During a distributed denial of service (DDoS) attack, an attacker overwhelms a website with malicious traffic and makes it unreachable to legitimate users. Think of it as a freeway on-ramp where the road is backed up for miles, with commuters unable to enter. DDoS protection can safeguard your website, keeping your online store up and running.
According to Cloudflare’s 2025 Q4 DDoS threat report, the number and volume of attacks has more than doubled in 2025 from the year before. This highlights the need for comprehensive protection and mitigating strategies. The repercussions of not doing so can be significant—downtime can cost even small online retailers up to $5,000 an hour, according to Calyptix Security.
Read on to find out what DDoS attacks are, what DDoS protection entails, and how Shopify protects merchants.
What is a DDoS attack?
DDOS attacks happen when a malicious actor targets a website and floods it with incoming traffic. The traffic exceeds the site’s ability to respond to each request and causes it to become unable to handle legitimate traffic.
When the attack traffic is sent from a single location, the source of the service disruption can be isolated and blocked. But distributed attacks work differently. They employ a network of thousands of compromised devices (a.k.a. a botnet) to send DDoS traffic from multiple locations at the same time. That makes it hard to stop the attack at the source. To prevent this, business owners must take DDoS mitigation steps to ensure business continuity.
Common types of DDoS attacks
Websites are vulnerable to different styles of DDoS attacks, each focused on a different part of business operations. There are three primary types of DDoS attacks (volumetric, protocol, and application layer), with different mitigation techniques for each:
Volumetric attacks
Volumetric attacks are the most basic kind of distributed denial attack. These work by consuming all of your site’s bandwidth, leaving none available for legitimate users. The most common DDoS attacks exploit flaws in fundamental protocols created during the earliest days of the Internet. Volumetric attacks fall into three categories:
Random port attacks
Attackers randomly send discrete chunks of data, known as packets, to ports designed to handle network communications using the User Datagram Protocol (UDP) and the Internet Control Message Protocol (ICMP). The web server is then forced to send a “destination unreachable” response to each packet. Sending tens of thousands of UDP requests each second quickly overwhelms network servers, rendering them unable to respond to legitimate requests.
DNS amplification
These attacks exploit the Internet’s domain name system (DNS), which translates domain names into numerical IP addresses and routes them to the correct destination. The attacker sends a lookup request asking for extensive information about a domain, but tells the DNS server to send responses to your business IP address. Because a small query can generate responses up to 70 times larger, asking for thousands of lookups can amplify the amount of network traffic redirected to your site.
NTP amplification
As with DNS amplification, attackers take advantage of legacy network infrastructure—in this case, the Network Time Protocol (NTP) servers that ensure all network resources stay in sync—by sending requests for large amounts of information, using your IP as the return address.
Protocol attacks
These cyber attacks exploit weaknesses in networking protocols to consume server resources instead of bandwidth. Here’s how two of the most common protocol attacks work.
SYN floods
These attacks target the Transmission Control Protocol (TCP), one of the most fundamental technologies underlying Internet connections. TCP uses a three-part connection process known as a handshake. A client device sends a synchronize (SYN) packet asking to make a connection. The server responds with an acknowledgment (SYN-ACK) saying it’s ready to communicate, and reserves memory and other finite system resources to receive more data. The client sends back an ACK packet confirming the connection and begins transmitting.
In a SYN flood, the client machine is controlled by an attacker who never sends the final ACK, leaving your business website waiting for a response that never comes. Flooding your site with SYN packets eventually ties up all your server resources, leaving the site unable to respond to legitimate requests for connections.
Malformed packets
Every packet sent across the Internet is governed by rules that determine its size, structure, and the types of network protocols it uses. By deliberately breaking these rules, attackers can cause a server to become unstable, and in some cases even execute malicious code on the target system.
Application layer attacks
Application-layer DDoS attacks may be the most serious concern for ecommerce businesses because they closely mimic real user behavior, making them harder to detect. The most common ones include:
-
HTTP floods. Attackers use bots to send what look like normal user requests, such as browsing products or loading images, but at such a high volume that they exhaust your system resources.
-
Shopping cart abuse. Attackers hammer your shopping cart and payment processing systems with requests, which require more system resources to handle than simple page loads.
-
Search and filter exhaustion. Bots may submit thousands of complex search queries simultaneously, forcing resource-intensive database operations. This attack can be especially damaging to sites with extensive product catalogs.
-
Account takeovers. Also known as credential stuffing, this attack involves flooding login pages with stolen user names and passwords, overloading your authentication systems while also attempting to steal customer identities.
-
Slow-rate attacks. In this exploit, attackers use bots to send HTTP requests very slowly in order to keep each connection open for as long as possible, tying up server resources without ever triggering traffic spike alerts.
What is DDoS protection?
- Traffic monitoring
- Anomaly detection
- Filtering malicious traffic
- Rate limiting
- Traffic scrubbing
- Rerouting diffusion
- Web application firewalls
- AI- and behavior-based detection
For most small businesses, DDoS protection entails using a web host that has DDoS protection features built in (such as Shopify), or contracting with a service provider like Akamai or Cloudflare specifically designed to mitigate such attacks.
These DDoS protection services work by analyzing traffic patterns, looking for abnormal activity, and then blocking malicious attempts at connection while allowing legitimate requests to pass through. Effective DDoS protection solutions typically involve a combination of layered defenses designed to handle different types of DDoS threats. Here are the most common ways DDoS services mitigate attacks:
Traffic monitoring
DDoS protection starts with establishing what normal traffic patterns look like, making it easier to identify anomalies or suspicious behavior. Establishing a baseline for legitimate traffic makes your DDoS protection services work more effectively.
Anomaly detection
DDoS detection systems look for abnormal traffic patterns: sudden volume spikes, unusual sources or locations, and behavior inconsistent with normal customers. Modern anomaly detection relies heavily on machine learning techniques to identify suspicious traffic.
Filtering malicious traffic
Filtering systems inspect incoming traffic and routinely block any that match patterns associated with sophisticated DDoS attacks. This includes malformed packets, invalid protocols, or requests from malicious IP addresses.
Rate limiting
This technique limits how many requests a single source can make during a specified time period, designed to thwart bots that would make many more requests per second than a legitimate customer would, especially during logins, searches, and checkouts.
Traffic scrubbing
This defense kicks in when an attack is already underway, diverting incoming requests to a specialized filtering infrastructure that separates legitimate traffic from malicious attacks. It passes clean requests from scrubbing centers onto your servers.
Rerouting and diffusion
In this defense technique, traffic from large-scale DDoS attacks is distributed across a global network of data centers, allowing each location to handle a manageable share of the attack.
Web application firewalls
A WAF intercepts all web traffic coming into your servers and inspects all requests at the application layer. This allows the firewall to identify attacks that mimic legitimate users, but at volumes or speeds no human would ever generate.
AI- and behavior-based detection
Modern DDoS protection services use advanced machine learning algorithms to identify suspicious traffic and novel DDoS attacks that don’t conform to existing attack patterns. This is increasingly important as attackers deploy increasingly sophisticated, human-like attacks.
How Shopify protects your site against DDoS attacks
Shopify uses the Cloudflare network to protect its platform from DDoS attacks and other cyber threats. Cloudflare deploys a global content delivery network (CDN) to help absorb large DDoS attacks, filter out malicious traffic, and ensure that only legitimate requests reach your servers.
All traffic sent to your online store on Shopify is automatically filtered through Cloudflare servers using sophisticated bot-detection techniques and Web application firewalls, enabling it to block DDoS threats and other suspicious traffic before it makes it to your site. Shopify Plus customers can also request and schedule periods of advanced bot protection during flash sales and other high-traffic events, helping limit auto-checkout bots by blocking bots from checkout.
In addition, Shopify’s enterprise-grade security is regularly audited by third parties for the integrity, availability, and confidentiality of its safeguards. It is compliant with the most advanced Payment Card Industry and Service Organization Control (SOC) standards.
DDoS protection FAQ
Why do hackers use DDoS attacks?
DDoS attackers may be driven by several motivations. A common scenario is when adversaries attack an ecommerce site and then demand money to make the attack stop, betting that the owners would rather pay the ransom than lose revenue to downtime. Another could be deliberate sabotage, where vendors employ DDoS-for-hire services to take down their competitors during busy sales periods. A DDoS attack may also provide cover for other types of attack, keeping IT staff busy with DDoS mitigation while they steal customer data or plant malware.
Is DDoS protection worth it?
Ecommerce businesses of every size need to have a plan to ensure service availability in the event of a DDoS attack. The questions you need to ask yourself are how much will downtime cost you, and how much can you afford to lose?
What is the best DDoS protection?
The best DDoS protection for small and midsize ecommerce vendors is picking a hosting platform with built-in protection against attacks. Platforms like Shopify build DDoS protections directly into their infrastructure, offering their merchants enterprise-grade security without any additional costs.




