What Is a DDoS Attack? A Plain-English Guide for Website Owners
A DDoS attack floods a website with traffic until real visitors can't get through. How DDoS attacks work, the main types, how likely a small site is to be hit, what DDoS protection actually does, and the cheap steps that protect a small app.
A DDoS attack — distributed denial of service — is an attempt to knock a website or service offline by overwhelming it with more traffic than it can handle. Real visitors can't get through because the server, or the network in front of it, is busy drowning.
The idea, with an analogy
Picture a small shop. A denial-of-service attack is one person blocking the doorway so customers can't get in. You can ask that one person to leave.
A distributed denial-of-service attack is ten thousand people, from all over town, crowding the entrance at once, each looking like a customer. You can't just remove one; there are too many, and they look like everyone else.
In practice, the "crowd" is usually a botnet: thousands or millions of hijacked devices — home routers, cameras, servers — controlled by an attacker and told to send traffic at a target.
The main types
1. Volume attacks
Send so much data that the connection to your server is saturated, like flooding a pipe. Measured in gigabits or even terabits per second. No single small server can absorb these; protection has to happen upstream, at the network level.
2. Protocol attacks
Abuse how network connections work — for example, starting huge numbers of connections and never finishing them, filling up the server's or firewall's connection tables.
3. Application-layer attacks
Send requests that look like normal visitors but target expensive pages — search, login, "generate report", an AI chat endpoint. Far fewer requests are needed, because each one makes your server or database do real work. These are harder to tell apart from real traffic.
How likely is a small site to be attacked?
Large, deliberate DDoS attacks usually target big companies, gaming servers, financial services, or sites someone has a grudge against. Most small apps will never face one.
What small apps face constantly is the milder cousin: bots — scrapers, vulnerability scanners, credential-stuffing attempts against your login, spam on your forms, and automated abuse of anything that costs you money (especially AI endpoints). They can't take a well-built site offline, but they can slow it down and run up bills. (How to stop bots from running up your AI app's bill.)
What DDoS protection does
DDoS protection providers — large CDNs and cloud networks — sit in front of your site with enormous network capacity spread across the world. They:
- absorb volume across their whole network, so your server never sees the flood,
- filter traffic that's clearly malicious (malformed packets, known botnets),
- challenge suspicious visitors with checks that real browsers pass and simple bots don't,
- rate-limit abusive sources.
Many CDN and hosting providers include basic DDoS protection by default, often on free plans. (What is a CDN?)
Practical steps for a small app
You don't need an enterprise contract. You need sensible defaults:
- Put your site behind a provider with DDoS protection, or a host that includes it.
- Rate-limit your expensive endpoints — login, signup, search, AI calls — per IP and per user. (What is rate limiting?)
- Cache what you can. Pages served from a cache cost your server nothing. (What is caching?)
- Add a CAPTCHA to public forms. (How to add a CAPTCHA to your forms.)
- Set spending limits and alerts on anything billed by usage — AI APIs, serverless functions, email — so an attack can't become a huge bill.
- Know when you're down. Uptime monitoring tells you before your users do. (How to know when your app is down.)
- Don't expose your server's real IP if you rely on a protective proxy — attackers who find it can bypass the protection.
If you're under attack
- Check your provider's dashboard: most show attack traffic and offer an "under attack" mode with stricter challenges.
- Temporarily rate-limit or block the targeted endpoint.
- Contact your host — they've seen it before.
- Keep a record of times and traffic for any later report.
DoS vs DDoS vs "just popular"
A sudden traffic spike isn't always an attack. A post going viral looks similar at first. The difference: real visitors browse normally across your site; attack traffic hammers the same few URLs with odd patterns. Your logs will tell you which. (Load testing your app helps you know how much legitimate traffic you can handle.)
The summary
- A DDoS attack overwhelms a site with traffic from many sources at once, usually a botnet.
- Types: volume floods, protocol abuse, and application-layer requests to expensive pages.
- Small sites rarely face big attacks but constantly face bots.
- Protection: a provider in front, rate limits, caching, CAPTCHAs, spending limits, monitoring.
EasySpawn runs every app on its own isolated virtual machine — so a noisy neighbour's traffic never becomes your outage — with daily backups and HTTPS on your own domain built in. See how it works or join the waitlist.
Related: What Is a Server? · Reverse Proxies Explained · Implementing Rate Limiting · Horizontal vs Vertical Scaling
Keep reading
UFW Firewall Basics: Lock Down a Linux Server in Five Commands
A firewall decides which network traffic can reach your server. UFW makes Linux's firewall simple: allow SSH, HTTP and HTTPS, deny the rest. The commands, how not to lock yourself out, why your database port should never be open, and the Docker gotcha that bypasses UFW.
Linux File Permissions Explained: chmod 755, 644, and "Permission Denied"
What rwxr-xr-x means, how chmod numbers like 755, 644 and 600 work, chmod +x for scripts, chown, the correct permissions for SSH keys, and why chmod 777 is never the right fix for "Permission denied".