o systematically catalog and mitigate distributed traffic floods, network engineers evaluate attacks based on the structural layers they target within the Open Systems Interconnection (OSI) reference model. The OSI model segments network communications into seven distinct operational layers, standardizing how separate computer systems, hardware appliances, and software services exchange data payloads.
Distributed denial-of-service campaigns typically focus their exploitation routines on three primary vectors: Volumetric Floods, State-Exhaustion Protocol Attacks, and Application-Layer Disruptions.
Table of Contents
1. Volumetric Attacks (Bandwidth Saturation)
Volumetric campaigns represent the most straightforward form of distributed disruption. The primary operational objective is to completely saturate the physical data pipes and available bandwidth capacity between the target network boundary and the public internet.
- Targeted Layers: Primarily impacts the network perimeter, pipe capacity, and edge routing gateways.
- Core Technical Mechanism: Threat actors use global botnets to flood the victim’s ingress ports with a massive volume of data frames, creating a traffic bottleneck that blocks legitimate data packets from reaching the infrastructure.
- DNS Amplification Case Example: An attacker leverages stateless UDP protocols to run a reflection-based amplification sequence. Using custom socket scripts, the attacker sends small, high-frequency Domain Name System (DNS) query packets to open public DNS resolvers distributed across the web. Crucially, the source IP addresses inside these request headers are sfałszowany (spoofed) to match the target victim’s public IP block.When the public DNS resolvers process the requests, they reply with large, comprehensive cryptographic zone file records. Because the source headers were manipulated, these amplified data responses are directed straight to the victim’s network. A minor initial request from the botnet results in an amplified payload delivery that quickly overwhelms the target’s data lines.
2. Protocol Attacks (State-Table Exhaustion)
Protocol-level campaigns target the internal processing limits of core infrastructural components, including web servers, load balancers, and stateful hardware firewalls. Rather than focusing purely on raw bandwidth volume, these vectors exploit the fundamental communication rules embedded within the network protocol stack.
- Targeted Layers: Layer 3 (Network) and Layer 4 (Transport) of the OSI protocol stack.
- Core Technical Mechanism: These exploits take advantage of known architectural behaviors within internet transfer frameworks to consume systemic connection table limits and memory queues.
- SYN Flood Case Example: This vector exploits the standard three-way handshake required to establish a reliable TCP (Transmission Control Protocol) connection. In normal operations, a client transmits a synchronization (
SYN) packet, the server returns a synchronization-acknowledgment (SYN-ACK) packet to reserve a temporary communication state, and the client closes the loop with an acknowledgment (ACK) packet.During a SYN flood, the botnet transmits a massive stream ofSYNrequests carrying falsified, unreachable source IP addresses. The target server dutifully allocates memory space in its connection tables and replies with aSYN-ACKpacket to each request. Because the source IPs are fake, the final closingACKhandshake never arrives. The server’s memory queues fill up waiting for these half-open connections to time out, leaving it unable to accept legitimate incoming connection requests.
3. Application-Layer Attacks (Resource Exhaustion)
Often designated as Layer 7 DDoS attacks, these operations focus on the specific software layer where web applications generate content, process transactions, and respond to user inputs. Because these requests closely mimic legitimate web browsing activity, they can be exceptionally difficult to detect and filter out.
- Targeted Layers: Layer 7 (Application) of the OSI model, focusing on protocols like HTTP, HTTPS, and API execution loops.
- Core Technical Mechanism: The attacker’s objective is to execute highly targeted requests that require minimal bandwidth to transmit but demand significant computational, database lookup, or memory resources from the backend origin host to process.
- HTTP Flood Case Example: An HTTP flood operates similarly to having thousands of computers simultaneously and continuously executing a hard manual refresh inside their web browsers. The botnet directs a stream of valid
HTTP GETorHTTP POSTrequests at resource-intensive endpoints on the target web server, such as complex search fields, file download scripts, or checkout payment forms.To answer each request, the web server must execute backend application code, query relational database servers, and dynamically compile the layout view. This high volume of concurrent data queries quickly consumes all available CPU cycles and database connection pools, causing the web application to drop connections or crash entirely.
Comparative Structural Summary
| Attack Category | OSI Layer Primary Target | Metric Measured By | Main System Vulnerability |
| Volumetric Attacks | Network / Edge Gateways | Bits per Second (bps) / Terabits per Second (Tbps) | Inbound internet pipe capacity limits. |
| Protocol Attacks | Layer 3 & Layer 4 (TCP/IP) | Packets per Second (pps) | Firewall state-tables and server connection memory pools. |
| Application Attacks | Layer 7 (HTTP / HTTPS) | Requests per Second (rps) | CPU thread availability and relational database query queues. |