DDoS
A DDoS attack overloads an online service with a flood of requests from many sources until it becomes unavailable.
A Distributed Denial of Service (DDoS) attack overwhelms a service with requests from many sources. The goal is to make websites, online services, or network connections unavailable.
How it works
Attackers use botnets of thousands of compromised devices, such as routers, cameras or servers. These simultaneously send large volumes of data or many requests to the target. A distinction is made between network, protocol, and application layer attacks. Application-layer attacks are harder to detect because they resemble normal user traffic. DDoS attacks are also used as a diversion during another, separate attack.
A practical example
A government agency's website is overloaded for several hours during a political event. A hacktivist group had announced the attack in advance. The provider's protection service filters a large portion of the traffic. The site remains accessible with limited performance, and no data is affected.
What to look out for
- Clarify with your provider what DDoS protection is included and how it is activated.
- Protect critical web services with a specialised service or a CDN.
- Establish a procedure defining who is informed during an attack.
- Assess which of your services are business-critical. Not every website requires the same level of defence.
- Watch for other suspicious activities during a DDoS attack.
Switzerland and regulation
Switzerland has seen repeated DDoS attacks against authorities and companies, often linked to political events. The National Cyber Security Centre (NCSC) informs the public and supports those affected. Since 1 April 2025, operators of critical infrastructure must report attacks threatening functionality to the NCSC. This must be done within 24 hours of discovery, as required by the Information Security Act (ISG).
Relevance for the SOC
DDoS defence is primarily handled by the provider or a specialised service. The SOC has a different role. It checks if the DDoS is a diversion for another attack. It also monitors all other systems with heightened attention.
Typical mistakes
It is often unclear if an existing provider contract includes DDoS protection. Valuable time is then lost during an incident.
How we implement it
During a DDoS event, we specifically monitor for any parallel attack activity. DDoS protection itself is provided by your provider or a specialist service.