How to Avoid DDoS Attacks?

A couple of milliseconds delay of your page load time can cause a significant loss of revenue. We have explained this in length, recently. What about a complete stop to all of your website functions? For hours, days, weeks? Such attacks on websites, especially those websites that deal with payment, business transactions or transfer of personal data, are becoming more and more frequent. They are known as denial-of-service (DoS) attacks. Distributed denial-of-service (DDoS) attack means that the attacker/hacker is choosing one computer system as a master system to control sometimes as many as hundreds of thousands other computer systems, known as zombies or bots. They all work with a uniform goal of flooding the targeted host with as many communication packets as possible to stop the website from working. Entirely.

As an online vendor, you are not only under the threat of being flooded with the denial-of-service packets, but also of being used as a zombie machine to perform such attacks.

Book a demo today to see GlobalDots is action.

Optimize cloud costs, control spend, and automate for deeper insights and efficiency.

Book a demo today to see GlobalDots is action.

Not even giants are immune to distributed denial-of-service (DDoS) attacks. Yahoo! was inaccessible for 3 hours in 2000, and the revenue lost was estimated to about $500,000. In the same year, Amazon was down for 10 hours, with a loss estimated to $600,000. The attacks in the past were not avoided by CIA, or even The Pirate Bay. Each time, the attacks have not only affected businesses, but also individuals, trading companies, file sharers and end-customers.

DDoS attacks are one of the biggest threats to the security on the Internet, since the users of controlled computer systems are usually not aware of the attack performed. And since packets are not coming from a single source, they can not be stopped by simply blocking a single IP address.

If not stopped, how can DDoS attacks be prevented?

Not that using one method of prevention alone can actually protect you. However, by using a combination of a few, you have a better chance of defending your business space. Or, to walk you through defense strategies:

  1. Updates, updates. You should make sure that all of your security patches are always up to date. That your firewalls are the latest versions of those firewalls. That your system is clean and all unused ports are always disabled on the host system.
  2. Use a CDN hosting. Content delivery networks (CDNs) use servers located at different data centers. Not only one, but many communication channels are used. Since the emergence of cloud computing, CDNs are employed not only as a tool for unclogging the internet (see the history of CDNs >>link to post), but also as a tool for mitigating (avoiding) DDoS attacks. CDNs will absorb less-sophisticated DDoS attacks, simply with bandwidth. With CDNs, you gain the advantage of – size.
  3. IP Broadcast and IP Hopping. See that IP broadcast is disabled on the host computer. Also, see that you change location of your active server proactively, using a pre-specified set of IP address ranges.
  4. Filters, filters. See that only trusted IP connections are accessing your website. Drop traffic with others. For this, you will, again, need to apply multiple methods of IP address filtering.
  • Ingress filtering: drop traffic with IP addresses that do not match a domain prefix connected to the ingress router
  • Egress filtering: ensure that only assigned or allocated IP address spaces leave the network
  • Connection limiting: the number of new connection requests is limited, existing connections are preferred
  • Age filtering: idle connections are removed from the IP tables in firewall and servers
  • Source rate filtering: when there are limited number of IP addresses involved in a DDoS attack, outer IP addresses that break the norm are identified
  • Dynamic filtering: create a short-span filtering rule and remove that rule after that time-span
  • Active verification: combined with SYN proxy, legitimate IP addresses are cached into a memory table for a limited period of time and are being let out without the SYN proxy check
  • Anomaly checks: works for scripted DDoS attacks
  • Black List/White List: deny/allow access to certain IP addresses from the lists
  • Dark address prevention: drop traffic with all IP addresses not assigned by IANA

Latest Articles

Your AI Policy Won’t Stop This. Here’s What Does.

A step-by-step walkthrough of what AI governance looks like when it’s technically enforced, not written on paper. Your acceptable use policy says something like: “employees must not share sensitive company data with AI tools.” Someone signed it last quarter. Then they opened ChatGPT, typed a customer name and a contract value into a prompt, and […]

Ganesh The Awesome
5th August, 2026
Who Controls What Your Team Shares with AI? | Cloudflare Zero Trust Webinar

Your employees are using AI tools. You probably don’t know which ones, or what they’re sending.In this session, Ganesh The Awesome walks through how to close that gap in 30 minutes using Cloudflare Zero Trust and Cloudflare AI Gateway. Want to go deeper? We’re happy to run a 1-on-1 session tailored to your environment.

Ganesh The Awesome
29th July, 2026
In 2026, Most CDN Teams Still Find Out About Outages From Customers First

This post is based on a live panel webinar co-hosted by GlobalDots, Hydrolix, and AWS, where engineers and go-to-market leaders across CDN, edge, and agentic AI operations discussed what actually happens when delivery infrastructure breaks. Just five people on the call talking about where visibility fails today, and what changes once agents start watching the […]

Eduardo Rocha
15th July, 2026
From Alert to Action: A CDN & Edge Practitioners Summit

Most teams still learn about a CDN problem from a customer rather than from their own monitoring stack.In this panel, GlobalDots, Hydrolix, and AWS break down why that keeps happening and what it takes to fix it: full-fidelity data instead of sampled logs, and AI agents that can actually act on it. Full Webinar: Demo […]

Eduardo Rocha
15th July, 2026

Unlock Your Cloud Potential

Schedule a call with our experts. Discover new technology and get recommendations to improve your performance.

    GlobalDots' industry expertise proactively addressed structural inefficiencies that would have otherwise hindered our success. Their laser focus is why I would recommend them as a partner to other companies

    Marco Kaiser
    Marco Kaiser

    CTO

    Legal Services

    GlobalDots has helped us to scale up our innovative capabilities, and in significantly improving our service provided to our clients

    Antonio Ostuni
    Antonio Ostuni

    CIO

    IT Services

    It's common for 3rd parties to work with a limited number of vendors - GlobalDots and its multi-vendor approach is different. Thanks to GlobalDots vendors umbrella, the hybrid-cloud migration was exceedingly smooth

    Motti Shpirer
    Motti Shpirer

    VP of Infrastructure & Technology

    Advertising Services

    GlobalDots guided our migration to Cloudflare, implemented SSL for SaaS, eliminated certificate maintenance, and remained highly responsive throughout.

    Chris Cutajar
    Chris Cutajar

    Infrastructure Eng. & Security Manager