Glossary
Volumetric attack
A volumetric attack is a type of Distributed Denial-of-Service (DDoS) attack that overwhelms a target with massive amounts of network traffic. The objective is to exhaust available bandwidth, network capacity, or infrastructure resources, preventing legitimate users from accessing websites, applications, APIs, or online services.
Volumetric attacks remain one of the most common and disruptive forms of DDoS activity because they are designed to consume resources at scale and create widespread service disruption.
{{anchor:How attacks work}}
How volumetric attacks work
Attackers typically use botnets or amplification techniques to generate large volumes of malicious traffic directed at a target.
Common volumetric attack methods include:
- UDP floods – Large volumes of User Datagram Protocol (UDP) traffic directed at a target.
- ICMP floods – High volumes of ping traffic designed to consume resources.
- DNS amplification attacks – Exploiting DNS infrastructure to amplify traffic directed at a victim.
- SYN floods – Overwhelming connection-handling capabilities through excessive connection requests.
- Reflection and amplification attacks – Leveraging third-party systems to increase attack volume.
These attacks are commonly measured in:
- Bits per second (bps)
- Packets per second (pps)
- Connections per second (cps)
As attack volumes increase, legitimate traffic may be delayed, dropped, or completely blocked.
{{anchor:Why they matter}}
Why volumetric attacks matter
Volumetric attacks can have significant business impacts, including:
- Service outages and downtime
- Degraded application performance
- Lost revenue and productivity
- Customer dissatisfaction and churn
- Increased operational and recovery costs
- Reputational damage
Organizations that depend on online availability are particularly vulnerable to the effects of large-scale traffic floods.
{{anchor:Reducing attack risk}}
Reducing volumetric attack risk
Organizations can improve resilience through a layered approach that includes:
- Traffic monitoring and anomaly detection
- Redundant and distributed infrastructure
- Rate limiting and traffic management controls
- DNS resilience and availability planning
- Content delivery networks (CDNs)
- Network architecture designed for scalability
- Incident response planning and testing
A resilient infrastructure strategy helps organizations absorb traffic surges and maintain service availability during attack conditions.
{{anchor:How DigiCert helps}}
How DigiCert can help
DigiCert UltraDNS provides enterprise-grade authoritative DNS services designed to help organizations maintain availability, performance, and resilience during periods of elevated traffic and attack activity. Built on a globally distributed Anycast architecture, UltraDNS distributes DNS traffic across multiple points of presence, helping reduce the risk of localized congestion and service disruption.