Cyber Risk Compendium

Denial of service

BSI ID: G 0.40

There are a variety of different types of attacks that aim to prevent the intended use of certain services, functions or devices. The generic term for such attacks is ‘denial of service’. The term ‘DoS attack’ is also frequently used. Such attacks can originate from disgruntled employees or customers, but also from competitors, blackmailers or politically motivated perpetrators. The targets of the attacks can be business-related assets of all kinds. Typical forms of DoS attacks are

  • Disruption of business processes, e.g. by flooding the order acceptance system with incorrect orders,

  • Impairment of infrastructure, e.g. by blocking the doors of the institution,

  • Causing IT failures, e.g. by deliberately overloading the services of a server in the network.

This type of attack is often related to distributed resources, whereby an attacker uses these resources to such an extent that they are no longer available to the actual users. In IT-based attacks, the following resources, for example, can be artificially restricted: processes, CPU time, RAM, disk space, transmission capacity.

Example:

  • In spring 2007, numerous Internet services in Estonia were subjected to severe DoS attacks over a prolonged period. This resulted in significant disruption to the use of information services and other services on the Internet in Estonia.