Distributed Denial-of-Service (DDoS) attacks are a significant threat to organisations, capable of crippling services and disrupting business operations. This SOC playbook outlines a structured response to DDoS attacks, detailing the phases of detection, investigation, containment, recovery, and lessons learned. By following this playbook, security teams can effectively mitigate the impact of DDoS attacks and enhance their overall network security posture.
Introduction — What incident does this playbook address?
This playbook addresses the structured response to DDoS attacks, which can manifest in various forms, including volumetric, protocol, and application layer attacks. Given their high severity and potential to disrupt organisational infrastructure and services, a well-defined incident response is crucial. The following sections provide a comprehensive guide to managing DDoS incidents, ensuring that security teams are equipped to handle these threats efficiently.
Detection & Triage — Initial indicators and severity assessment
Initial Indicators
The first step in responding to a DDoS attack is detecting its occurrence. Key indicators include:
- Traffic Anomalies: Unusual spikes in inbound traffic, often characterised by a high volume of requests from a single or multiple IP addresses.
- Service Degradation: Slow response times or complete unavailability of services, which may be reported by users or detected through monitoring tools.
- Alerts from Security Tools: Notifications from intrusion detection systems (IDS), firewalls, or DDoS mitigation services indicating abnormal traffic patterns.
Severity Assessment
Once a potential DDoS attack is detected, the severity must be assessed. This involves:
- Traffic Analysis: Use network monitoring tools to analyse traffic patterns. Identify the type of DDoS attack (volumetric, protocol, or application layer) and quantify the traffic volume against baseline metrics.
- Impact Evaluation: Determine the affected services and the potential impact on business operations. Consider factors such as customer experience, revenue loss, and reputational damage.
- Prioritisation: Based on the analysis, prioritise the incident for response. High-severity incidents warrant immediate action, while lower-severity incidents may require monitoring.
Investigation Steps — Detailed analysis procedure
Step 1: Collect Data
Gather relevant data to understand the attack's scope and methodology. This includes:
- Network Logs: Review logs from firewalls, routers, and load balancers to identify the source and type of traffic.
- Application Logs: Examine application logs for error messages or unusual access patterns that may indicate an application layer attack.
- Threat Intelligence: Consult threat intelligence feeds to identify known attack vectors and tactics associated with the observed traffic patterns.
Step 2: Identify Attack Vector
Determine the specific attack vector being employed. This may involve:
- Volumetric Attacks: Characterised by overwhelming bandwidth consumption, often using UDP floods or ICMP floods.
- Protocol Attacks: Exploiting weaknesses in network protocols, such as SYN floods or fragmented packet attacks.
- Application Layer Attacks: Targeting specific applications, often using HTTP floods or Slowloris techniques.
Step 3: Assess Mitigation Options
Based on the attack vector, evaluate available mitigation strategies. This may include:
- Rate Limiting: Implementing rate limiting on servers to control the number of requests processed.
- Traffic Filtering: Using firewalls or DDoS mitigation services to filter out malicious traffic.
- Load Balancing: Distributing traffic across multiple servers to absorb the impact of the attack.
Containment & Eradication — How to stop and remove the threat
Immediate Containment
- Engage DDoS Mitigation Services: If contracted, activate DDoS mitigation services to absorb and filter malicious traffic.
- Adjust Firewall Rules: Modify firewall rules to block known malicious IP addresses and restrict traffic to essential services only.
- Implement Traffic Shaping: Apply traffic shaping techniques to prioritise legitimate traffic and throttle suspicious requests.
Eradication
- Remove Malicious Traffic: Continuously monitor traffic and adjust filtering rules as necessary to remove any remaining malicious traffic.
- Patch Vulnerabilities: Ensure that all systems are updated to mitigate any vulnerabilities that may have been exploited during the attack.
- Review Access Controls: Assess and strengthen access controls for critical services to prevent future exploitation.
Recovery — Restoring normal operations
Step 1: Service Restoration
- Gradual Service Restoration: Begin restoring services gradually, ensuring that they are monitored closely for any signs of residual attack traffic.
- Performance Monitoring: Implement enhanced monitoring to track performance metrics and user experience during the recovery phase.
Step 2: Post-Incident Review
- Conduct a Post-Mortem: Hold a post-incident review with all stakeholders to discuss the attack, response actions, and areas for improvement.
- Update Incident Response Plan: Revise the incident response plan based on lessons learned, ensuring that future responses are more effective.
Lessons Learned — Post-incident improvements and reporting
Continuous Improvement
- Documentation: Document the incident thoroughly, including timelines, actions taken, and outcomes. This will serve as a reference for future incidents.
- Training and Simulation: Conduct regular training sessions and tabletop exercises to prepare the team for potential DDoS attacks. Simulations can help identify gaps in the response plan.
- Stakeholder Reporting: Prepare a report for senior management and stakeholders outlining the incident, impact, response actions, and recommendations for improvement.
Final Thoughts
DDoS attacks pose a significant risk to organisations, but with a structured SOC playbook, security teams can effectively manage these incidents. By following the outlined phases of detection, investigation, containment, recovery, and lessons learned, organisations can not only mitigate the impact of DDoS attacks but also enhance their overall cybersecurity resilience.
For comprehensive support in developing and implementing effective incident response strategies, contact CyberZonic today. Our expert team is ready to assist you in fortifying your organisation against DDoS attacks and other cybersecurity threats.


