Denial-of-Service (DoS) attacks aim to make a system or network unavailable to legitimate users by overwhelming resources. This module covers DoS vs DDoS attacks, SYN flood, Smurf attack, Ping of Death, Teardrop, buffer overflow attacks, application layer DoS, botnet-based distributed attacks, and mitigation techniques.
The CEHStudy app carries 17 flashcards for Module 10 across 2 sections — learn the three attack classes (volumetric, protocol, application layer) first; every example card maps to exactly one of them.
Key Topics Covered
DoS vs DDoS: single-source vs distributed attacks
SYN flood attack: overwhelming TCP connection tables with half-open connections
Smurf attack: ICMP amplification using broadcast addresses
Ping of Death: oversized or fragmented ICMP packets crashing systems
Teardrop attack: overlapping IP fragments causing system crash
Buffer overflow attacks on network services
Application layer DoS (Layer 7): HTTP flood, Slowloris, RUDY
Distributed Denial-of-Service (DDoS) via botnets
DoS mitigation and prevention strategies
Important Terms & Concepts
DoS (Denial-of-Service): An attack from a single source that overwhelms a target's resources, making it unavailable to legitimate users.
DDoS (Distributed Denial-of-Service): A DoS attack launched from multiple sources (typically a botnet), making it harder to mitigate through simple IP blocking.
SYN Flood: Attacker sends rapid TCP SYN requests but never completes the handshake. Target's connection table fills with half-open connections, exhausting resources.
Smurf Attack: ICMP-based amplification attack. Attacker sends ping (ICMP echo) to a broadcast address with spoofed source IP (victim). All hosts on the network reply to the victim simultaneously.
Ping of Death: Sends malformed or oversized ICMP packets (>65,535 bytes) that overflow buffers when reassembled, causing system crashes.
Teardrop: Sends IP fragments with overlapping offset values. When the target tries to reassemble them, the system crashes due to the malformed fragment data.
Botnet: A network of infected computers (zombies) controlled by a command-and-control (C2) server. Used to launch massive DDoS attacks from thousands of sources simultaneously.
How to Study This Module
Understand the difference between DoS and DDoS attacks
Memorize each attack type and its specific mechanism (SYN flood, Smurf, Ping of Death, Teardrop)
Know mitigation techniques: SYN cookies, rate limiting, traffic filtering, blackholing
Understand how botnets enable distributed attacks at massive scale
Frequently Asked Questions
What is the difference between DoS and DDoS? DoS comes from one source. DDoS comes from many sources simultaneously (a botnet), making it much harder to mitigate since you can't simply block one IP address.
What is a SYN flood attack? The attacker sends thousands of TCP SYN packets but never responds with the final ACK. The target's TCP connection table fills up with half-open connections, preventing new legitimate connections.
What are Denial-of-Service Attacks in Ethical Hacking?
Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks are a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. They target availability — one pillar of the CIA triad (Confidentiality, Integrity, Availability) — from simple volumetric floods to amplification attacks that can bring down internet infrastructure. The exam classifies attacks by OSI layer: volumetric at L3/L4, protocol exploitation, application-layer at L7 — and by the mechanism each uses to exhaust target resources. Module 10 accounts for approximately 10% of CEH v13 exam questions.
Key Concepts in Denial-of-Service Attacks
Volumetric vs Protocol vs Application DoS: The exam categorizes DoS by how it exhausts resources: volumetric (SYN flood, UDP flood, ICMP flood) consumes bandwidth and connection-table space at L3/L4; protocol attacks (Teardrop, Ping of Death) exploit stack implementation flaws to cause crashes; application-layer (Slowloris, HTTP flood, R.U.D.Y.) consumes L7 resources (threads, connections, CPU). Identify the type from the description: 'half-open connections' = SYN flood, 'broadcast address with spoofed source' = Smurf/amplification, 'open but incomplete HTTP requests' = Slowloris.
Amplification & Reflection Attacks: the most effective modern DDoS technique. The attacker sends small requests to open servers (DNS, NTP, Memcached, SSDP) with a spoofed source IP (the victim); each response lands on the victim much larger than the request. Amplification factors: DNS ~54x, NTP monlist ~556x, Memcached ~51,000x, SSDP ~30x. Amplification requires (a) an open/accessible service on internet-facing servers, (b) source IP spoofing, (c) a protocol whose response is disproportionately larger than its request. The 2016 Dyn attack and 2017 Mirai botnet are real-world examples the exam may reference.
Layer 7 DoS (Slowloris & HTTP Flood): Slowloris opens many TCP connections but sends only partial HTTP headers, keeping each open and consuming worker threads without completing requests — the server exhausts its thread pool while every connection looks legitimate. HTTP flood sends valid but resource-intensive GET/POST requests at high rates, consuming CPU/memory rather than bandwidth. R.U.D.Y. (R-U-Dead-Yet) is a Slowloris variant that slowly trickles POST body data to keep connections alive. Distinguish: SYN flood = L4 TCP handshake exhaustion; Slowloris = L7 thread-pool exhaustion with incomplete requests; HTTP flood = L7 resource exhaustion with complete but numerous requests.
DDoS Mitigation Strategy: layered defense: (1) BCP38/BCP84 — source address validation at the network edge to prevent spoofing (prerequisite for amplification defense); (2) SYN cookies — allow connections without reserving table space until the handshake completes; (3) rate limiting — cap requests per IP on specific endpoints; (4) AnyCast routing — distribute traffic across global PoPs so no single point is overwhelmed; (5) DDoS scrubbing (CDN services like Cloudflare, Akamai) — filter attack traffic before it reaches origin; (6) blackholing/null routing — drop all traffic to the attacked IP as last resort. No single technique mitigates all DDoS types — defense must be layered by attack vector.
Common Exam Mistakes in Module 10
Misclassifying the attack type: the exam sorts attacks into three classes and tests the mapping. SYN floods and Smurf are protocol (state-exhaustion) attacks — they burn connection state, not bandwidth; volumetric = raw bandwidth floods (UDP/ICMP floods, amplification); Slowloris is application-layer, exhausting HTTP connection slots with partial requests and almost no traffic.
Mixing Smurf with Fraggle: same amplification mechanics — broadcast request with the victim's spoofed source IP, every host replies to the victim — but different protocols: Smurf = ICMP echo requests, Fraggle = the UDP echo variant. The protocol in the stem is the deciding detail.
Blocking one IP to stop a "DDoS": filtering a single source stops a DoS, because a DoS comes from one system. A DDoS arrives from many compromised hosts (a botnet), so the defenses that matter are rate limiting and throttling, anycast distribution, CDN and scrubbing services, blackhole routing (RFC 3896) — controls that absorb distributed volume rather than drop a source.
Tools Used in DoS/DDoS Attacks
Flood tooling and mitigation services the CEH exam references for this domain, by job:
LOIC / HOIC: Low and High Orbit Ion Cannon — basic traffic-flood stressers; LOIC runs simple TCP/UDP/HTTP floods, HOIC adds protocol presets
hping3: low-level packet generator for SYN floods (-S --flood), UDP floods, ping-of-death and teardrop-style malformed packets
Slowloris: Python application-layer tool that holds many HTTP connections open with partial requests until the web server's connection slots run out — tiny bandwidth, big impact
MFlood / GoldenEye: memory-efficient DDoS flooding and lightweight DoS tools in the same stresser family
Mirai: the leaked IoT botnet source code — the exam's standing example of UDP amplification at scale from compromised cameras, routers and other embedded devices
Cisco F5 Big-IP: hardware DDoS mitigation appliance, the on-prem answer to "which product absorbs the flood?"
Cloudflare / Akamai Prolexic / AWS Shield: commercial CDN-based protection and scrubbing; with anycast networking, attack volume is spread across geographically dispersed data centers sharing one address
Worked Example: Reading an Outage and Naming the Attack Class
An e-commerce site slows during a sale. The edge log shows the connection table filling with half-open TCP sessions — SYNs arrive in volume but final ACKs never come, so each request parks a slot until timeout. That signature is a SYN flood (protocol class); the textbook mitigations are SYN cookies plus rate limiting at the edge, not more bandwidth.
The twist: hours later bandwidth looks "fine" but the site still times out, with hundreds of open HTTP connections stuck mid-request — the Slowloris signature. It is application-layer and survives volumetric defenses because it consumes connection state, not links. The exam answer shifts from "buy scrubbing capacity" to "enforce request timeouts and L7 connection limits"; the two outages show why DoS defense must cover all three classes.
How to Study DoS Attacks for the CEH v13 Exam
To study Module 10:
Create a comparison table of all DoS attack types: Attack Name | OSI Layer | Mechanism (what it exhausts) | Key Indicator in description — the exam's identification questions turn on mechanism and exhausted resource
Memorize amplification factors: DNS (~54x), NTP (~556x), Memcached (~51,000x), SSDP (~30x) — expect highest-multiplier and most-dangerous-service questions
Hands-on: in a VirtualBox lab with a web server VM, SYN flood with hping3 (watch the connection table fill via `ss -tan` on the target), then run Slowloris to show thread-pool exhaustion. Document which metrics change per attack type — they map directly to detection-indicator questions
What is the difference between a SYN flood and an HTTP flood on the CEH exam?
SYN flood operates at Layer 4 (Transport): the attacker sends TCP SYNs but never completes the three-way handshake with an ACK. The kernel keeps half-open entries in a limited table; once full, new legitimate connections are refused. Mitigation: SYN cookies (a stateless identifier instead of reserved table space). HTTP flood operates at Layer 7 (Application): complete, valid GET or POST requests at high volume, each fully processed by the web application — consuming CPU for business logic, database queries, template rendering. The connections are established and legitimate-looking. Mitigation: rate limiting per IP/endpoint, CDN-based challenges, request fingerprinting to identify bots. Key distinction: SYN flood = kernel-level connection-table exhaustion; HTTP flood = process-level application resource exhaustion.
Why are IoT devices so effective in DDoS attacks?
IoT devices (webcams, IP cameras, smart TVs, routers) make ideal DDoS zombies: (1) Linux with default/weak credentials never changed, (2) always-on network connectivity, (3) limited processing power that runs no security software, (4) exposed UPnP/SSDP services enabling amplification, (5) firmware that rarely receives patches. Mirai (2016) compromised ~600,000 IoT devices in its first 20 hours and launched a 1 Tbps DDoS against Dyn DNS, taking down Twitter, Netflix, GitHub and other major services. The attack surface grows with every connected device; the primary defense is network-level filtering (blocking unauthorized outbound UDP) — these devices have no endpoint security.
Related CEH v13 Modules
Module 7: Malware Threats — the malware propagation and C2 architecture that creates the botnet zombie networks powering DDoS
Module 12: Evading IDS, Firewalls & Honeypots — advanced DoS traffic is shaped (fragmentation, rate normalization, protocol manipulation) to stay under signature- and rate-based detection