PlaybooksDDoS attack overwhelms the service
Infrastructurecritical45 minutes to prepare

DDoS attack overwhelms the service

Malicious traffic exhausts bandwidth, connections, compute, or expensive application operations.

01DetectConfirm the signal
02ContainStop more damage
03RecoverRestore control
04VerifyProve it works

Your preparation

0 of 0 safeguards ready
0%
Incident worksheet

Make the next decision with evidence

Keep critical paths available, separate abusive from legitimate demand, and avoid moving the bottleneck from the edge to the origin or a paid dependency.

EvidenceDecisionActionProof

Capture before evidence disappears

  • Capture request rate, bandwidth, methods, paths, countries, ASNs, IPs, fingerprints, cache status, challenge outcomes, origin load, and start time.
  • Separate network, protocol, application, login, search, API, and expensive-query traffic patterns.
  • Record every rule, threshold, allowlist, block, challenge, cache, and origin change with before-and-after impact.

Decisions that change the response

QuestionAct whenAction
Block or challenge?A signal is strong enough to measure false positives.Block high-confidence abuse, challenge uncertain traffic, and preserve access for customers and providers.
Degrade features?Expensive noncritical endpoints threaten core availability.Disable or cache them, cap concurrency, and prioritize authentication, purchase, and status paths.

Proof that recovery worked

  • Origin saturation, error rate, and latency recover while legitimate conversion and login rates remain acceptable.
  • Rules work at the edge and attackers cannot bypass them through alternate hostnames or direct origin access.
  • Costs, logs, and third-party limits remain controlled through the attack window.

Controls to put in place

  • Hide and firewall the origin so only approved edge networks can reach it.
  • Set endpoint-specific rate, concurrency, cache, and cost controls before an attack.
  • Maintain provider contacts, emergency rules, safe allowlists, and a static status channel.
Tabletop drill

Generate authorized load against a staging endpoint. Apply a targeted rule, preserve a legitimate cohort, degrade an expensive feature, and verify the origin stays below its limit.

Escalate when

Open the DDoS provider's emergency route when capacity or attack sophistication exceeds self-service controls; involve law enforcement only through qualified advice for credible extortion or threats.

What this means

The attack may target the network, HTTP endpoints, login, search, exports, or any operation that amplifies cost. Scaling alone can convert downtime into a large bill.

Warning signs

  • Request volume or connections rise without matching customers or conversions.
  • Traffic clusters around costly endpoints, networks, or fingerprints.
  • Origin resources saturate while the CDN remains reachable.
  • Cloud cost and latency increase together.

Recover now

First 15 minutes

  1. Confirm traffic shape and the exhausted resource.
  2. Put the service behind the configured DDoS/CDN protection layer.
  3. Rate-limit or challenge abusive paths and protect the origin address.
  4. Disable optional expensive features before scaling blindly.

Today

  1. Work with hosting and protection providers using timestamps and traffic samples.
  2. Add caching, queues, concurrency caps, and per-account limits.
  3. Rotate an exposed origin address or credential if attackers bypass the edge.
  4. Review cost exposure and set temporary spending controls.

Verify recovery

  • Legitimate journeys work at expected latency.
  • Origin traffic comes only through intended paths.
  • Abusive traffic is blocked before scarce resources.
  • Cost and resource use return to a sustainable range.

Prepare now

Access

  • Protection controls can be changed by two authorized people.

Backups and evidence

  • Traffic, firewall, origin, and cost logs are retained.

Contacts and ownership

  • Hosting, CDN, and DNS emergency support routes are recorded.

Practice

  • A load test has proved rate limits and degraded-mode behavior.

Common mistakes

  • Autoscaling without a cost ceiling.
  • Blocking entire countries without measuring customer impact.
  • Leaving the origin directly reachable.

Sources

Last reviewed July 19, 2026Guidance changes. Confirm provider-specific actions in the linked official sources.