The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How a Denial-of-Service attack works

Prev Next

In most DoS attacks, the legitimate users are denied access to an online resource, a website, or a server. This is achieved by exhausting the physical resources of the victim or by disrupting network connections to it. There are also some specific DoS attacks which exploit a flaw in the target. These are known as vulnerability attacks. However, the result is the same — disruption of the network services. The two most common methods of perpetrating a DoS attack is targeting physical resources and network connections.

Targeting physical resources

Targeting physical resources of a victim is often an effective tactic because it is a violation of how the internet works. The virtual world of the internet is a web of interconnected physical resources, such as, bandwidth, processors, memory and so on. These resources are limited. For example, at any given time, a website processes a number of requests. Once this number is achieved, all the current requests are processed before handling new ones. If a DoS attacker continues to flood the website with requests, new requests are prevented from being fulfilled. The legitimate user requests are also denied access, thus creating a DoS attack.

Targeting network connections

The Internet depends on network connection, such as connections established between a website and a user's computer. The number of connections that can be established with a website are limited. Additionally, the connections should conform to certain protocols. An attacker disrupts these connections by using invalid or an exhaustive number of connection requests to flood the victim. This results in a DoS attack.

Attacked systems see an upsurge in network traffic. If the system does not crash from the attacks, its network capacity is exhausted. Some attacks generate traffic at the rate of several gigabits per second, which far exceeds the capacity of most Internet sites. The increase often results in the Internet service being significantly slowed or completely disconnected. Attempts to form new connections, or reconnect, might not be processed at all.