Skip to content
normSight — Cyber Security

Solutions

DoS/DDoS Testing

DoS/DDoS testing measures, under controlled conditions, at what point and in what way an organisation's web and network systems fail under denial-of-service attack.

In recent years both institutions and brands have faced DDoS attacks that pose very significant risks to web and network systems. These are known as denial-of-service attacks. In order to take precautions against them, many institutions and businesses choose to commission comprehensive professional DoS/DDoS testing services at regular intervals.

As a result of denial-of-service attacks, companies become unreachable through their online services for extended periods. Users, customers and members outside the company are affected as well. As noted, these attacks — which indirectly prevent access to services — have in recent years caused many companies losses running into billions of dollars.

Every brand and every company needs to know how resilient its network and web systems are against attacks of this kind. Through a purpose-built architecture, the DoS/DDoS testing services developed by security companies therefore provide organisations with a robust defence simulation against such attacks.

Fundamentally, these attacks exploit the fact that network resources have finite limits: they disrupt the service being provided and render the targeted network entirely unusable. When you commission DoS/DDoS testing services from a professional firm, you can therefore learn how well protected your system is against attacks and what needs to be done. The simulation gives you the opportunity to make your protective measures more effective and more robust.

Frequently Asked Questions

Will the test actually bring our systems down?

The purpose is to find the limit of resilience, so the system is expected to come under strain. The work is carried out with written approval, within a pre-agreed maintenance window, and escalates in stages so it can be stopped at any point.

We already have a DDoS protection service — do we still need testing?

Yes. Whether protection solutions are correctly configured can only be verified under real load. Configurations in which application-layer attacks bypass network-layer protection are a common finding.

Which attack types are attempted?

Network and transport layer volumetric attacks and application layer attacks are assessed separately; which types fall within scope is agreed with the organisation before the work begins.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.