Hosting Cost
Intermediate Security

DDoS Protection in Hosting

Marcus Feld, Infrastructure Editor
Marcus Feld

Infrastructure Editor

Disclosure: Some links on this page are affiliate links — if you sign up through one, we may earn a commission at no extra cost to you. It never changes our ratings, rankings or verdicts: we don't sell hosting and take no pay-for-placement.

Who it's for

  • Small business website owners
  • Ecommerce site operators
  • Developers
  • Agencies choosing hosting for clients

By Marcus Feld, Infrastructure Editor

What DDoS Protection Hosting Does

A distributed denial-of-service (DDoS) attack floods a website with traffic from many sources at once. It aims to exhaust the site’s bandwidth, connections, or processing capacity until it can’t respond to legitimate visitors. DDoS protection hosting is the set of network and application controls that detect and filter this flood traffic before it reaches your server, so the site stays reachable through the attack. It’s a distinct layer from a general firewall — a web application firewall filters malicious requests, while DDoS protection filters malicious volume.

a hand holding a phone photographing a monitor in a dim home office, the screen showing a firewall settings panel and a spiky traffic graph,

Threat Model: The Two Attack Types

Volumetric Attacks

Volumetric attacks flood the network connection itself with junk traffic (UDP floods, amplification attacks) until legitimate requests can’t get through. They’re measured in Gbps.

Application-Layer Attacks

Application-layer attacks mimic legitimate requests — repeated page loads, form submissions, API calls — at high volume to exhaust server CPU, memory, or database connections. These are harder to distinguish from a real traffic spike, and are the more common threat for small and mid-size sites.

Small business sites are more often hit by opportunistic, lower-volume application-layer floods than by the large-scale volumetric attacks that make headlines. But on shared hosting’s tighter resource ceilings, even a modest flood can take a site down.

Prevention

CDN-Based Traffic Filtering

CDN-based traffic filtering routes traffic through a distributed network that absorbs and filters volume before it reaches the origin server. See CDN in hosting.

Rate Limiting

Rate limiting caps requests per IP address in a given window, blunting both brute-force and flood attempts.

Edge Hosting

Edge, or geo-distributed, hosting spreads load across multiple points of presence rather than a single origin. See edge hosting.

Cloud Hosting

Cloud hosting’s ability to absorb traffic spikes with additional resources reduces, though doesn’t eliminate, the impact of a flood compared with a fixed-resource plan.

Detection

  • Sudden, sustained traffic spikes with an unusual geographic or IP pattern (many requests from a narrow IP range or unlikely locations)
  • A spike in server resource usage (CPU, memory, database connections) that doesn’t correlate with a real marketing event or press mention
  • Increased error rates or slow response times reported by uptime monitoring — see why is my website slow for how to distinguish a flood from an organic performance issue
  • Your host’s own network monitoring flagging and notifying you of anomalous inbound traffic

Remediation During an Active Attack

  1. Contact your host or CDN provider immediately — most DDoS mitigation is more effective activated or escalated in real time than left on default settings.
  2. Enable “under attack” or aggressive challenge modes if your CDN offers one (these add a verification step for suspicious visitors).
  3. Temporarily tighten rate limits and geo-restrictions if the attack traffic is concentrated.
  4. Review logs after the attack subsides to identify the pattern and adjust standing rules to catch a repeat attempt earlier.
a compact rack-mounted switch with many cables plugged in and glowing port lights, a black router on the shelf above, dim room

Hardening Checklist

  • Confirm what DDoS mitigation is included by default with your hosting plan versus what costs extra
  • Route traffic through a CDN with built-in DDoS filtering
  • Enable rate limiting at the server or CDN layer
  • Set up uptime and traffic-anomaly monitoring so an attack is detected within minutes, not hours
  • Know your host’s escalation path (support contact, response-time SLA) before you need it
  • Choose hosting with headroom to scale if your traffic profile makes you a plausible target (ecommerce, high-traffic publishers)

Provider Responsibility vs Yours

Network-level DDoS filtering is almost always the host’s responsibility — you can’t filter volumetric traffic from inside your own application. What remains yours: choosing a host or CDN with mitigation strong enough for your risk profile, configuring rate limits and challenge modes correctly, and having a monitoring and escalation plan ready before an attack happens. For traffic-sensitive sites, this is a factor worth weighing directly in best hosting for high-traffic sites rather than assuming any plan covers it equally.

a sunlit kitchen table with a closed laptop, a bowl of fruit and a glass of water, bright morning light

FAQ

Does every hosting plan include DDoS protection? Most hosts include some baseline network-level filtering, but the strength and scope varies enormously — entry-level shared plans often provide only minimal protection, while cloud and CDN-fronted setups offer far more capacity to absorb an attack.

Can a small business website actually be targeted by DDoS? Yes. Attacks aren’t limited to large, high-profile targets — competitor disputes, disgruntled individuals, and opportunistic bot networks target sites of any size, and small sites’ thinner resource ceilings make them easier to knock offline with less effort.

Does a firewall stop a DDoS attack? A web application firewall filters malicious request content, not traffic volume — it helps against application-layer floods disguised as normal requests but won’t stop a volumetric flood on its own; that requires network-level filtering.

How is DDoS protection different from a CDN? A CDN’s core job is caching and delivering content closer to visitors for speed; DDoS protection is a security feature many CDNs bundle on top of that delivery network, but the two are separate capabilities even when sold together.