ALL PASS, NO FAIL!

CEH v13 Module 10: Denial-of-Service

Denial-of-Service (DoS) attacks aim to make a system or network unavailable to legitimate users by overwhelming resources. This module covers DoS vs DDoS attacks, SYN flood, Smurf attack, Ping of Death, Teardrop, buffer overflow attacks, application layer DoS, botnet-based distributed attacks, and mitigation techniques.

The CEHStudy app carries 17 flashcards for Module 10 across 2 sections — learn the three attack classes (volumetric, protocol, application layer) first; every example card maps to exactly one of them.

Key Topics Covered

Important Terms & Concepts

DoS (Denial-of-Service): An attack from a single source that overwhelms a target's resources, making it unavailable to legitimate users.
DDoS (Distributed Denial-of-Service): A DoS attack launched from multiple sources (typically a botnet), making it harder to mitigate through simple IP blocking.
SYN Flood: Attacker sends rapid TCP SYN requests but never completes the handshake. Target's connection table fills with half-open connections, exhausting resources.
Smurf Attack: ICMP-based amplification attack. Attacker sends ping (ICMP echo) to a broadcast address with spoofed source IP (victim). All hosts on the network reply to the victim simultaneously.
Ping of Death: Sends malformed or oversized ICMP packets (>65,535 bytes) that overflow buffers when reassembled, causing system crashes.
Teardrop: Sends IP fragments with overlapping offset values. When the target tries to reassemble them, the system crashes due to the malformed fragment data.
Botnet: A network of infected computers (zombies) controlled by a command-and-control (C2) server. Used to launch massive DDoS attacks from thousands of sources simultaneously.

How to Study This Module

Frequently Asked Questions

What is the difference between DoS and DDoS?
DoS comes from one source. DDoS comes from many sources simultaneously (a botnet), making it much harder to mitigate since you can't simply block one IP address.

What is a SYN flood attack?
The attacker sends thousands of TCP SYN packets but never responds with the final ACK. The target's TCP connection table fills up with half-open connections, preventing new legitimate connections.

Related Modules

What are Denial-of-Service Attacks in Ethical Hacking?

Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks are a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. They target availability — one pillar of the CIA triad (Confidentiality, Integrity, Availability) — from simple volumetric floods to amplification attacks that can bring down internet infrastructure. The exam classifies attacks by OSI layer: volumetric at L3/L4, protocol exploitation, application-layer at L7 — and by the mechanism each uses to exhaust target resources. Module 10 accounts for approximately 10% of CEH v13 exam questions.

Key Concepts in Denial-of-Service Attacks

Common Exam Mistakes in Module 10

Misclassifying the attack type: the exam sorts attacks into three classes and tests the mapping. SYN floods and Smurf are protocol (state-exhaustion) attacks — they burn connection state, not bandwidth; volumetric = raw bandwidth floods (UDP/ICMP floods, amplification); Slowloris is application-layer, exhausting HTTP connection slots with partial requests and almost no traffic.
Mixing Smurf with Fraggle: same amplification mechanics — broadcast request with the victim's spoofed source IP, every host replies to the victim — but different protocols: Smurf = ICMP echo requests, Fraggle = the UDP echo variant. The protocol in the stem is the deciding detail.
Blocking one IP to stop a "DDoS": filtering a single source stops a DoS, because a DoS comes from one system. A DDoS arrives from many compromised hosts (a botnet), so the defenses that matter are rate limiting and throttling, anycast distribution, CDN and scrubbing services, blackhole routing (RFC 3896) — controls that absorb distributed volume rather than drop a source.

Tools Used in DoS/DDoS Attacks

Flood tooling and mitigation services the CEH exam references for this domain, by job:

Worked Example: Reading an Outage and Naming the Attack Class

An e-commerce site slows during a sale. The edge log shows the connection table filling with half-open TCP sessions — SYNs arrive in volume but final ACKs never come, so each request parks a slot until timeout. That signature is a SYN flood (protocol class); the textbook mitigations are SYN cookies plus rate limiting at the edge, not more bandwidth.

The twist: hours later bandwidth looks "fine" but the site still times out, with hundreds of open HTTP connections stuck mid-request — the Slowloris signature. It is application-layer and survives volumetric defenses because it consumes connection state, not links. The exam answer shifts from "buy scrubbing capacity" to "enforce request timeouts and L7 connection limits"; the two outages show why DoS defense must cover all three classes.

How to Study DoS Attacks for the CEH v13 Exam

To study Module 10:

  1. Create a comparison table of all DoS attack types: Attack Name | OSI Layer | Mechanism (what it exhausts) | Key Indicator in description — the exam's identification questions turn on mechanism and exhausted resource
  2. Memorize amplification factors: DNS (~54x), NTP (~556x), Memcached (~51,000x), SSDP (~30x) — expect highest-multiplier and most-dangerous-service questions
  3. Hands-on: in a VirtualBox lab with a web server VM, SYN flood with hping3 (watch the connection table fill via `ss -tan` on the target), then run Slowloris to show thread-pool exhaustion. Document which metrics change per attack type — they map directly to detection-indicator questions
  4. Review related modules: Module 7 (Malware Threats) for the botnet C2 architecture behind DDoS, and Module 12 (Evading IDS) for shaping DoS traffic under rate-based detection

Frequently Asked Questions About DoS Attacks

What is the difference between a SYN flood and an HTTP flood on the CEH exam?

SYN flood operates at Layer 4 (Transport): the attacker sends TCP SYNs but never completes the three-way handshake with an ACK. The kernel keeps half-open entries in a limited table; once full, new legitimate connections are refused. Mitigation: SYN cookies (a stateless identifier instead of reserved table space). HTTP flood operates at Layer 7 (Application): complete, valid GET or POST requests at high volume, each fully processed by the web application — consuming CPU for business logic, database queries, template rendering. The connections are established and legitimate-looking. Mitigation: rate limiting per IP/endpoint, CDN-based challenges, request fingerprinting to identify bots. Key distinction: SYN flood = kernel-level connection-table exhaustion; HTTP flood = process-level application resource exhaustion.

Why are IoT devices so effective in DDoS attacks?

IoT devices (webcams, IP cameras, smart TVs, routers) make ideal DDoS zombies: (1) Linux with default/weak credentials never changed, (2) always-on network connectivity, (3) limited processing power that runs no security software, (4) exposed UPnP/SSDP services enabling amplification, (5) firmware that rarely receives patches. Mirai (2016) compromised ~600,000 IoT devices in its first 20 hours and launched a 1 Tbps DDoS against Dyn DNS, taking down Twitter, Netflix, GitHub and other major services. The attack surface grows with every connected device; the primary defense is network-level filtering (blocking unauthorized outbound UDP) — these devices have no endpoint security.

Related CEH v13 Modules

Related Glossary Terms