidth. But there are practical steps:

  1. Power off your router for 5–10 minutes. Most home connections use a dynamic IP, so you’ll often come back on a different address the attack isn’t aimed at. See why your IP changes and how to force a new one.
  2. Leave the game or lobby. If it started during a match, don’t rejoin the same session — you’ll simply hand over your new address.
  3. Contact your ISP. They can see the flood, and they can null-route it or assign you a fresh IP. This is a routine request; you won’t be the first person to make it.
  4. Don’t negotiate. If there’s a threat attached, engaging confirms the address works and marks you as responsive.
  5. Report it. DDoS is a criminal offence in most countries, including under the US Computer Fraud and Abuse Act and the UK Computer Misuse Act. “It was only a stresser” is not a defence.

How to Protect Yourself Long-Term

The defence for a home user isn’t filtering the attack — it’s making sure nobody has an address to attack in the first place.

  • Don’t let your real IP circulate. This is the whole game. A VPN means other players and services see the VPN server’s address instead of yours, and a provider’s infrastructure absorbs floods your home line never could.
  • Be careful with peer-to-peer games and voice chat. Prefer titles and platforms that use dedicated servers rather than connecting players directly.
  • Never click unknown “IP grabber” links. Shortened links shared in chat are a standard way to harvest addresses.
  • Lock down your own devices. Change default router passwords and keep firmware updated — this is exactly how devices get recruited into botnets. Full checklist: How to Secure Your Home Network.
  • Keep your router’s firewall on. It won’t stop a flood, but it handles everything smaller. See what a NAT firewall does.

🔒 Keeping Your IP Off the Table

If you play online games where your address is visible to other players, routing through a VPN is the single most effective step — attackers can only target what they can see:

  • PureVPN — wide server coverage, DDoS-resistant infrastructure
  • IPVanish — strong speeds, which matters for gaming latency

Other approaches to the same problem: How to Hide Your IP Address.

How Websites Defend Against DDoS

If you run a site rather than just play on one, the tools are different:

  • A CDN or scrubbing service sits in front of your server and absorbs floods across a network far larger than any single origin.
  • Rate limiting caps how many requests one source can make, which blunts application-layer attacks.
  • Hiding the origin IP matters more than people expect — if attackers find the real server address behind the CDN, they can bypass the protection entirely.
  • Overprovisioned capacity buys time, though it’s rarely a match for a serious volumetric attack on its own.

⚠️ Common Misconceptions

  • “I was DDoSed, so I was hacked.” No. Nothing was accessed. Your connection was congested, and it recovers when the traffic stops.
  • “They can DDoS me through my username.” Not directly — they need your IP. The real question is how it was exposed. See can someone hack you with your IP.
  • “An antivirus will stop it.” Antivirus inspects files on your machine. A DDoS never gets that far — it’s a bandwidth problem upstream.
  • “Stresser services are legal because they say ‘testing’.” Testing infrastructure you don’t own or have written permission to test is a crime, regardless of the marketing.
  • “A firewall protects me.” Your firewall can drop the packets, but they’ve already consumed your bandwidth getting to it.

Frequently Asked Questions

How long does a DDoS attack last?

Most are short — minutes to a couple of hours — because attacks cost money to sustain and rented botnet time is sold in blocks. Attacks against businesses, where there’s a financial motive, can run considerably longer.

Can a DDoS attack steal my data?

Not by itself. It’s purely about exhausting capacity. It’s worth noting that attackers occasionally use one as a distraction while attempting something else, but the flood itself accesses nothing.

Will restarting my router really help?

Often, yes — if your ISP assigns dynamic addresses, an extended power-off frequently gets you a new one, and the attack keeps hitting the old address. It won’t help on a static IP, in which case call your ISP.

Does a VPN stop a DDoS attack?

It prevents one from targeting you, which is the more useful outcome. Attackers see the VPN server’s address, and that infrastructure is built to absorb floods. If an attack is already underway against your home IP, connecting a VPN won’t clear it — you need a new address.

Is DDoS illegal?

Yes, in most countries, including when carried out through a paid “stresser” service. People are prosecuted for it regularly, and buyers of these services have been charged as well as operators.

Why would anyone DDoS a home user?

Almost always personal: losing an online match, an argument, or a grudge. It’s cheap and requires no skill, which is exactly why trivial disputes turn into attacks.

Can my ISP stop it?

They’re the only party who realistically can, because they control the link upstream of your router. They can filter the traffic before it reaches you or move you to a new address.

Could my devices be part of a botnet?

It’s possible — especially smart devices with default passwords and outdated firmware. Signs include unexplained slowdowns and heavy upload activity when nothing should be uploading. Related reading: what smart home devices actually do.


Related Reading

Scroll to Top