A DDoS attack happens when someone overwhelms a website or online service with more traffic or requests than it can handle. The goal is simple. Push the system past its limits until real users struggle to get through.

But the traffic doesn’t always look the same. Attackers use different methods depending on what they want to exhaust. Sometimes it’s network bandwidth. Sometimes it’s a server resource. And sometimes the attacker goes after the application itself.

Volume-Based DDoS Attacks

Imagine your website has a road leading to it. Now imagine that road suddenly fills with useless traffic, leaving no room for genuine visitors. That’s roughly what a volumetric DDoS attack does.

A UDP flood is one common example. The attacker sends huge numbers of UDP packets toward the target, forcing the network or server to deal with traffic that isn’t coming from legitimate users. Because UDP doesn’t establish a connection in the same way TCP does, it’s often abused for this purpose.

ICMP floods work differently but aim for a similar result. The attacker sends large amounts of ICMP traffic, such as ping requests, and the target spends resources processing them.

Why These Attacks Hurt

The biggest problem is bandwidth. Once the connection is saturated, normal requests have nowhere to go.

• UDP floods can generate enormous traffic, and the server still has to spend resources processing those packets.

• ICMP traffic looks harmless at first, but a large enough flood can clog the connection surprisingly quickly.

Protocol Attacks

Protocol attacks get a little more specific. Instead of simply throwing as much traffic as possible at the network, they take advantage of how network devices handle connections and requests.

A SYN flood is a classic example. A normal TCP connection begins with a handshake. The attacker sends a large number of SYN requests but doesn’t complete the process, leaving the target holding incomplete connections while more requests keep arriving.

So the server’s connection resources gradually fill up. Legitimate users then find that their requests are delayed or rejected.

Another example is a Ping of Death attack, which abuses unusually large or malformed network packets. Modern systems are far better at handling this technique, so it’s mostly a historical example now.

Application-Layer DDoS Attacks

Application-layer attacks go after the part users actually interact with. Think websites, APIs, or specific online functions.

An HTTP flood is probably the easiest example to picture. The attacker sends huge numbers of HTTP requests that look like ordinary website visits. If enough requests reach a login page or search function, the application has to keep working through them.

And that’s what makes these attacks annoying to detect. The traffic can look much closer to genuine activity than a giant stream of obviously abnormal packets.

The Quiet Ones

Slowloris attacks take another approach. Instead of sending a massive amount of traffic, the attacker keeps many connections open and sends data very slowly. The server waits for those connections while legitimate users try to get in.

It feels less like a flood and more like someone quietly occupying every available seat.

Multi-Vector DDoS Attacks

Some attacks don’t stick to one technique. Attackers combine methods and change direction if the first approach gets blocked.

For example, a campaign might begin by overwhelming network bandwidth and then shift toward an application endpoint. The exact combination depends on the target and its defenses.

The important question isn’t simply whether a website gets attacked. It’s what the attacker chooses to exhaust. Bandwidth. Connections. Server resources. Or the application itself.