What Is The Difference Between DoS Attacks And DDoS Attacks?

What is the difference between DoS and DDoS Attack

Updated:

September 28, 2026

Table of Contents

    A denial-of-service (DoS) attack makes a service unavailable by overwhelming or disrupting it. A distributed denial-of-service (DDoS) attack does the same using multiple sources. The scale of the threat is clear: Cloudflare mitigated 935network-layer DDoS attacks exceeding 1 Tbps in the first half of 2026. 

    The key difference is where the attack comes from, though both can interrupt websites, applications, and business operations. Common methods target network capacity, connection handling, or application resources. Effective defenses depend on the attack type and may include traffic monitoring, and upstream DDoS mitigation. Our Security Assessments and Penetration Testing can help identify weaknesses that put service availability at risk. 

    In this article, we’ll compare DoS and DDoS attacks, explain their common types and how they work,

    Let’s find out! 

    What Is a Denial-of-Service Attack?

    A denial-of-service (DoS) attack is a cyberattack that makes a website, server, network, or device unavailable to legitimate users. Attackers flood the target with traffic or exploit weaknesses that cause it to slow down, freeze, or crash. A DoS attack originates from a single source. A distributed denial-of-service (DDoS) attack uses multiple sources, often a network of compromised devices called a botnet.

    Verizon’s 2025 Data Breach Investigations Report analyzed 6,520 denial-of-service incidents, highlighting the scale of threats to service availability. This category includes distributed attacks and does not represent single-source DoS attacks alone.

    How Does a DoS Attack Work?

    A DoS attack disrupts a system’s ability to process legitimate requests. It can exhaust resources such as bandwidth, memory, or processing power, or exploit a software flaw that interrupts normal operation.

    Two common methods are:

    Animated Bright Defense diagram showing how a DoS attack works, where a hooded hacker at a laptop sends thousands of fake requests to a website server until it overloads, blocking a real visitor from getting in.
    dos-attack-how-it-works

    Flood Attacks

    Flood attacks overwhelm a target with traffic or requests, consuming the resources needed to serve legitimate users. Some attacks saturate network bandwidth, while others send requests that demand substantial server processing. The result can be slow responses, failed connections, or a complete service outage.

    Vulnerability Exploitation

    Attackers exploit software flaws to crash a service or exhaust its resources. For example, a buffer overflow occurs when a program writes more data into a memory buffer than it can hold. This can corrupt memory and cause the application to crash. A carefully crafted request can sometimes disrupt a vulnerable system without a large volume of traffic.

    What Is a DDoS Attack?

    A distributed denial-of-service (DDoS) attack overwhelms a website, server, or network with traffic from multiple sources, making it slow or unavailable to legitimate users. The attack consumes bandwidth, processing power, or other resources needed for normal operation. Attackers often use compromised computers and Internet of Things (IoT) devices, such as connected cameras and routers, to generate this traffic.

    Cloudflare mitigated 47.1 million DDoS attacks in 2025, more than double its total for the previous year. This figure reflects attacks observed across Cloudflare’s network. |

    How Does a DDoS Attack Work?

    Animated Bright Defense diagram showing how a DDoS attack works, where a hooded hacker at a laptop infects six PCs with malware, orders the bots to flood a website server at once until it crashes, and a real visitor can't get in.
    ddos-attack-how-it-works

    A DDoS attack coordinates traffic from multiple sources to overwhelm a target or its supporting infrastructure. One common method uses a botnet, a group of devices infected with malware and controlled remotely. Each compromised device, called a bot, sends traffic or requests toward the target under the attacker’s instructions. The combined traffic can exhaust available resources, causing slow responses, failed connections, or a service outage. Some DDoS attacks use third-party servers to reflect and amplify traffic toward the target without infecting those servers.

    What Is the Difference Between DoS and DDoS Attacks?

    A denial-of-service (DoS) attack disrupts access to a website, application, or network service by exhausting a resource it needs to operate. A distributed denial-of-service (DDoS) attack has the same goal but sends attack traffic from multiple sources. Both can overwhelm network capacity, consume connection resources, or overload an application with requests.

    The number of attack sources is the defining difference. It affects how much traffic an attacker can generate and how defenders identify and block it. 

    Here is a table that discusses the differences of each side by side: 

    FactorDoS AttackDDoS Attack
    Attack sourcesOriginates from one source.Uses multiple devices or systems.
    Traffic volumeLimited by the capacity of its source, though it can still disrupt a vulnerable service.Can combine traffic from many sources to overwhelm a target.
    ExecutionMay use a script or tool running on one machine.Often uses a botnet coordinated through command-and-control infrastructure, though other distributed methods exist.
    Detection and mitigationTraffic from one source is often easier to isolate and block.Defenders must identify malicious traffic across many sources while allowing legitimate requests.
    Tracing the attackerThe attack source is generally easier to identify, though it may not reveal the person responsible.Identifying the traffic sources may not reveal who controls them, particularly when devices are compromised or addresses are spoofed.

    What Are the Main Types of DoS and DDoS Attacks?

    DoS and DDoS attacks disrupt services by exhausting bandwidth, connection capacity, or application resources. The distinction is the number of sources: a DoS attack originates from one source, while a DDoS attack uses multiple sources. Both can affect the availability of systems protected by network security measures.

    The following examples show how different attack techniques operate as DoS or DDoS attacks:

    1. Teardrop and IP Fragmentation Attacks (DoS)

    IP fragmentation divides a packet into smaller pieces that the receiving system must reassemble. A teardrop attack sends fragments with overlapping positions, causing a vulnerable system to handle them incorrectly. This can disrupt the system’s ability to process traffic.

    The example is a DoS attack when one machine sends the malformed fragments. Teardrop is a specific fragmentation technique, and its effect depends on a vulnerability in the target’s packet reassembly process.

    2. SYN Flood (DoS)

    A SYN flood repeatedly sends requests to begin TCP connections. The target responds and waits for each connection to be completed. If too many remain incomplete, legitimate clients may be unable to connect.

    This is a DoS attack when the requests come from one source. It targets connection handling at Layer 4 of the OSI model.

    3. Slowloris Attack (DoS)

    A Slowloris attack opens connections to a web server and sends partial HTTP requests slowly. The server keeps those connections open while waiting for the rest of each request, tying up capacity it needs to serve other users.

    It is a DoS attack when one machine maintains the disruptive connections. Multiple machines using the same method would make it a DDoS attack.

    4. Distributed ICMP Flood (DDoS)

    An ICMP flood sends large numbers of echo requests toward a target. The target must receive and process the traffic, which can consume bandwidth or other resources needed for legitimate requests.

    It is a DDoS attack when many devices send the requests together. Their combined traffic can overwhelm a connection that any one device could not saturate alone.

    5. DNS Amplification Attack (DDoS)

    In a DNS amplification attack, an attacker sends queries to publicly reachable DNS servers using the target’s spoofed IP address. The servers send their responses to the target, increasing the volume of traffic it receives.

    It is a DDoS attack when responses arrive from multiple servers. The target must handle traffic generated across those separate sources, even though the attacker initiated the queries.

    6. Distributed HTTP Flood (DDoS)

    An HTTP flood sends large numbers of requests to a website or application. Each request can consume server processing capacity, so the service may slow down or stop responding to legitimate users.

    It is a DDoS attack when the requests come from many devices, such as a botnet. Because the requests may resemble ordinary visits, defenders must separate attack traffic from legitimate users.

    How Can Bright Defense Help Defend Against DoS and DDoS Attacks?

    Bright Defense helps organizations identify security gaps before attackers exploit them. Our penetration tests assess web applications, APIs, and networks under an agreed scope. When service availability is a concern, the assessment can examine exposed systems and configurations, then provide prioritized findings and remediation guidance.

    A penetration test helps teams find and address weaknesses, but defending against an active DDoS attack requires traffic monitoring and mitigation capacity. Bright Defense’s security assessment and remediation services can help prioritize improvements to those defenses and guide the work needed to close identified gaps. Contact Bright Defense to discuss the systems you need to protect and the appropriate testing scope.

    Frequently Asked Questions

    1. What Is a DDoS Attack?

    A distributed denial-of-service (DDoS) attack disrupts a website, application, or network service using traffic from multiple sources. Those sources may include compromised devices controlled as a botnet.

    2. What Is a DoS Attack?

    A denial-of-service (DoS) attack makes a service unavailable to legitimate users. It originates from a single source and may overwhelm the target with traffic or exhaust a resource the service needs to operate.

    3. What Are the Main Types of DoS and DDoS Attacks?

    The three main categories are volumetric attacks, which saturate bandwidth; protocol attacks, which exhaust connection or network resources; and application layer attacks, which overwhelm software handling user requests. SYN floods, ICMP floods, HTTP floods, and Slowloris are examples. The method determines the category; the number of attack sources determines whether it is DoS or DDoS.

    4. How Do DoS and DDoS Attacks Work?

    Attackers send traffic or requests that consume more bandwidth, connections, or processing capacity than the target can handle. The service may slow down or stop responding to legitimate users. A DDoS attack draws that traffic from multiple sources, making it harder to block at a single point.

    5. What Are DDoS Protection and Mitigation?

    DDoS protection consists of measures put in place before an attack, such as traffic filtering, rate limits, and upstream capacity. Mitigation is the detection and filtering of malicious traffic during an attack to keep the service available.

    6. What Is a DoS Attack? Give an Example.

    A denial-of-service (DoS) attack disrupts a service from a single source. For example, one machine can send repeated TCP connection requests without completing them. This SYN flood can prevent legitimate users from connecting.

    7. What Are the Three Main Types of DDoS Attacks?

    The three main types are volumetric attacks, which overwhelm bandwidth; protocol attacks, which exhaust network or connection resources; and application layer attacks, which overwhelm the software handling requests. Each is a DDoS attack when traffic comes from multiple sources.

    8. Is a DoS Attack a Cybercrime?

    Launching a DoS attack against someone else’s system without authorization can be a cybercrime. The applicable offense depends on the jurisdiction and circumstances. Testing a system with the owner’s permission is different from attacking it without permission.

    9. What Are Two Examples of DoS Attacks?

    A single-source SYN flood consumes connection capacity by leaving TCP handshakes incomplete. A single-source Slowloris attack holds web server connections open by sending partial HTTP requests slowly. Both are DoS attacks when they originate from one source.

    Tamzid is a cybersecurity researcher with more than 5 years of experience spanning SaaS, cybersecurity, compliance, and blockchain. He holds certifications in Google Foundations of Cybersecurity, Cisco AI Fundamentals with IBM SkillsBuild, Fortinet NSE 1, and Open Source Intelligence (OSINT) from the Basel Institute on Governance.
    His work focuses on turning complex security and compliance topics into clear, practical insights, supported by primary-source research, verified data, and evidence-based analysis.

    Get In Touch

      Group 1298 (1)-min