Back to Blog

What Is a DDoS Attack? How It Works and How to Stay Protected

What is DDoS? Learn how DDoS attacks work, how L3/L4 and L7 attacks differ, how to tell you are under attack and how to protect a server or website.

Nodesty Team8 min readSecurity
The word DDoS with the network layers L3, L4 and L7 on a dark Nodesty background

A DDoS (Distributed Denial of Service) attack is an attempt to make a server, website or network unavailable by flooding it with more traffic or requests than it can handle. Unlike a simple outage, the traffic comes from thousands of different machines at once, usually a botnet of hijacked computers, routers and IoT devices, so it cannot be stopped by blocking a single address. If you have ever asked "what is DDoS?" after your game server lagged out or your website stopped responding, the short answer is: someone is deliberately exhausting a resource your service depends on, whether that is bandwidth, connection tables or application capacity.

This guide explains how DDoS attacks work, the main attack types, how to recognise one and what actually protects you.

What is DDoS?

Every online service has limits. A server has a network port of a certain speed, an operating system that can track a certain number of connections, and an application that can answer a certain number of requests per second. A DDoS attack pushes one of those limits past breaking point so that legitimate users can no longer get through.

The "distributed" part is what makes it hard. Attackers rarely use their own machines. They rent or build botnets, networks of compromised devices that send traffic on command, or they abuse reflection: they send small requests to public services such as DNS or NTP servers with a forged source address, and those services send much larger replies to the victim. The victim sees traffic from tens of thousands of legitimate-looking addresses at the same time.

The goal is almost never to break into the system. A DDoS attack is about availability: keeping your players, customers or visitors out for as long as the attack runs.

DoS vs DDoS: what is the difference?

A DoS (Denial of Service) attack comes from a single source. One machine sends malformed packets, opens thousands of connections or hammers an expensive page. Because there is only one source, it is relatively easy to identify and block, either by IP address or with a firewall rule.

A DDoS attack does the same thing from many sources at once. That changes the defence completely:

DoSDDoS
SourcesOne machineThousands of devices or reflectors
Typical volumeLimited by one connectionCan exceed what a single server link can carry
Blocking by IPUsually worksImpractical; addresses change and may be spoofed
Where it must be stoppedOn the server or its firewallUpstream, before traffic reaches the server

In practice almost every attack you will encounter today is a DDoS attack, because botnets and reflection make it cheap for attackers to use many sources.

Types of DDoS attacks

Attacks are usually grouped by the layer of the network they target. Knowing the type tells you where the defence has to happen.

Volumetric attacks (L3/L4)

Volumetric attacks try to fill the network pipe. They are measured in bits per second (Gbps or Tbps) and packets per second. Common examples are UDP floods and amplification attacks, where attackers abuse DNS, NTP, memcached, SSDP or similar services to multiply the traffic they send. Once the link to your server is full, it does not matter how fast your CPU is: legitimate packets are dropped on the way in.

Protocol attacks (L3/L4)

Protocol attacks target the way network stacks and devices keep track of connections. A SYN flood sends huge numbers of connection requests that are never completed, filling the connection table of a server, firewall or load balancer. Other variants use fragmented packets or abuse TCP flags. These attacks can take a service down with much less bandwidth than a volumetric attack, because they exhaust state rather than capacity.

Application-layer attacks (L7)

Application-layer attacks look like normal users. An HTTP flood requests pages, search results or login forms over and over; a Slowloris attack opens connections and sends data so slowly that the web server keeps them open. Game servers face their own version: floods of server-list queries or connection attempts that the game process has to answer. L7 attacks are measured in requests per second, and they are the hardest to filter because each request on its own can be indistinguishable from a real one.

How to tell you are under a DDoS attack

The symptoms depend on which layer is being hit, but some patterns are typical:

  • Sudden latency and packet loss for everyone at once, while your server's CPU and memory look normal. This usually points to a saturated network link.
  • Players disconnecting with timeouts or rubber-banding on a game server that was running fine minutes earlier.
  • A website that returns errors or times out, with the web server or database at full load and logs full of requests from many unrelated IP addresses.
  • Traffic graphs that jump far above your normal peak, often in a single step rather than a gradual rise.
  • Connection table or firewall alerts, such as warnings about too many half-open connections.

Not every slowdown is an attack. A popular post, a game update or a misbehaving plugin can produce similar symptoms. The difference is usually the source: organic traffic comes from your real audience, attack traffic from addresses and countries that have nothing to do with it. If your provider shows attack logs or sends attack notifications, those are the fastest way to confirm what is happening. On Nodesty, both are available in the customer panel for protected IP addresses.

Why game servers and websites are targeted

Game servers are among the most frequently attacked services online. Communities compete for players, banned users want revenge, and some attackers simply want to disrupt a popular server. Games run in real time over UDP, so even a short burst of packet loss is immediately visible to every player. A Minecraft, FiveM or Rust server that drops for a few minutes during peak hours can lose players to a competitor, which is exactly what some attackers are after. If you run one, our game server hosting plans are built for this kind of traffic.

Websites and online shops are targeted for different reasons: extortion ("pay or we keep you offline"), competition during a busy sales period, political motives, or as a smokescreen while someone tries another kind of intrusion. For an online business, downtime translates directly into lost orders.

Low cost is the common thread. Attack services are cheap and easy to find, so the people behind an attack often have far fewer resources than the services they take down.

How to protect against DDoS attacks

No single setting makes a server immune. Effective protection combines filtering in the network with sensible configuration on the server itself.

  1. Filter upstream. Volumetric and most protocol attacks have to be stopped before they reach your server, in your provider's network or a scrubbing service with far more capacity than any single link. This is the one thing you cannot do yourself.
  2. Use protection that is always on. Attacks often come in short, repeated bursts. Mitigation that has to be activated manually, or only kicks in after minutes of detection, lets the first waves through.
  3. Harden the operating system. Enable SYN cookies, keep sensible connection limits and close every port you do not need. A firewall such as nftables or iptables will not stop a flood, but it reduces the surface attackers can reach.
  4. Hide the origin of websites. Put a reverse proxy or CDN in front of your site and make sure the origin IP does not leak through DNS records, email headers or old subdomains.
  5. Rate-limit and cache at the application layer. Cache pages that do not change per user, rate-limit logins and searches, and use challenges for suspicious clients. This is where L7 attacks are won or lost.
  6. Have a plan. Know how to reach your provider's support, which logs to collect and how to tell your users what is happening.

Extra tips for game servers

  • Keep admin ports private. Ports for RCON, txAdmin or web panels only need to be reachable by you; allow them for your own IP address only.
  • Run your website and Discord bot elsewhere. A website on the same IP as your game server hands that address to anyone who looks.
  • Give players a domain name. An address like play.yourdomain.com does not stop an attack, but it lets you move the server to a new IP without players changing anything.
  • Keep records. The time an attack started, the affected port and player reports help your provider tune its filters.

If your workload is on a single virtual server, the choice of provider matters most, because the network in front of the server is what decides whether a large attack ever reaches it. Our guide What is a VPS? explains how virtual servers work and what else to check when choosing one.

What to look for in a DDoS-protected server

"DDoS protection included" can mean very different things. When comparing providers, ask:

  • Filtering capacity. How much traffic can the network absorb and filter? It needs to be far larger than the port speed of your server.
  • Layers covered. Does the protection only handle L3/L4 floods, or does it also cover application-layer and game traffic? Protection that ignores UDP is of little use to a game server.
  • Always-on or on-demand. Is traffic filtered continuously, or is protection switched on only after an attack is detected?
  • Visibility. Can you see attack logs, and are you notified when an attack starts? Without this you are guessing.
  • Cost. Is protection part of the price, or billed separately once an attack exceeds a threshold?
  • Location and latency. Filtering should not add noticeable latency for your users, especially for game servers.
  • Support. Attacks do not keep office hours. Make sure support is available 24/7.

Every AMD Ryzen 9 9950X VPS at Nodesty includes nShield DDoS protection with more than 3 Tbps of filtering capacity across layers 3 to 7, at no extra cost, together with attack logs and notifications in the panel.

Frequently Asked Questions

Is a DDoS attack illegal?

Yes. Launching or paying for a DDoS attack is a criminal offence in most countries, including the United States, the United Kingdom, EU member states and Turkey. "Stress testing" services that attack targets you do not own fall under the same laws.

Can a DDoS attack steal my data?

No. A DDoS attack targets availability, not confidentiality, so it does not read or copy data by itself. It is sometimes used as a distraction while another intrusion is attempted, so review your logs after a large attack.

How long does a DDoS attack last?

Anything from a few minutes to several days. Many attacks are short bursts repeated over time, which is why protection that is always on matters more than protection you have to switch on manually.

Can my own firewall stop a DDoS attack?

Only small or application-layer attacks. A volumetric attack fills the network link before packets ever reach your firewall, so it has to be filtered upstream by your hosting provider or a scrubbing network.

Does hiding my IP address help?

For websites, yes. Putting a reverse proxy or CDN in front of your site hides the origin server. Game servers usually cannot hide their IP because players connect to it directly, so they need protection on the IP itself.

Is DDoS protection included with Nodesty servers?

Yes. nShield DDoS protection, with more than 3 Tbps of filtering capacity across layers 3 to 7, is included with every AMD Ryzen 9 9950X VPS at no extra cost.

Nodesty

About the author

Nodesty Team · Infrastructure & Support

The Nodesty team runs our servers, network and DDoS protection day to day and answers customer support requests around the clock. These guides come from that work.

Related articles

Launch your server now.

Build, scale, and conquer without limits on Nodesty's premium infrastructure.

                                                                                                                                                                                                                            
                                                                                                                                                                                                                            
                                                                                                                                                                                                                            
                                                                                                                             ············································                                                   
                                                ··································································································..........···························                                     
                                       ················..........................................................................................................................··············                             
                                  ·············.................::::::::::::::::::::::::::::::::::::::::::::::....................:::::::::::::::::::::::::::::::::::::::................···········                        
                             ············................:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::............·········                     
                         ············.................:::::::::::::::::::::::::::::::::::::::::::::::::::------------::::::::::::::::::::::::::::::----------------:::::::::::::::::::::..........········                  
                    ············......................::::::::::::::::::::::::::::::::::::------------------------------------------------------------------------------------:::::::::::::.........········                
                ··········.............................................::::::::::::::::::-------------==========================================-----------------------------------:::::::::::........·······               
             ········..................:.....................................::::::::::--------=======+++++++++++++++++++++++++++++++++++++=========================------------------::::::::::.......·······              
           ······.........::::::::::::::::::::................................:::::::-----=====++++xxxxxx**************************xxxxxxxxx++++++++++++++===================------------::::::::.......·······             
          ·····.......:::::::::::::::::::::::::::.............................:::::----===+++xxx****%%%%&&&&&&#############&&&&&&&%%%%%*******xxxxxxxx++++++++++++++==============----------:::::::......······             
         ····......::::::::-------------:::::::::::..........................::::---===+++xx***%%%&&&####@@@@@@@@@@@@@@@@@@@@@@@@####&&&&&%%%%*******xxxxxxxxx+++++++++++++===========--------::::::......·····             
        ····.....:::::::--------------------:::::::::.......................::::---===++xxx**%%&&&###@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@###&&&&%%%%%********xxxxxxxxxxx++++++++++++========------::::::.....······            
        ····.....:::::--------------------------::::::::....................::::---===++xx***%%&&&####@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@###&&&&&%%%%%**********xxxxxxxxxxxxx+++++++++=======------:::::.....·····            
        ····....::::::-------=============---------:::::::::................:::::---===+++xx***%%%&&&#####@@@@@@@@@@@@@@@@@@@@@@@@@#####&&&&&%%%%%%*************xxxxxxxxxxxxxx+++++++++======-----:::::....·····            
         ····....:::::-------================---------:::::::::...............:::::----===++++xxx***%%%%&&&&&&#################&&&&&&%%%%%%%*******************xxxxxxxxxxxxxxxxx++++++++======----:::::....·····            
         ·····....:::::--------=================---------::::::::::..............:::::::-----====+++++xxxxxx**************************xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx++++++++=====-----::::....·····            
          ·····.....:::::--------=================----------:::::::::::.................:::::::::-------=============++++++++++++++++++++++++++++++++++++xxxxxxxxxxxxxxxxxxxxxxx++++++++======-----::::....·····            
            ·····.....:::::::----------===========-------------::::::::::::.........................::::::::::::::::::------------------=============+++++++++++++++++++++++++++++++++=======-----::::.....·····            
              ······......:::::::---------------------------------:::::::::::::........................................:::::::::::::::-----------============+++++++++++++++++++++========------:::::.....·····             
                 ······........:::::::::---------------------------:::::::::::::::::...........................................:::::::::::::------------=============================--------::::::.....······              
                    ·········.........:::::::::::::::-------------::::::::::::::::::::::::.......................................::::::::::::::::--------------------------------------::::::::......·······                
                          ··········............::::::::::::::::::::::::::::::::::::::::::::::::::................................::::::::::::::::::::::::::-------------:::::::::::::::.........········                   
                                  ············..................:::::::::::::::::::::::::::::::::::::::::::.........................:::::::::::::::::::::::::::::::::::::................···········                        
                                             ················.............................................................................................................·················                                 
                                                           ······················................................................................···························                                                
                                                                               ·········································································