# BlackNeuron > Patent-Pending Adaptive DDoS Testing and Cloud Resilience Engineering. We test whether > DDoS defences actually hold under a live, adapting attack, rather than whether they are > configured. Independent of any mitigation vendor. What distinguishes our material: a static or scripted test replays a fixed script, while a real attacker changes vector, rate and source distribution in response to your defences. Our writing is organised around what a test can actually measure and what it cannot, and we state the limits of every method we describe. Authorization note: everything we publish is defensive. Our open-source tools are read-only self-audits that send no attack traffic, and we do not publish attack tooling. ## Start here - [The Complete Guide to DDoS Testing](https://blackneuron.ai/blog/complete-guide-to-ddos-testing): The pillar. Methodology, scope, measurement, and how a structured test is designed. - [How We Work](https://blackneuron.ai/how-we-work): Our testing methodology and the deliverables a client receives. - [DDoS Readiness](https://blackneuron.ai/ddos-readiness): CISO-level view of readiness and what evidence a board needs. - [DDoS Testing](https://blackneuron.ai/ddos-testing): The service: adaptive, multi-vector testing against your live defences. - [Cloud Resilience Engineering](https://blackneuron.ai/cloud-hardening): Architecture review and hardening across AWS, Azure, GCP and on-premise. ## Free open-source tools (read-only self-audits, MIT) - [Free DDoS Resilience Tools](https://blackneuron.ai/tools): All four tools, what each answers, and what they deliberately do not claim. - [ddos-protection-path-check](https://github.com/BlackNeuron-ai/ddos-protection-path-check): Is your protection in the path? Checks whether every public hostname on your domain actually routes through your CDN, WAF, or scrubbing edge, or whether one of them resolves around it. - [origin-exposure-check](https://github.com/BlackNeuron-ai/origin-exposure-check): Is your origin reachable past the CDN? Looks for origin IPs that still serve your site directly, bypassing the edge you put in front of it. - [edge-cache-check](https://github.com/BlackNeuron-ai/edge-cache-check): Does your edge actually absorb the flood? Measures how much of your site the CDN really serves from cache, and how much it forwards to your origin. - [dns-resilience-check](https://github.com/BlackNeuron-ai/dns-resilience-check): Is your DNS a single point of failure? Audits nameserver count, provider and network diversity, DNSSEC, and TTL sanity. ## Blog (46 posts) - [DDoS Testing in the UK: What Regulators, Providers and Buyers Expect](https://blackneuron.ai/blog/ddos-testing-uk): DDoS testing in the UK is measured in time: how FCA and PRA impact tolerances, CBEST, DORA and NCSC guidance shape what a UK firm must be able to show. - [Cloud DDoS Testing: When the Infrastructure Is Not Yours](https://blackneuron.ai/blog/cloud-ddos-testing): Cloud DDoS testing changes when the infrastructure is not yours: the pipe, the mitigation, and the evidence belong to the provider. What a test accounts for. - [AWS WAF Rate-Based Rule Testing: Count Mode, Thresholds, and the Traffic That Slips Under](https://blackneuron.ai/blog/aws-waf-rate-based-rule-testing): AWS WAF rate-based rule testing: the aggregation key, count mode, and trailing window decide what slips under. Measure enforcement at the origin. - [AWS Shield Advanced Testing: When It Engages, and What It Lets Through](https://blackneuron.ai/blog/aws-shield-advanced-testing): AWS Shield Advanced testing: enrollment is not protection. Measure when automatic mitigation engages, what reaches origin, and whether the SRT loop fires. - [Akamai DDoS Testing: Prolexic, the Diversion Window, and What to Validate](https://blackneuron.ai/blog/akamai-ddos-testing): Akamai DDoS testing: Prolexic and App and API Protector mitigate by routing. Validate the diversion window, the Site Shield origin lock, and the response loop. - [Fastly DDoS Testing: The Cache-Miss Problem, the Programmable Edge, and What to Validate](https://blackneuron.ai/blog/fastly-ddos-testing): Fastly DDoS testing: the edge is a programmable cache, so the attack is a cache miss. Measure what the cache absorbs and what reaches origin when it cannot. - [Bare-Metal DDoS Testing: The Packet-Rate Ceiling, the Missing Cushion, and What to Validate](https://blackneuron.ai/blog/bare-metal-ddos-testing): Bare-metal DDoS testing: a dedicated server fails on packet rate, not bandwidth, with no autoscaler behind it. Find the hard ceiling before an attacker does. - [Hetzner DDoS Testing: The Free Automatic Protection, the Missing Dials, and What to Validate](https://blackneuron.ai/blog/hetzner-ddos-testing): Hetzner DDoS testing: the free automatic protection has no settings to tune, so you measure the black box instead of auditing it. What to validate. - [OVHcloud DDoS Testing: The Free Anti-DDoS, the Detection Window, and What to Validate](https://blackneuron.ai/blog/ovhcloud-ddos-testing): OVHcloud DDoS testing: the free always-on anti-DDoS is a scrubbing system with a detection window, not an inline wall. What to measure and what it misses. - [DDoS Testing Starts Here: Is Your Protection Actually in the Path?](https://blackneuron.ai/blog/ddos-protection-in-the-path): DDoS testing begins with one question: does your protection actually receive your traffic? Why the apex hostname drifts out of the path, how to check it from outside, and what a path check cannot tell you. - [Alibaba Cloud DDoS Testing: Anti-DDoS Basic, the Blackhole Threshold, and What to Validate](https://blackneuron.ai/blog/alibaba-cloud-ddos-testing): Alibaba Cloud DDoS testing: Anti-DDoS Basic blackholes your IP past a threshold, protecting the platform not you. The blackhole finding and what to validate. - [Linode DDoS Testing: The Akamai Edge, Origin Lockdown, and What to Validate](https://blackneuron.ai/blog/linode-ddos-testing): Linode DDoS testing: a Linode instance inherits a free L3/L4 floor but not Akamai's edge. The brand-halo false green, origin lockdown, and what to validate. - [Vultr DDoS Testing: Opt-In Protection, Origin Lockdown, and What to Validate](https://blackneuron.ai/blog/vultr-ddos-testing): Vultr DDoS testing: its L3/L4 DDoS Protection is an opt-in, per-instance add-on, not a free floor. Origin lockdown, the L7 gap, and what to validate. - [IBM Cloud DDoS Testing: Cloud Internet Services, Origin Lockdown, and What to Validate](https://blackneuron.ai/blog/ibm-cloud-ddos-testing): IBM Cloud DDoS testing: Cloud Internet Services is a Cloudflare-powered edge you provision, plus network mitigation, origin lockdown, and what to validate. - [Oracle Cloud (OCI) DDoS Testing: Methodology, WAF Enforcement, and What to Validate](https://blackneuron.ai/blog/oracle-cloud-ddos-testing): Oracle Cloud (OCI) DDoS testing: always-on L3/L4 mitigation, the two WAF enforcement points, block versus observe, origin exposure, and what to validate. - [The DDoS Test Plan: Scope, Rules of Engagement, Success Criteria, and Abort Gates](https://blackneuron.ai/blog/ddos-test-plan): A DDoS test plan sets scope, rules of engagement, success criteria, and abort gates before any traffic runs. What each section must contain, and why. - [DDoS Testing Tools: What to Look For (and Why Static Scripts Fall Short)](https://blackneuron.ai/blog/ddos-testing-tools): DDoS testing tools compared by what each class can never show you: a taxonomy and a selection rubric that reads structural blind spots, not peak throughput. - [Continuous DDoS Testing: Why One-Off Tests Miss Configuration Drift](https://blackneuron.ai/blog/continuous-ddos-testing): Continuous DDoS testing: why a one-off result decays. How configuration drift re-opens gaps between tests, and why to test on change, not the calendar. - [Testing Azure Front Door and WAF Policies: Detection Mode, Rate Limits, and the Seams Between DDoS Layers](https://blackneuron.ai/blog/azure-front-door-waf-testing): Azure Front Door and WAF testing: why a Detection-mode policy logs every attack and blocks none, and how failures hide in the seams between Azure DDoS layers. - [DDoS Testing Approaches Compared: Static, Multi-Vector, and Adaptive](https://blackneuron.ai/blog/ddos-testing-approaches-compared): DDoS testing approaches compared: static scripts, multi-vector, and adaptive. Why what the test does to your defense matters more than who runs it. - [DDoS Penetration Testing: Where It Fits in a Security Assessment](https://blackneuron.ai/blog/ddos-penetration-testing): DDoS penetration testing sits beside a pentest, not inside it: why the standard scope excludes DoS, where the two overlap, and how each is run. - [How to Test Your DDoS Protection: A Step-by-Step Methodology](https://blackneuron.ai/blog/how-to-test-ddos-protection): How to test your DDoS protection step by step: scope, authorize, baseline, escalate, measure, report. Why the order is the method, not the traffic generator. - [CDN Cache and DDoS: Why the Edge Only Absorbs the Traffic It Caches](https://blackneuron.ai/blog/cdn-cache-ddos-absorption): A CDN only shields your origin from a flood for the traffic it caches. If your responses are not cacheable, the edge forwards the flood straight to your origin. How absorption works, what quietly breaks it, and how to test what your edge actually keeps. - [Testing Google Cloud Armor (GCP) Adaptive Protection: Rules, Rate Limiting, and Preview Mode](https://blackneuron.ai/blog/gcp-cloud-armor-adaptive-protection-testing): GCP Cloud Armor Adaptive Protection is a learning detector, so a static script green-checks a defense it never stressed. Why testing Google Cloud Armor needs an adaptive test. - [Serverless DDoS Testing: Concurrency Limits, Economic Denial, and What to Validate](https://blackneuron.ai/blog/serverless-ddos-testing): Serverless DDoS testing targets the limits elastic compute hides: the concurrency quota, the downstream dependency, and the bill a flood runs up. - [Evaluating a DDoS Testing Methodology: The Questions That Matter](https://blackneuron.ai/blog/evaluating-ddos-testing-methodology): Evaluating a DDoS testing methodology means judging its output, not its claims: the questions that separate a reproducible finding from a capability pitch. - [Hybrid-Cloud DDoS Testing: Testing the Seams Between Cloud and On-Premise](https://blackneuron.ai/blog/hybrid-cloud-ddos-testing): Hybrid-cloud DDoS testing checks the seams between cloud and on-premise: the interconnect, asymmetric protection, and failover a single-leg test misses. - [DNS DDoS Testing: Authoritative and Recursive Resolution Under Attack](https://blackneuron.ai/blog/dns-ddos-testing): DNS DDoS testing checks whether name resolution survives attack, across the authoritative servers you run and the recursive resolvers your users rely on. - [Layer 7 DDoS Testing: Application-Layer (L7) Detection & Methodology](https://blackneuron.ai/blog/l7-ddos-testing): Layer 7 (L7) DDoS testing checks whether your application stack can tell adversarial HTTP traffic from legitimate — and what deciding costs in false positives. - [DDoS Readiness Assessment: Scope, Methodology, and Deliverables](https://blackneuron.ai/blog/ddos-readiness-assessment): A DDoS readiness assessment measures whether controls and response close in time, not just what is deployed: its scope, methodology, and deliverables. - [Measuring DDoS Resilience: A Scoring Framework for Defensive Posture](https://blackneuron.ai/blog/ddos-resilience-score): A DDoS resilience score should measure how a system behaves under attack, not the controls it owns: an outcome-based scoring rubric for defensive posture. - [Multi-Vector DDoS Testing: Simultaneous Versus Sequential Methodologies](https://blackneuron.ai/blog/multi-vector-ddos-testing): Multi-vector DDoS testing runs L3, L4, and L7 vectors at once. Here is what simultaneous delivery surfaces that sequential, one-at-a-time testing cannot. - [DigitalOcean DDoS Testing: Methodology and What to Validate](https://blackneuron.ai/blog/digitalocean-ddos-testing): DigitalOcean DDoS testing validates the real stack: L3/L4 mitigation, Cloud Firewall and Load Balancer limits, and the L7 layer the platform leaves to you. - [Kubernetes DDoS Testing: Ingress, Autoscaling, and What to Validate](https://blackneuron.ai/blog/kubernetes-ddos-testing): Kubernetes DDoS testing validates the cluster under load: ingress limits, autoscaler timing and tip-over, node conntrack ceilings, and direct-to-pod exposure. - [Cloudflare DDoS Testing: Validating WAF, Rate Limiting, and Origin Protection](https://blackneuron.ai/blog/cloudflare-ddos-testing): Cloudflare DDoS testing validates your zone under attack: proxy status, WAF and bot rule actions, rate limits, and whether the origin is reachable directly. - [On-Premise DDoS Testing: Scrubbing, BGP, and What to Validate](https://blackneuron.ai/blog/on-premise-ddos-testing): On-premise DDoS testing validates the chain you assemble yourself: transit headroom, the on-demand scrubbing diversion window, and stateful perimeter limits. - [GCP DDoS Testing: Cloud Armor, Load Balancing, and What to Validate](https://blackneuron.ai/blog/gcp-ddos-testing): GCP DDoS testing validates the real stack under attack: Cloud Armor enforcement, Adaptive Protection mitigation, origin exposure, and the scale-out window. - [Azure DDoS Testing: Methodology, Protection Tiers, and What to Validate](https://blackneuron.ai/blog/azure-ddos-testing): Azure DDoS testing validates the real stack under attack: protection-plan coverage, WAF Prevention mode, Front Door origin exposure, and the scale-set window. - [Origin IP Exposure: How Attackers Bypass CDN DDoS Protection (and How to Test for It)](https://blackneuron.ai/blog/origin-ip-exposure-cdn-bypass): A CDN only filters traffic that passes through it. If the origin server is still reachable on its real IP, attackers bypass it in one step. How the address leaks, how to test for it, and how to close it. - [AWS DDoS Testing: Methodology, Shield Interaction, and What to Validate](https://blackneuron.ai/blog/aws-ddos-testing): AWS DDoS testing validates the real stack under attack: Shield enrollment, WAF rule actions, CloudFront origin exposure, and the autoscaler window. - [Running a DDoS Test Without Disrupting Production: Scoping, Safeguards, and Blast-Radius Control](https://blackneuron.ai/blog/ddos-testing-without-disrupting-production): Safe DDoS testing without production downtime: scoping, traffic caps, kill switches, blast-radius control, and cloud-provider authorization. - [The Complete Guide to DDoS Testing: Methodology, Attack Classes, Metrics, and Evaluation](https://blackneuron.ai/blog/complete-guide-to-ddos-testing): DDoS testing, end to end: definitions, static vs adaptive methodology, attack classes by layer, metrics, environments, and reporting. - [Adaptive DDoS Testing: An Engineering Definition and Why Static Testing Falls Short](https://blackneuron.ai/blog/adaptive-ddos-testing-engineering-definition): Adaptive DDoS testing vs static simulation: simultaneous multi-vector delivery, real-time adaptation, and configuration findings each methodology surfaces. - [Understanding DDoS Attack Vectors: A Technical Deep Dive](https://blackneuron.ai/blog/understanding-ddos-attack-vectors): DDoS attack vectors across L3, L4, and L7: amplification mechanics, protocol abuse, application-logic exploitation, and mitigation by layer. - [AWS Shield Advanced vs Cloudflare DDoS Protection: Architecture, Coverage, and Configuration](https://blackneuron.ai/blog/aws-shield-vs-cloudflare-ddos-comparison): AWS Shield Advanced vs Cloudflare DDoS Protection: coverage, detection-to-mitigation timing, origin IP exposure, and the configuration disciplines. - [DDoS Resilience Testing: How It Differs from Load Testing and Why It Matters](https://blackneuron.ai/blog/ddos-resilience-testing): DDoS resilience testing and load testing measure fundamentally different things. Mechanics, measurements, and why the distinction matters under adversarial conditions. ## DDoS definitions (131 terms) - [Scrubbing Center](https://blackneuron.ai/definitions/scrubbing-center): A scrubbing center is upstream infrastructure that filters DDoS traffic out of the flow before it reaches the origin, forwarding only clean traffic onward. - [SYN Flood](https://blackneuron.ai/definitions/syn-flood): A SYN flood is an L4 attack that sends TCP SYN packets without completing the handshake, exhausting the SYN backlog so legitimate connections fail. - [Rate Limiting](https://blackneuron.ai/definitions/rate-limiting): Rate limiting caps how many requests a source can make per time window, a primary L7 control whose thresholds DDoS testing validates under load. - [RTBH (Remotely Triggered Black Hole)](https://blackneuron.ai/definitions/rtbh): RTBH (remotely triggered black hole) uses BGP to null-route all traffic to a targeted IP at the edge, dropping that destination to protect the network. - [UDP Reflection / Amplification](https://blackneuron.ai/definitions/udp-reflection-amplification): A UDP reflection/amplification attack spoofs the victim IP to misconfigured servers that reply with far larger responses, multiplying attack bandwidth. - [Slowloris](https://blackneuron.ai/definitions/slowloris): Slowloris is an L7 slow attack that holds many connections open with partial HTTP requests sent slowly, exhausting the connection pool at low bandwidth. - [Anycast](https://blackneuron.ai/definitions/anycast): Anycast announces one IP from many locations so traffic routes to the nearest node, letting DDoS mitigation spread attack load across the edge network. - [SYN Cookies](https://blackneuron.ai/definitions/syn-cookies): SYN cookies are a kernel defense against SYN floods that encode connection state into the SYN-ACK sequence number instead of allocating SYN backlog state. - [JA3 / JA4 Fingerprinting](https://blackneuron.ai/definitions/ja3-ja4-fingerprinting): JA3 and JA4 are TLS fingerprinting methods that hash ClientHello features into a string identifying client software, used to detect and filter bot traffic. - [ACK Flood](https://blackneuron.ai/definitions/ack-flood): An ACK flood is an L4 attack that sends TCP ACK packets matching no open connection, forcing stateful firewalls and conntrack tables to waste lookups. - [RST Flood](https://blackneuron.ai/definitions/rst-flood): An RST flood is an L4 attack that sends spoofed TCP RST packets, forcing the target and inline stateful devices to burn CPU on connection-table lookups. - [HTTP Flood](https://blackneuron.ai/definitions/http-flood): An HTTP flood is an L7 attack that sends high volumes of valid-looking GET or POST requests, exhausting CPU, worker threads, and the database tier. - [DNS Amplification](https://blackneuron.ai/definitions/dns-amplification): A DNS amplification attack spoofs the victim IP to open resolvers, which return far larger responses, building a volumetric flood of hundreds of Gbps. - [NTP Amplification](https://blackneuron.ai/definitions/ntp-amplification): An NTP amplification attack abuses the monlist command on open NTP servers to reflect a tiny spoofed query into a response hundreds of times larger. - [Memcached Amplification](https://blackneuron.ai/definitions/memcached-amplification): A memcached amplification attack reflects a small spoofed UDP request off open port 11211 servers into a flood, the highest known amplification factor. - [Volumetric Attack](https://blackneuron.ai/definitions/volumetric-attack): A volumetric attack is a DDoS class that saturates the network link in bits per second, dropping legitimate packets before they reach the origin. - [Application-Layer Attack](https://blackneuron.ai/definitions/application-layer-attack): An application-layer attack is an L7 DDoS class of valid but costly requests that exhaust CPU and backends at low bandwidth, evading volumetric filters. - [Ping of Death](https://blackneuron.ai/definitions/ping-of-death): A ping of death is an L3 attack sending an oversized ICMP packet that overflows the reassembly buffer, crashing or hanging a vulnerable host. - [Smurf Attack](https://blackneuron.ai/definitions/smurf-attack): A smurf attack is an L3 reflection vector that spoofs the victim IP in ICMP echoes to a broadcast address, so every host floods the victim at once. - [CLDAP Amplification](https://blackneuron.ai/definitions/cldap-amplification): A CLDAP amplification attack spoofs the victim IP to exposed LDAP servers on UDP 389, which reply 50x to 70x larger to build a volumetric flood. - [IP Fragmentation Attack](https://blackneuron.ai/definitions/ip-fragmentation-attack): An IP fragmentation attack floods a target with incomplete or overlapping IP fragments, exhausting the kernel reassembly buffer at low packet rates. - [DNS Water Torture](https://blackneuron.ai/definitions/dns-water-torture): A DNS water torture attack floods resolvers with random nonexistent subdomains, forcing every query down to the victim's authoritative DNS servers. - [TCP Connection Flood](https://blackneuron.ai/definitions/tcp-connection-flood): A TCP connection flood opens many full TCP connections and holds them idle, exhausting socket and conntrack tables so new connections fail. - [TLS Renegotiation Attack](https://blackneuron.ai/definitions/tls-renegotiation-attack): A TLS renegotiation attack forces repeated handshakes to exhaust server CPU on asymmetric crypto, saturating compute at very low bandwidth. - [RUDY Attack (R-U-Dead-Yet)](https://blackneuron.ai/definitions/rudy-attack): A RUDY (R-U-Dead-Yet) attack is an L7 slow-POST attack that dribbles a large request body byte by byte, tying up worker threads at low bandwidth. - [Carpet Bombing](https://blackneuron.ai/definitions/carpet-bombing): A carpet bombing attack spreads a volumetric flood across many IPs in a subnet at once, staying under per-IP thresholds to evade detection. - [Pulse Wave Attack](https://blackneuron.ai/definitions/pulse-wave-attack): A pulse wave attack delivers short repeated bursts of high-volume traffic, exploiting the reaction window before scrubbing fully engages. - [Protocol Attack](https://blackneuron.ai/definitions/protocol-attack): A protocol attack is a DDoS class that exhausts stateful tables in firewalls and kernels with packet floods, measured in packets per second. - [WAF (Web Application Firewall)](https://blackneuron.ai/definitions/waf): A WAF (web application firewall) is an L7 control that inspects HTTP requests and blocks malicious patterns, filtering application-layer DDoS floods. - [CDN (Content Delivery Network)](https://blackneuron.ai/definitions/cdn): A CDN (content delivery network) is a distributed edge that caches content and absorbs volumetric DDoS load across many points of presence. - [Bot Management](https://blackneuron.ai/definitions/bot-management): Bot management is an L7 control that classifies clients by fingerprint and behavior, filtering automated DDoS traffic while passing real users. - [Geo-Blocking](https://blackneuron.ai/definitions/geo-blocking): Geo-blocking is a control that drops traffic by source country, shrinking the attack surface when an application serves only certain regions. - [Challenge-Response](https://blackneuron.ai/definitions/challenge-response): A challenge-response control interrupts suspect clients with a test (JS, CAPTCHA, or proof-of-work) that bots fail, filtering automated DDoS traffic. - [BGP Flowspec](https://blackneuron.ai/definitions/bgp-flowspec): BGP Flowspec is a control that distributes packet-filter rules across routers via BGP, dropping DDoS flows by port, protocol, or size at the edge. - [BCP 38 (Ingress Filtering)](https://blackneuron.ai/definitions/bcp-38): BCP 38 is an ingress-filtering standard that drops packets with spoofed source IPs at the edge, preventing reflection and amplification attacks. - [Block vs Count Mode](https://blackneuron.ai/definitions/block-vs-count-mode): Block-vs-count mode is the WAF setting deciding whether a matched rule drops a request or only logs it; a rule left in count mode is absent under attack. - [Mitigation Cutover](https://blackneuron.ai/definitions/mitigation-cutover): Mitigation cutover is the switch from normal routing to scrubbing when an attack is detected; the cutover delay sets how long the origin stays exposed. - [TCP SYN Backlog](https://blackneuron.ai/definitions/tcp-syn-backlog): The TCP SYN backlog is the kernel queue holding half-open connections; a SYN flood fills it so legitimate handshakes fail until it is tuned. - [TCP Accept Queue](https://blackneuron.ai/definitions/accept-queue): The TCP accept queue holds established connections awaiting accept(); a flood that fills it drops completed handshakes even when the SYN backlog is tuned. - [Conntrack Exhaustion](https://blackneuron.ai/definitions/conntrack-exhaustion): Conntrack exhaustion is a failure where a flood fills the kernel connection-tracking table, so stateful firewalls drop new legitimate flows. - [uRPF (Unicast Reverse Path Forwarding)](https://blackneuron.ai/definitions/urpf): uRPF (unicast reverse path forwarding) is an anti-spoofing control that drops packets whose source IP fails a reverse-route check at the network edge. - [Sinkholing](https://blackneuron.ai/definitions/sinkholing): Sinkholing is a control that reroutes attack traffic to a sinkhole for capture and analysis, unlike a black hole, which silently discards it at the edge. - [IP Reputation](https://blackneuron.ai/definitions/ip-reputation): IP reputation is an L7 control that scores source addresses from threat-intel feeds, blocking or challenging traffic from hosts with a history of abuse. - [Clean Pipe](https://blackneuron.ai/definitions/clean-pipe): A clean pipe is a managed DDoS service that routes traffic through a scrubbing provider, returning only filtered clean traffic to the origin link. - [Always-On Mitigation](https://blackneuron.ai/definitions/always-on-mitigation): Always-on mitigation routes all traffic through scrubbing at all times, removing the detection-and-cutover delay that on-demand DDoS protection incurs. - [Tarpit](https://blackneuron.ai/definitions/tarpit): A tarpit is a defensive control that deliberately stalls suspicious connections, holding attacker sockets open to slow floods and exhaustion attacks. - [ACL (Access Control List)](https://blackneuron.ai/definitions/acl): An ACL (access control list) is a network control that permits or denies packets by IP, port, or protocol, dropping bad traffic at the router or firewall. - [Amplification Factor](https://blackneuron.ai/definitions/amplification-factor): An amplification factor is the ratio of a reflected response to the spoofed request that triggered it, measuring how much a vector multiplies bandwidth. - [Time-to-Mitigation (TTM)](https://blackneuron.ai/definitions/time-to-mitigation): Time-to-mitigation is the elapsed time from the first attack packet to full scrubbing engaging; the whole interval is when the origin stays exposed. - [Time-to-Recovery (TTR)](https://blackneuron.ai/definitions/time-to-recovery): Time-to-recovery is the time from scrubbing engaging to the service returning to its normal baseline: error rates, latency, and pools all restored. - [Layer of First Failure](https://blackneuron.ai/definitions/layer-of-first-failure): The layer of first failure is the tier that breaks first as attack load rises (link, conntrack, LB, TLS, app, or database), setting the stack ceiling. - [False-Positive Rate](https://blackneuron.ai/definitions/false-positive-rate): A false-positive rate is the fraction of legitimate traffic a mitigation control wrongly blocks while filtering an attack, the cost of tighter thresholds. - [Autoscaler Exposure](https://blackneuron.ai/definitions/autoscaler-exposure): Autoscaler exposure is the risk that an L7 flood is read as real demand and scaled into, turning an attack into a cloud bill instead of an outage. - [Multi-Vector Attack](https://blackneuron.ai/definitions/multi-vector-attack): A multi-vector attack combines volumetric, protocol, and application-layer floods at once, hitting different tiers so a single-vector defense is bypassed. - [Blast Radius](https://blackneuron.ai/definitions/blast-radius): A blast radius is how far an attack or test spreads beyond its target, through shared dependencies, tenants, or upstream links into other systems. - [DDoS Resilience](https://blackneuron.ai/definitions/ddos-resilience): DDoS resilience is how well a system keeps serving legitimate traffic under attack and how fast it recovers, an emergent property of the whole stack. - [Origin IP Exposure](https://blackneuron.ai/definitions/origin-ip-exposure): Origin IP exposure is the risk that a server's real IP is discoverable, letting attackers flood it directly and bypass the CDN or scrubbing layer. - [Direct-to-Origin (D2O) DDoS Attack](https://blackneuron.ai/definitions/direct-to-origin-ddos-attack): A DDoS technique in which the attacker sends attack traffic straight at a discovered origin IP, bypassing the CDN, WAF, or scrubbing layer so edge mitigation never touches the flood. - [Goodput](https://blackneuron.ai/definitions/goodput): Goodput is the share of throughput that delivers useful legitimate traffic, the number that stays meaningful when an attack inflates raw bandwidth. - [Packets Per Second (PPS)](https://blackneuron.ai/definitions/packets-per-second): Packets per second (PPS) is the rate of packets a device processes, the unit measuring protocol attacks that exhaust hardware regardless of bandwidth. - [Bits Per Second (BPS)](https://blackneuron.ai/definitions/bits-per-second): Bits per second (BPS) is the rate of data crossing a link, the unit that measures volumetric DDoS attacks built to saturate the network pipe. - [Requests Per Second (RPS)](https://blackneuron.ai/definitions/requests-per-second): Requests per second (RPS) is the rate of HTTP requests an application receives, the unit that measures application-layer floods at the L7 tier. - [False-Negative Rate](https://blackneuron.ai/definitions/false-negative-rate): A false-negative rate is the fraction of attack traffic a mitigation control fails to block, the leakage that reaches the origin past the filter. - [Mean Time to Detect (MTTD)](https://blackneuron.ai/definitions/mean-time-to-detect): Mean time to detect (MTTD) is the average time from the first attack packet to detection recognizing it, the front half of total time-to-mitigation. - [Attack Surface](https://blackneuron.ai/definitions/attack-surface): An attack surface is the full set of exposed endpoints, IPs, ports, and services an attacker can reach, the inventory a DDoS test maps before load. - [Baseline Traffic](https://blackneuron.ai/definitions/baseline-traffic): Baseline traffic is a service's normal measured traffic profile, the reference an anomaly-based mitigation compares against to flag a DDoS surge. - [Botnet](https://blackneuron.ai/definitions/botnet): A botnet is a network of malware-infected devices an operator controls remotely to flood a target with coordinated traffic from many sources. - [Mirai](https://blackneuron.ai/definitions/mirai): Mirai is a botnet malware family that infects IoT devices with default credentials, building the fleets behind several record-breaking DDoS attacks. - [IP Spoofing](https://blackneuron.ai/definitions/ip-spoofing): IP spoofing is forging the source address of packets so a flood appears to come from elsewhere, enabling reflection and evading per-IP blocks. - [Command-and-Control (C2)](https://blackneuron.ai/definitions/command-and-control): Command-and-control (C2) is the channel an operator uses to direct a botnet, issuing the target, vector, and timing for a coordinated DDoS attack. - [Reflector](https://blackneuron.ai/definitions/reflector): A reflector is a third-party server tricked by a spoofed request into sending its reply to the victim, the building block of amplification attacks. - [Booter / Stresser](https://blackneuron.ai/definitions/booter-stresser): A booter or stresser is a rented DDoS-for-hire service that sells attack traffic on demand, lowering the skill needed to launch a flood. - [IoT Botnet](https://blackneuron.ai/definitions/iot-botnet): An IoT botnet is a botnet built from compromised cameras, routers, and other devices, valued for their numbers and always-on connections. - [Open Resolver](https://blackneuron.ai/definitions/open-resolver): An open resolver is a misconfigured DNS server that answers any client, abused as a reflector to amplify spoofed queries into a flood. - [Residential Proxy DDoS](https://blackneuron.ai/definitions/residential-proxy-ddos): Residential proxy DDoS routes attack traffic through real home IPs, so requests blend with legitimate users and defeat IP-reputation filtering. - [UDP Flood](https://blackneuron.ai/definitions/udp-flood): A UDP flood is an L4 volumetric attack that sends high rates of datagrams to closed ports, forcing ICMP unreachable replies that saturate CPU and link. - [ICMP Flood (Ping Flood)](https://blackneuron.ai/definitions/icmp-flood): An ICMP flood (ping flood) is an L3 volumetric attack that sends high rates of ICMP packets, saturating link capacity and CPU on the responding host. - [DNS Flood](https://blackneuron.ai/definitions/dns-flood): A DNS flood is an L7 attack that aims high volumes of direct queries at authoritative or recursive servers, exhausting them until name resolution stops. - [SSDP Amplification](https://blackneuron.ai/definitions/ssdp-amplification): An SSDP amplification attack spoofs the victim IP to UPnP devices on UDP 1900, which reply far larger, building a volumetric flood from many reflectors. - [SNMP Amplification](https://blackneuron.ai/definitions/snmp-amplification): An SNMP amplification attack spoofs the victim IP to devices on UDP 161 with default community strings, reflecting GetBulk replies into a flood. - [HTTP/2 Rapid Reset](https://blackneuron.ai/definitions/http2-rapid-reset): HTTP/2 Rapid Reset (CVE-2023-44487) is an L7 attack that opens and instantly cancels streams at scale, driving record request floods over few connections. - [SSL Flood (TLS Handshake Flood)](https://blackneuron.ai/definitions/ssl-flood): An SSL flood is an L7 attack that forces repeated TLS handshakes to exhaust server CPU on asymmetric crypto, stalling the service at low bandwidth. - [CHARGEN Amplification](https://blackneuron.ai/definitions/chargen-amplification): A CHARGEN amplification attack spoofs the victim IP to legacy UDP 19 services, which reply with large character streams, building a volumetric flood. - [LAND Attack](https://blackneuron.ai/definitions/land-attack): A LAND attack sends a TCP SYN with source IP and port equal to the destination, making a vulnerable host reply to itself in a loop until it hangs. - [Teardrop Attack](https://blackneuron.ai/definitions/teardrop-attack): A teardrop attack sends overlapping or malformed IP fragments so a vulnerable reassembly routine miscalculates buffers and crashes the target host. - [Fraggle Attack](https://blackneuron.ai/definitions/fraggle-attack): A Fraggle attack is a UDP reflection vector that spoofs the victim IP in packets to a broadcast address, so every host on it floods the victim at once. - [TCP Middlebox Reflection](https://blackneuron.ai/definitions/tcp-middlebox-reflection): A TCP middlebox reflection attack abuses censorship and firewall middleboxes to reflect amplified TCP traffic at a spoofed victim IP. - [QUIC Flood](https://blackneuron.ai/definitions/quic-flood): A QUIC flood is an L4 attack that floods a server with QUIC handshake packets on UDP 443, forcing costly crypto and connection-state setup. - [GRE Flood](https://blackneuron.ai/definitions/gre-flood): A GRE flood is an L3 volumetric attack that sends high rates of GRE-encapsulated packets (IP protocol 47) to exhaust the target's link and CPU. - [WS-Discovery Amplification](https://blackneuron.ai/definitions/ws-discovery-amplification): A WS-Discovery amplification attack spoofs the victim IP to IoT devices on UDP 3702, which reply far larger, building a high-factor volumetric flood. - [mDNS Amplification](https://blackneuron.ai/definitions/mdns-amplification): An mDNS amplification attack spoofs the victim IP to open multicast DNS responders on UDP 5353, which reflect larger replies into a volumetric flood. - [NetBIOS Amplification](https://blackneuron.ai/definitions/netbios-amplification): A NetBIOS amplification attack spoofs the victim IP to name-service hosts on UDP 137, which reflect larger replies into a volumetric flood. - [Portmap Amplification](https://blackneuron.ai/definitions/portmap-amplification): A portmap amplification attack spoofs the victim IP to rpcbind hosts on UDP 111, which reflect larger replies into a volumetric flood. - [TFTP Amplification](https://blackneuron.ai/definitions/tftp-amplification): A TFTP amplification attack spoofs the victim IP to open TFTP servers on UDP 69, which reflect far larger file replies into a volumetric flood. - [Ransom DDoS (RDDoS)](https://blackneuron.ai/definitions/ransom-ddos): A ransom DDoS (RDDoS) is an extortion attack that floods a target, or threatens to, unless a cryptocurrency payment is made to stop or avert it. - [Deep Packet Inspection (DPI)](https://blackneuron.ai/definitions/deep-packet-inspection): Deep packet inspection (DPI) is a control that examines packet payloads, not just headers, to identify and drop DDoS traffic by its content. - [Reverse Proxy](https://blackneuron.ai/definitions/reverse-proxy): A reverse proxy is a control that fronts origin servers, terminating connections and filtering DDoS traffic before it reaches them. - [Null Routing (Blackholing)](https://blackneuron.ai/definitions/null-route): Null routing (blackholing) is a control that drops all traffic to a targeted IP via a null interface, sacrificing that host to save the rest. - [Availability](https://blackneuron.ai/definitions/availability): Availability is the share of time a service responds correctly to legitimate users, the metric a DDoS attack is built to drive down. - [Throughput](https://blackneuron.ai/definitions/throughput): Throughput is the volume of traffic a system processes per unit time, the capacity a volumetric DDoS attack tries to push past its ceiling. - [LOIC (Low Orbit Ion Cannon)](https://blackneuron.ai/definitions/loic): LOIC (Low Orbit Ion Cannon) is an open-source tool that floods a target with TCP, UDP, or HTTP requests, used in volunteer DDoS campaigns. - [Low and Slow Attack](https://blackneuron.ai/definitions/low-and-slow-attack): A low and slow attack sends request data at a crawling pace to pin server workers, exhausting the connection pool at almost no bandwidth. - [FIN Flood](https://blackneuron.ai/definitions/fin-flood): A FIN flood sends out-of-state TCP FIN segments to force costly connection-table lookups, exhausting a stateful firewall or load balancer. - [Yo-Yo Attack](https://blackneuron.ai/definitions/yo-yo-attack): A yo-yo attack bursts load to trigger autoscaling then stops, driving capacity up and down so the target pays for scale it never uses. - [SYN-ACK Flood](https://blackneuron.ai/definitions/syn-ack-flood): A SYN-ACK flood sends unsolicited TCP SYN-ACK packets, forcing stateful firewalls to burn CPU matching each to no open connection. - [Cache-Busting Attack](https://blackneuron.ai/definitions/cache-busting-attack): A cache-busting attack adds a unique query string to every L7 request, forcing CDN cache misses so all traffic falls through to the origin. - [Slow Read Attack](https://blackneuron.ai/definitions/slow-read-attack): A slow read attack advertises a tiny TCP receive window so the server cannot drain its response, pinning workers open at near-zero bandwidth. - [PSH-ACK Flood](https://blackneuron.ai/definitions/psh-ack-flood): A PSH-ACK flood is an L4 attack sending TCP packets with the PSH and ACK flags set, forcing stateful devices to burn CPU matching each to no open session. - [Christmas Tree Attack](https://blackneuron.ai/definitions/christmas-tree-attack): A Christmas tree attack floods a target with TCP packets with FIN, PSH, and URG flags all set, costing several times the CPU of a normal packet to process. - [BlackNurse](https://blackneuron.ai/definitions/blacknurse-attack): A BlackNurse attack is a low-bandwidth flood of ICMP Type 3 Code 3 packets that can saturate some firewalls to 100% CPU at just 15 to 18 Mbps. - [Denial of Service (DoS)](https://blackneuron.ai/definitions/denial-of-service): A denial-of-service (DoS) attack makes a service unreachable by exhausting a finite resource; DDoS distributes the same load across many hosts. - [Phantom Domain Attack](https://blackneuron.ai/definitions/phantom-domain-attack): A phantom domain attack floods a recursive resolver with queries for domains whose authoritative servers never answer, filling its query slots. - [SIP Flood](https://blackneuron.ai/definitions/sip-flood): A SIP flood overwhelms a VoIP server with INVITE or REGISTER messages, exhausting its transaction table and worker threads at low bandwidth. - [Amplification Attack](https://blackneuron.ai/definitions/amplification-attack): An amplification attack sends small spoofed requests to servers that reply with far larger responses, multiplying attack bandwidth at the victim. - [Reflection Attack](https://blackneuron.ai/definitions/reflection-attack): A reflection attack spoofs the victim's IP and sends requests to third-party servers so their replies bounce onto the target, hiding the attacker. - [Load Balancer](https://blackneuron.ai/definitions/load-balancer): A load balancer distributes incoming connections across a backend pool, a control whose limits and health-check behavior DDoS testing validates. - [CAPTCHA](https://blackneuron.ai/definitions/captcha): A CAPTCHA is an L7 challenge that interposes a puzzle only a human can solve, filtering automated bot floods before they reach the origin. - [JavaScript Challenge](https://blackneuron.ai/definitions/javascript-challenge): A JavaScript challenge is an L7 control that makes a client run browser code to prove it is a real browser, silently filtering simple bots. - [Zombie](https://blackneuron.ai/definitions/zombie): A zombie is a compromised, attacker-controlled host that, with many others in a botnet, floods a target in a distributed denial-of-service attack. - [CoAP Amplification](https://blackneuron.ai/definitions/coap-amplification): A CoAP amplification attack is a UDP reflection vector that abuses exposed IoT devices on port 5683 to flood a victim with oversized responses. - [SYN Proxy](https://blackneuron.ai/definitions/syn-proxy): A SYN proxy is an inline device that completes the TCP handshake for the origin, so spoofed SYN floods die at the proxy and never reach it. - [Proof of Work](https://blackneuron.ai/definitions/proof-of-work): A proof-of-work challenge makes each client spend CPU on a puzzle before service, raising the per-request cost of an L7 flood. - [HTTP/2 CONTINUATION Flood](https://blackneuron.ai/definitions/http2-continuation-flood): An HTTP/2 CONTINUATION flood streams endless CONTINUATION frames without END_HEADERS, exhausting server memory on a request that never completes. - [Traffic Shaping](https://blackneuron.ai/definitions/traffic-shaping): Traffic shaping meters a flow to a committed rate with a token bucket, queuing short bursts and dropping sustained excess beyond the burst size. - [Rate-Based Rule](https://blackneuron.ai/definitions/rate-based-rule): A rate-based rule counts requests per source over a sliding window and blocks a source once it crosses the configured threshold. - [ReDoS (Regular Expression Denial of Service)](https://blackneuron.ai/definitions/redos): A ReDoS is an L7 attack that sends a crafted string to a vulnerable regex, forcing exponential backtracking that pins a CPU core at almost no bandwidth. - [XML-RPC Pingback Attack](https://blackneuron.ai/definitions/xml-rpc-pingback-attack): An XML-RPC pingback attack abuses WordPress pingback.ping so many legitimate sites fetch a victim URL, reflecting an HTTP flood from clean server IPs. - [HashDoS (Hash-Collision DoS)](https://blackneuron.ai/definitions/hash-collision-dos): A HashDoS sends a payload of colliding keys that all hit one hash bucket, degrading a parser hash map to a linear scan that pins a CPU core. - [Anomaly Detection](https://blackneuron.ai/definitions/anomaly-detection): Anomaly detection learns a normal traffic baseline and flags large deviations as attacks; DDoS testing measures its detection latency and false positives. - [Signature-Based Detection](https://blackneuron.ai/definitions/signature-based-detection): Signature-based detection matches traffic against a database of known attack patterns and drops hits: precise on known vectors, blind to novel ones. - [Stateful Firewall](https://blackneuron.ai/definitions/stateful-firewall): A stateful firewall tracks each connection in a finite state table; a flood can fill that table and make the firewall the first point of failure. ## Contact - [Contact](https://blackneuron.ai/contact): Testing is scoped in conversation. We do not publish a price list.