Skip to content

Attacks

Attack classes

An attack class is worth writing about only through three questions: what resource it exhausts, what makes it visible before a customer calls, and which tier of the defence can answer it. A campaign that saturates a transit circuit and a campaign that exhausts a session table look identical on a bandwidth graph and demand opposite responses, and most bad architecture decisions start with that confusion.

The pages below read each class structurally rather than dramatically. Where an attack has a name in the trade press, the name is used, but the argument is about counters — distinct-destination cardinality, request concurrency, state-table pressure — because those are what a rulebook can act on and what an acceptance test can reproduce.

None of these pages tells you how to run an attack. Validation guidance is written for the defender, and the safe way to test a defence is against your own infrastructure with authorisation in writing.

Start here

Go deeper