Computer Science · Ch 12 — Security Aspects
Denial of Service
Denial of Service
What a Denial of Service attack really is
A Denial of Service (DoS) attack is not about stealing data or breaking into a system. It is about making a resource unusable. The attacker's goal is to stop an authorised user from accessing a service, a device, or any other resource — not by hacking it, but by overloading it with illegitimate requests until it can no longer serve anyone.
Think of a small shop with one counter. If a hundred people rush in and crowd the counter without buying anything, a genuine customer cannot reach the counter at all. The shop looks busy, but no real business is happening. That is exactly how a DoS attack works: it floods the victim resource with traffic, making the resource appear busy to everyone else.
How a DoS attack is carried out
When attackers target a website, they flood it with a very large number of network packets. Crucially, they use different IP addresses to send these packets, so the flood does not look like it is coming from one obvious source. The web server gets overloaded and cannot respond to legitimate users.
The users on the other side simply see that the website is not working. They do not know about the attack — they just assume the site is down. This causes real damage to the victim's organisation, because lost visitors mean lost trust, lost business, and a damaged reputation.
What can be attacked
A DoS attack is not limited to websites. The same technique can be used against many kinds of resources:
- Email servers — flooded so that genuine mail cannot be delivered or received.
- Network storage — overloaded so that files become inaccessible.
- Connections between two machines — disrupted so that communication breaks down.
- The state of information — for example, by resetting active sessions, forcing users to log in again or losing their ongoing work.
Recovering from a DoS attack
The recovery depends on the type of attack. If a DoS attack makes a server crash, the simplest fix is to restart the server or resource. Once it is back up, it can function normally again.
But a flooding attack is much harder to recover from. The problem is that among the flood of illegitimate requests, there are also some genuine legitimate requests mixed in. You cannot simply block everything, because you would block real users too. Separating the genuine traffic from the attack traffic is what makes recovery so difficult.
Distributed Denial of Service (DDoS)
A DDoS attack is a more dangerous variant of DoS. Here, the flooded requests do not come from one machine — they come from many compromised computer systems spread across the globe or over a very large area. These compromised machines are called Zombies.
The attacker first installs a malicious software called a Bot on each Zombie machine. This Bot gives the attacker control over that machine. Then, depending on the requirement and availability, the attacker activates a network of these Zombie computers. This network of Zombies is called a Bot-Net, and it is this Bot-Net that carries out the DDoS attack.