Skip to content
Symmetric Metro Internet: equal download and upload up to 10 Gbps
Erbe Bilişim
Cyber Security

What Is a DDoS Attack? How to Protect Your Corporate Internet Line

Learn what a DDoS attack is and how to protect your corporate internet line with ISP-level scrubbing and a genuinely separate backup route.

  • Erbe Bilişim Uzman Ekibi
  • 6 min read
Cyber Security category cover — a shield icon on a dark navy background

Your monitoring dashboard is green: servers healthy, code untouched, yet customers cannot reach your website while requests time out and orders stall. This is the classic face of a distributed denial-of-service (DDoS) attack: your internet line drowning under traffic you never asked for. This guide explains what a DDoS attack is, how to spot one early, and how to keep your corporate internet line online.

What Is a DDoS Attack and How Does It Work?

The simplest answer: a DDoS attack tries to make a service unavailable to legitimate users by flooding it with fake traffic from thousands of compromised devices at once, rather than a single source.

This army of devices is a botnet, built from infected computers, insecure cameras, and home routers whose owners never know they are involved. An attack from one source is a DoS; from distributed sources, a DDoS. Blocking one IP is trivial, but separating tens of thousands of malicious IPs from real users is a serious engineering problem.

Crucially, a DDoS attack rarely steals data; it targets availability. It does not break your server, it clogs the road to it. That is why defense starts on the line itself, on corporate-grade infrastructure such as our Euronet Symmetric Metro Internet product.

DDoS Attack Types: Volumetric, Protocol, and Application

DDoS is examined across three layers, each targeting a different weak point and defense.

TypeTargetExample methodUnit
VolumetricLine bandwidthUDP flood, DNS amplificationGbps
ProtocolServer/firewall resourcesSYN flood, Ping of DeathPackets/second
ApplicationWeb server logicHTTP flood, slow requestsRequests/second

Volumetric attacks are the most visible: send enough data to overflow your line and legitimate requests wait at the door. Point 10 Gbps at a 100 Mbps line and it is over. Protocol attacks target connection tables instead of bandwidth; a SYN flood opens connections and leaves them half-finished, exhausting server and firewall resources.

Application-layer attacks are the subtlest. Volume is low, so they barely register on graphs, yet each request triggers a heavy operation like a search or payment. Because they look valid, only behavior-analyzing layers catch them, as covered in our next-generation firewall article.

Symptoms and Business Impact

In the first hours, teams often look in the wrong place, checking logs and code when the problem is on the network. A DDoS attack is likely when several of these appear together:

  • Pages failing or slowing sharply while server resources look normal
  • A sudden, unexplained spike in requests to a specific service
  • Abnormal traffic concentrated from one country or similar IP blocks
  • Firewall connection tables filling up and VPN access dropping
  • Line bandwidth pinned at its ceiling for a long time

The business impact runs deep. On an e-commerce site every minute is lost revenue, and a cut banking or public-sector integration damages reputation. Many DDoS attacks are also a smokescreen for the real objective, such as ransomware or data exfiltration, so they are rarely standalone events.

ISP-Level Traffic Scrubbing

You cannot stop a volumetric attack with a device inside your office, because the traffic has already reached your line. Once the flood is at the door, it must be stopped upstream.

That is why serious protection begins at the internet service provider (ISP) level, through traffic scrubbing. When an attack is detected, all traffic bound for your line first passes through the provider's scrubbing center, where malicious packets are removed and only legitimate traffic is delivered:

  1. Detection: the traffic profile is monitored continuously, and a sudden deviation raises an alarm.
  2. Redirection: attack traffic is diverted to the scrubbing center.
  3. Filtering: malicious packets are removed through pattern analysis.
  4. Delivery: clean traffic returns to your line without interruption.

Turkish regulatory context: foreign companies operating in Turkey should note that national cyber incidents are reported and coordinated through USOM, the national response center — a useful contact point during a large-scale attack. See USOM.

SLA and a Genuinely Separate Backup Line

Protection technology matters, but so does securing it in a contract through a service level agreement (SLA) and a backup line. A strong corporate SLA should state in writing:

  • A committed availability rate, for example 99.9%
  • A defined DDoS detection and response-time commitment
  • A maximum resolution time for faults
  • A credit or penalty clause for outages

A backup line is the foundation of business continuity. If the primary line collapses, traffic should fail over automatically to a secondary line on a different physical route and technology; two lines on the same infrastructure leave redundancy on paper only.

In one customer environment, ERBE SIEM on-premises monitoring recorded 262 attack attempts, 104 distinct IPs, and 16 attempts per second over 24 hours, with 0 cloud transfer — decisive for both speed and privacy. Our Network Solutions service plans backup lines and routing, and our Firewall Installation service adds an on-site layer that complements ISP-level scrubbing.

DDoS Protection on Metro Ethernet

For corporate access, Metro Ethernet delivers a dedicated, symmetric connection with equal download and upload speeds. During an attack your servers still respond, ship logs, and run backups, yet on asymmetric lines the smaller upload channel cannot carry this legitimate outbound traffic; symmetric infrastructure removes the bottleneck. We cover the difference in our symmetric internet guide.

In the DDoS context, Metro Ethernet offers concrete advantages:

  • Dedicated bandwidth: you do not share the line, so performance holds under sudden load.
  • Provider-level filtering: scrubbing can engage where the line meets the backbone.
  • Predictable SLA: commitments rest on measurable targets, not best effort.
  • Symmetric capacity: legitimate outbound traffic is not choked, so monitoring and response continue.

The most resilient customers share one profile: a dedicated symmetric line, a defined backup route, and a written SLA — with availability treated as a core security objective, as NIST publications stress.

Conclusion

A DDoS attack targets availability, not data, so defense is shaped by the quality of your internet line and provider-level scrubbing. Recognizing attack types early, negotiating a strong SLA, and building a truly separate backup line turn a crisis into a manageable event. To move your corporate internet line onto dedicated, symmetric, and predictable infrastructure, review our Euronet Symmetric Metro Internet product.

Frequently Asked Questions

Can a small business really be hit by a DDoS attack?

Yes, and the risk is higher than most assume. Attackers often do not pick targets; automated tools strike every weak address they find. Rented DDoS services are cheap, so small companies become targets through competitor grudges or extortion. Dedicated lines and provider-level protection are the most effective measures, regardless of company size.

What should I do first during a DDoS attack?

First, diagnose correctly: if access is down while server resources look normal, you are probably on the network layer. Contact your internet service provider immediately and request traffic scrubbing. Trim unnecessary services on the server and preserve your logs. Restarting the server in a panic is rarely the fix; the real response happens upstream, on the provider side.

Can a firewall stop a DDoS attack on its own?

No, a firewall alone is not enough. It can filter some application- and protocol-layer attacks, but in a volumetric attack the line is already full before the device even sees the traffic. Effective protection is layered: provider-level scrubbing, a dedicated symmetric line, a backup route, and an on-site firewall must work together.

Tags

  • ddos attack
  • metro ethernet
  • business continuity