Let's take a look at what is a DDoS attack?

Distributed Denial of Service attack (DDoS) is a set of malicious manipulations and procedures used to disable and make inaccessible endpoints on the Internet. Using this attack, the attacker overloads channels and resources of network equipment and thus causes the server or website to fail, depending on the type of attack.

Usually the attacker uses the important parameter of the communication channel - its bandwidth. Using an attack called "flooding", the attacked server is faced with the fact that its entire channel is clogged to failure, "to the ceiling", and thus the actual and "live" requests to the server address can not make it through the queue of this flooding.

L3-L4 network layers are generally considered infrastructure layers and are the most common for attacks because of their ease of implementation. This includes primitive channel jamming via UDP flooding or SYN flooding and subsequent line congestion. Such attacks can be easily spotted by traffic monitoring and appropriate action can be taken.

Application layers L6-L7 are less used because of the complexity of their implementation, as these attacks are aimed at interacting with a specific application on the resource (site, page, form on the site, application on the network, game server) and require certain technical skills.

Methods of protection against DDoS attacks

DDoS protection for VPS/VDS or dedicated server can be performed in active and passive forms.

Passive methods of protection involve the use of special software, which is aimed at filtering incoming traffic to the server and its processing depending on the required parameters. It should be noted that this type of protection is effective only in narrowly targeted attacks with a small amount of traffic, because all of its processing falls on the attacked server. This requires resources and time. And if you have a high-loaded application or resource - it will be extremely detrimental to its availability.

Active methods include filtering and blocking network traffic at the provider level.

Filtering of incoming traffic is done through firewalls and access control lists (ACLs). The entire load of processing incoming traffic on the server falls on the network equipment provider network, so your server gets only clean, filtered traffic and does not experience increased loads and resource consumption during its processing.

