Testing resistance to DoS and DDoS attacks

Why simulate DoS and DDoS attacks?

Testing resistance

Simulating DoS (Denial of Service) and DDoS (Distributed Denial of Service) attacks is essential for verifying whether an organization's critical systems are able to withstand overload and remain functional even under pressure. These tests reveal weaknesses in network infrastructure, application services, and incident response capabilities.

Benefits of DoS/DDoS attack simulation:


  • Verification of network and application infrastructure capacities
  • Identification of bottlenecks and insufficient protection mechanisms
  • Testing real-time detection, mitigation, and response capabilities
  • Validating firewall, WAF, CDN, and anti-DDoS solution configurations
  • Compliance with regulatory requirements (e.g., DORA, NIS2)

Main objectives of DoS and DDoS testing


  • Simulation of attacks with the aim of overloading critical systems and determining their performance limits
  • Verification of mitigation functionality at the network and application layers
  • Testing of incident response processes and IT/SOC team cooperation
  • Identification of vulnerabilities at system entry points
  • Evaluating the robustness of services provided by third parties (e.g., DNS, CDN, cloud hosting)

Typical attacks and differences between DoS and DDoS


Attack Name Type Category Description
SYN Flood DoS/DDoS Volumetric Flooding a server with TCP requests
HTTP GET/POST Flood DDoS Application High volume of legitimate requests from many clients
ICMP Flood DoS/DDoS Volumetric Flooding a server with ICMP requests
Slowloris DoS Logical Keeping HTTP connections open with incomplete headers

How testing works in practice

Icon

Preparation phase

Defining the scope of the test, identifying critical systems, obtaining approvals (e.g., from cloud service operators).

Icon

Simulation of attacks

Performing controlled DoS/DDoS scenarios with different vectors – e.g., SYN flood, HTTP flood, UDP flood, Slowloris, etc.

Icon

Monitoring and metric collection

Recording performance and status data on target systems, overview of impact on SLA.

Icon

Analysis and reporting

Evaluating the effectiveness of defenses, compiling findings and proposing measures.

Icon

Retesting (optional)

Verify remediation measures and improved resilience after their implementation.

What are the requirements for testing teams?


  • Expertise in network security and traffic engineering.
  • Experience with anti-DDoS technologies such as Cloudflare, Arbor, Radware, Akamai.
  • DORA does not impose specific certifications, but requires proof of adequate team expertise.
  • Independence of the testing team from the development team, IT operations department, and infrastructure suppliers.
  • Knowledge of legal aspects – emphasis on permits, supervision, and legal limits of the test.

In accordance with the European DORA regulation, organizations must:

01

Conduct performance and stress tests of critical systems (e.g., DoS/DDoS simulations), especially for services critical to stability and continuity of operations.

02

Include scenario testing (including stress/DoS) and coordination with relevant third parties as necessary, if this is appropriate to the nature of the services. Involve qualified and independent testing teams with proven experience in DoS/DDoS.

03

DORA does not impose specific certifications, but requires appropriate team expertise.

04

Ensure documentation of results, propose corrective measures, and perform retesting if necessary.

05

Integrate findings into a broader cyber resilience and incident preparedness strategy.

Why work with BDO?


BDO provides DoS/DDoS attack simulations as part of an overall cyber resilience testing strategy in accordance with European DORA and NIS2 regulations and proven standards such ISO 27001, and OWASP.

01 Technical expertise and experience

Náš tým disponuje specializovanými znalostmi v oblasti síťových útoků, testování infrastruktury a konfigurace anti-DDoS obrany. Máme zkušenosti s testováním i největších finančních subjektů a provozovatelů cloudových platforem.

02  Knowledge of the regulatory framework

We understand DORA requirements and can tailor tests so that the outputs are usable for supervision and auditing. We help set up a testing strategy and ensure its compliance with other types of testing (TLPT, penetration tests).

03  Independence and credibility

As an independent consulting company, we offer objective and credible results. Our work is a sign of quality for regulators and the client's internal management.

04  Certified team with expert practice

Our team has specialized knowledge in the field of network attacks, infrastructure testing, and anti-DDoS defense configuration. We have experience testing even the largest financial institutions and cloud platform operators.

Main contacts

Martin Hořický

Martin Hořický

Partner • Digital Services
View bio
kovalcik

Marek Kovalčík

Chief Information Security Officer • Digital Services
View bio