Malware
DDoS
Also called distributed denial of service.
DDoS is a flood of requests from many machines at once, meant to exhaust a site's bandwidth, CPU, or connections so real visitors get errors. The "distributed" part is what makes blocking one address useless.
How it is measured
You measure it from the edge: requests per second, bandwidth in Mbps or Gbps, and the number of distinct source IPs over a window. A site that serves 40 requests a second on a normal day and sees 25,000 for ten minutes is under attack. Application-layer floods hit expensive URLs like search or login; network floods fill the pipe.
Uptime monitors show the effect from outside: timeouts and 503s from several locations, while the server's own metrics show maxed CPU or full connection tables.
Worked example
A ticketing site goes dark minutes after a concert goes on sale. The origin log shows 180,000 requests in 90 seconds to `/search?q=` from about 9,000 addresses, each making 20 requests. The database is at its connection limit.
The host turns on rate limiting on search, serves a cached result for repeat queries, and puts a challenge page in front of the endpoint. Error rate falls from 94 percent to 3 percent within the hour.
How it differs
A DDoS is volume designed to deny service. A WAF filters individual malicious requests by their content. A WAF may help with an application-layer flood, but cannot absorb a volumetric one that fills your network link. Rate limiting caps what one source can do and weakens a DDoS only when sources are few enough to hit the cap.
Common errors
Calling any traffic spike an attack, when a viral post looks similar. Blocking by IP when there are thousands. Skipping caching on expensive pages. Not knowing who to call at your host. Assuming a small site is not a target. Forgetting that one request to a heavy endpoint can cost more than a hundred static ones.
In practice
Learn your normal request rate and your most expensive URLs this week. Cache what you can, rate-limit search and login, and put a CDN or scrubbing service in front of the origin. Write down your host's emergency contact before you need it.