In today’s digital environment, the security of information systems is of paramount importance. Today, a huge number of people as well as companies rely on online services and network resources for their daily activities. However, along with the obvious benefits of digitalization, there are also serious challenges to cybersecurity. For example, one such threat is the so-called DoS (Denial of service) attack.
While the term «DoS attack» may be unfamiliar to the general public, this type of cyberattack poses a real danger. The first case of this type of attack was recorded back in February 2000, in which a hacker from Canada attacked the web servers of Amazon and eBay. Since then, this form of cyber intrusion has become increasingly common in many areas.
To better understand DoS attacks and how they can affect your virtual holdings, check out our guide here. In this article we will explain in detail what Denial of service attacks are, how they occur, what damage they can cause and how you can protect yourself from them.
Kinds of DoS attacks
A DoS (Denial of service) attack is a class of cyberattack intended to disrupt the usual operation of online resources. Attackers try to overload a system or web site with an enormous amount of requests, which eventually results in denial of service for another customer.
There are several basic kinds of DoS attacks, each of which has its own characteristics and methods of realization:
Buffer overflow
This is among the most widespread forms of DoS attacks. It is based on submitting a large volume of information to an object that cannot process it correctly. For instance, an attacker can submit much more data to a web server than it is capable of receiving and processing. As a result, the server «chokes» from the excessive load, begins to work incorrectly and may eventually be paralyzed. Such attacks not only disrupt the resource, but also potentially give an attacker the opportunity to gain control over it.
ICMP flooding
Also called «death ping» or «smurf attack», this attack targets vulnerabilities in the configuration of network devices. The hacker submits a large amount of bogus ICMP packets (e.g., echo reply requests) to all nodes in the target network. This leads to network channel congestion and resulting denial of services.
SYN flooding
In this attack, the hacker utilizes a weakness in the TCP connection establishment mechanism. An attacker sends multiple TCP connection establishment requests (SYN packets) but does not complete them. This blocks the resources of the web server, which tries to keep track of all these incomplete connections, causing the server to stop working.
UDP flooding
Utilizes a weakness in the UDP protocol. The hacker submits a large amount of UDP packets to random ports on the destination server. This causes the server to try to find the application to which the packets are intended and eventually refuses to serve the requests.
What is the distinction between DoS and DDoS attacks?
DoS and DDoS (Distributed denial of service) attacks have the same goals of disrupting the regular functioning of web resources and making them inaccessible to users. However, there are important distinctions among these 2 kinds of attacks.
A DoS attack originates from a common source — the attacker utilizes a server or computer to send a large amount of requests to the destination network resource. This overloads the system and causes a denial of service.
A DDoS attack, on the other hand, is a distributed attack. In this case, the threat is coming from numerous sources at once - an entire network of compromised PCs, a so-called «botnet», simultaneously bombards the victim with its requests. Such a coordinated attack from multiple locations is much more effective and more difficult to detect and counteract.
The basic characteristics of DoS and DDoS attacks are as follows:
- Number of sources: DoS is a single source, DDoS is multiple sources
- Complexity: DDoS is more difficult to detect and block than a simple DoS attack.
- Scale: DDoS can paralyze large and well-defended resources, while a DoS attack can be less destructive.
- Anonymity: DDoS provides more anonymity to attackers than DoS does
What effect can DoS and DDoS attacks have on virtual currencies?
DoS and DDoS attacks are a critical threat to the cryptocurrency ecosystem.
The blockchain networks that underpin most digital currencies have some protection against such attacks due to their distributed structure. Even if some nodes in the network are taken down, the blockchain can continue to function as there are many other active nodes validating transactions.
However, this doesn’t mean that cryptocurrencies are completely secure. Vulnerable «places» can be cryptocurrency wallets, servers of mining pools or websites of crypto projects. Disruption of these elements can negatively affect the entire ecosystem. For example, a DoS/DDoS attack on crypto stock exchanges can prevent traders from making transactions, cause panic in the trading market and result in considerable price swings.
In order to protect their assets, market participants need to utilize more advanced methods to counter cyber risks:
- Multi-level defense. Implement comprehensive solutions that combine advanced traffic analytics, abnormality identification, auto-response, and manual control. This approach allows you to quickly identify and neutralize attacks of various nature.
- Distributed architecture. Cryptocurrency projects should strive to decentralize their systems as much as possible by distributing critical components across different geographically remote sites. This increases resilience and makes successful DDoS attacks more difficult.
- Integration with countermeasure services. Use of specialized scrubbing systems which can monitor and filter harmful traffic in real time, preventing it from entering the crypto project infrastructure.
- Constant monitoring and response. Implement systems to monitor network activity, quickly detect and remediate DoS/DDoS threats, and debug incident action plans.
Understanding and utilizing these and other security best practices is key to reliably protecting crypto ecosystems from disruption.



