{"id":8951,"date":"2026-05-29T23:01:24","date_gmt":"2026-05-29T21:01:24","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=8951"},"modified":"2026-05-29T23:01:25","modified_gmt":"2026-05-29T21:01:25","slug":"types-of-ddos-attacks","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/types-of-ddos-attacks\/","title":{"rendered":"Types of DDoS attacks"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">o systematically catalog and mitigate distributed traffic floods, network engineers evaluate attacks based on the structural layers they target within the <strong>Open Systems Interconnection (OSI) reference model<\/strong>. The OSI model segments network communications into seven distinct operational layers, standardizing how separate computer systems, hardware appliances, and software services exchange data payloads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Distributed denial-of-service campaigns typically focus their exploitation routines on three primary vectors: <strong>Volumetric Floods<\/strong>, <strong>State-Exhaustion Protocol Attacks<\/strong>, and <strong>Application-Layer Disruptions<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/types-of-ddos-attacks\/#1_Volumetric_Attacks_Bandwidth_Saturation\" >1. Volumetric Attacks (Bandwidth Saturation)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/types-of-ddos-attacks\/#2_Protocol_Attacks_State-Table_Exhaustion\" >2. Protocol Attacks (State-Table Exhaustion)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/types-of-ddos-attacks\/#3_Application-Layer_Attacks_Resource_Exhaustion\" >3. Application-Layer Attacks (Resource Exhaustion)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/types-of-ddos-attacks\/#Comparative_Structural_Summary\" >Comparative Structural Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_Volumetric_Attacks_Bandwidth_Saturation\"><\/span>1. Volumetric Attacks (Bandwidth Saturation)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<\/div>\n\n<div id=\"mybox-2117937262\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Volumetric campaigns represent the most straightforward form of distributed disruption. The primary operational objective is to completely saturate the physical data pipes and available bandwidth capacity between the target network boundary and the public internet.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Targeted Layers:<\/strong> Primarily impacts the network perimeter, pipe capacity, and edge routing gateways.<\/li>\n\n\n\n<li><strong>Core Technical Mechanism:<\/strong> Threat actors use global botnets to flood the victim\u2019s ingress ports with a massive volume of data frames, creating a traffic bottleneck that blocks legitimate data packets from reaching the infrastructure.<\/li>\n\n\n\n<li><strong>DNS Amplification Case Example:<\/strong> An attacker leverages stateless UDP protocols to run a reflection-based amplification sequence. Using custom socket scripts, the attacker sends small, high-frequency Domain Name System (DNS) query packets to open public DNS resolvers distributed across the web. Crucially, the source IP addresses inside these request headers are <em>sfa\u0142szowany<\/em> (spoofed) to match the target victim&#8217;s public IP block.When the public DNS resolvers process the requests, they reply with large, comprehensive cryptographic zone file records. Because the source headers were manipulated, these amplified data responses are directed straight to the victim&#8217;s network. A minor initial request from the botnet results in an amplified payload delivery that quickly overwhelms the target&#8217;s data lines.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_Protocol_Attacks_State-Table_Exhaustion\"><\/span>2. Protocol Attacks (State-Table Exhaustion)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Protocol-level campaigns target the internal processing limits of core infrastructural components, including web servers, load balancers, and stateful hardware firewalls. Rather than focusing purely on raw bandwidth volume, these vectors exploit the fundamental communication rules embedded within the network protocol stack.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Targeted Layers:<\/strong> <strong>Layer 3 (Network)<\/strong> and <strong>Layer 4 (Transport)<\/strong> of the OSI protocol stack.<\/li>\n\n\n\n<li><strong>Core Technical Mechanism:<\/strong> These exploits take advantage of known architectural behaviors within internet transfer frameworks to consume systemic connection table limits and memory queues.<\/li>\n\n\n\n<li><strong>SYN Flood Case Example:<\/strong> This vector exploits the standard three-way handshake required to establish a reliable <strong>TCP (Transmission Control Protocol)<\/strong> connection. In normal operations, a client transmits a synchronization (<code>SYN<\/code>) packet, the server returns a synchronization-acknowledgment (<code>SYN-ACK<\/code>) packet to reserve a temporary communication state, and the client closes the loop with an acknowledgment (<code>ACK<\/code>) packet.During a SYN flood, the botnet transmits a massive stream of <code>SYN<\/code> requests carrying falsified, unreachable source IP addresses. The target server dutifully allocates memory space in its connection tables and replies with a <code>SYN-ACK<\/code> packet to each request. Because the source IPs are fake, the final closing <code>ACK<\/code> handshake never arrives. The server&#8217;s memory queues fill up waiting for these half-open connections to time out, leaving it unable to accept legitimate incoming connection requests.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"3_Application-Layer_Attacks_Resource_Exhaustion\"><\/span>3. Application-Layer Attacks (Resource Exhaustion)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Often designated as <strong>Layer 7 DDoS attacks<\/strong>, these operations focus on the specific software layer where web applications generate content, process transactions, and respond to user inputs. Because these requests closely mimic legitimate web browsing activity, they can be exceptionally difficult to detect and filter out.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Targeted Layers:<\/strong> <strong>Layer 7 (Application)<\/strong> of the OSI model, focusing on protocols like HTTP, HTTPS, and API execution loops.<\/li>\n\n\n\n<li><strong>Core Technical Mechanism:<\/strong> The attacker&#8217;s objective is to execute highly targeted requests that require minimal bandwidth to transmit but demand significant computational, database lookup, or memory resources from the backend origin host to process.<\/li>\n\n\n\n<li><strong>HTTP Flood Case Example:<\/strong> An HTTP flood operates similarly to having thousands of computers simultaneously and continuously executing a hard manual refresh inside their web browsers. The botnet directs a stream of valid <code>HTTP GET<\/code> or <code>HTTP POST<\/code> requests at resource-intensive endpoints on the target web server, such as complex search fields, file download scripts, or checkout payment forms.To answer each request, the web server must execute backend application code, query relational database servers, and dynamically compile the layout view. This high volume of concurrent data queries quickly consumes all available CPU cycles and database connection pools, causing the web application to drop connections or crash entirely.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Comparative_Structural_Summary\"><\/span>Comparative Structural Summary<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><td><strong>Attack Category<\/strong><\/td><td><strong>OSI Layer Primary Target<\/strong><\/td><td><strong>Metric Measured By<\/strong><\/td><td><strong>Main System Vulnerability<\/strong><\/td><\/tr><\/thead><tbody><tr><td><strong>Volumetric Attacks<\/strong><\/td><td>Network \/ Edge Gateways<\/td><td>Bits per Second (bps) \/ Terabits per Second (Tbps)<\/td><td>Inbound internet pipe capacity limits.<\/td><\/tr><tr><td><strong>Protocol Attacks<\/strong><\/td><td>Layer 3 &amp; Layer 4 (TCP\/IP)<\/td><td>Packets per Second (pps)<\/td><td>Firewall state-tables and server connection memory pools.<\/td><\/tr><tr><td><strong>Application Attacks<\/strong><\/td><td>Layer 7 (HTTP \/ HTTPS)<\/td><td>Requests per Second (rps)<\/td><td>CPU thread availability and relational database query queues.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10,42],"manual_kb_tag":[767,768,772,804,850,884,205,210,531,712],"class_list":["post-8951","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety","manualknowledgebasecat-miscellaneous","manual_kb_tag-web-server","manual_kb_tag-web-servers","manual_kb_tag-domain","manual_kb_tag-relational-database","manual_kb_tag-http","manual_kb_tag-web-applications","manual_kb_tag-hardware","manual_kb_tag-edge","manual_kb_tag-domain-name","manual_kb_tag-domain-name-system"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8951","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8951\/revisions"}],"predecessor-version":[{"id":8952,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8951\/revisions\/8952"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=8951"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=8951"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=8951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}