High severityHARDEC6 steps · 5 phases
Denial of Service (DoS/DDoS) Response
Incident response for volumetric/protocol/application-layer DoS attacks.
Information note
Informational note: In DDoS response, rapidly identify the traffic type (volumetric, protocol exploitation, or application layer); different categories require different mitigation mechanisms. Against amplification attacks on UDP-based protocols such as NTP, DNS, and SSDP, ISP-level source filtering (BCP38/RFC 2827) and a cloud-based scrubbing service should be used together. Prioritize affected services in the incident and activate the partial service continuity plan.
1
Preparation
1 steps- DDoS protection & runbook
Upstream/CDN scrubbing, capacity plan, provider emergency contacts, rate limiting.
2
Detection & Analysis
1 steps- Characterize the attack
Vector (volumetric/protocol/app-layer), target service, source distribution, deviation from baseline.
3
Containment, Eradication & Recovery
2 steps- Mitigate traffic
Activate scrubbing/CDN, block/geofence malicious sources, rate-limit, distribute via anycast.
- Filter malicious traffic
Tune filter rules, apply bot management/WAF for app-layer, report the source (botnet).
4