← See all resources
Botnet DDoS Attack
🕸️Network Attacks • Attack Types

Botnet DDoS Attack

How botnets are used to perform distributed denial-of-service attacks.

Tags

BotnetDDoSMalwareNetworking
Download infographic

File: SecPro-ataque-ddos-botnets.png

What is a botnet and how does it run a DDoS?

A botnet is a network of infected devices (computers, routers, IP cameras, IoT gear) remotely controlled by an attacker through a command-and-control (C2) server. On command, every bot sends traffic against a single target at once — the core of distributed denial-of-service (DDoS) attacks, where 'distributed' is exactly the power of thousands of sources striking simultaneously.

Why are botnets so dangerous?

Because traffic comes from thousands of legitimate IPs around the world, telling bots apart from real users and blocking them without harming the service is very hard. Botnets like Mirai proved that misconfigured IoT devices — with default passwords — can be recruited by the millions and generate hundreds of Gbps or Tbps attacks capable of taking down entire infrastructures.

How to defend against a botnet attack?

Defense combines edge mitigation (anti-DDoS services with absorption and scrubbing capacity), rate limiting, IP reputation lists and behavioral analysis to separate human from automated traffic. On the prevention side, keep your own devices from becoming bots: change default credentials, update firmware and segment IoT equipment.

More from Network Attacks • Attack Types

Explore more infographics

View full catalog

Need help with your cybersecurity? 💬