northdan.
Vezi pagina în română

IT Glossary

What is a DDoS attack?

A distributed denial of service attack floods a website or online service with fake traffic from thousands of devices at once, until genuine customers can no longer get in.

The worst day to lose your website is the day you spent the most on advertising for it, and attackers know that too. In a distributed denial of service attack, thousands of compromised machines — home routers, cameras, hijacked servers scattered across the world — send requests to your site simultaneously. No password is broken and no data is stolen. The site simply runs out of capacity to answer, and the customer who wanted to buy sees a timeout. The distributed part is what makes it hard: blocking a single address achieves nothing when the flood arrives from tens of thousands of them, most belonging to innocent owners. Motives range from extortion notes and competitor mischief to attacks aimed at a hosting neighbour that catch you by accident. The commercial exposure is easy to calculate and unpleasant to experience: revenue lost per hour offline, penalty clauses in the service agreements you signed with your own clients, and a cloud bill for traffic that was never going to convert. Mitigation is now cheap enough that being unprotected is a decision rather than a budget constraint.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

Trading continues through peak days

Filtered traffic keeps checkout reachable exactly when a campaign, a launch or a seasonal peak makes downtime most expensive.

Predictable infrastructure bills

Junk requests absorbed at the network edge never reach your servers, so an attack does not arrive later as a surprise usage invoice.

Reputation and SLAs protected

Uptime commitments you made to your own customers survive an event you did not cause and could not otherwise control.

Frequently asked questions

Who would bother attacking a small company website?

Most attacks are not personal. Rented attack services cost less than a restaurant meal per hour, so targets include shops during promotions, booking platforms, anyone who annoyed the wrong forum, and firms whose only sin was sharing infrastructure with the real target. Being small is not protection; being uninteresting merely shortens the attack.

How do I tell an attack apart from a genuine traffic spike?

Real traffic has a story behind it: a campaign, a newsletter, a mention somewhere, and it converts at roughly the usual rate. Attack traffic arrives instantly, concentrates on a few expensive pages, shows implausible geography and browser signatures, and buys nothing at all. Your analytics and server logs answer this within minutes if someone knows where to look.

What anti-DDoS protection fits a mid-market budget?

For most firms the answer is a content delivery network with mitigation included, at tens of euros a month, plus rate limiting and caching on the application itself. Dedicated scrubbing services and provider-level packages exist for businesses where minutes offline cost thousands. That cheap first layer stops the overwhelming majority of what actually arrives.