skip to content

In a for-hire DDoS attack, what does the buyer actually have to compromise?

level: juniorimportance: should knowfreq 58%

answer

  1. bought capacity, not built capacity
  2. three roles, three budgets
  3. the fleet existed months before the order
  4. buyer supplies target, duration, payment

basics

~20 s

Nothing. Flood capacity is a commodity: the buyer rents time on a fleet someone else built, supplies a target and a duration, and never touches a host. The volume that arrives says nothing about the buyer's skill.

solid answer

~50 s

Flood supply splits into three roles, and whoever orders an attack occupies the last one. A herder spends months acquiring and holding a fleet of compromised devices or servers. A reseller slices that fleet into minutes or hours and sells access to it like a subscription. The buyer supplies a target address, a duration and payment, and traffic arrives. The buyer needs no exploit, no implant and no intrusion of their own; the compromises happened much earlier, done by someone else, against parties unrelated to the target. Two consequences matter. First, the arriving volume is evidence about the fleet, not about the person who paid for it. Second, the attack tends to be shaped like the product that was sold: fixed durations, a small menu of traffic types, an abrupt stop when the window ends, and identical repeats when another window is bought.

go deeper

for a junior

Be ready to say that flood capacity is rented and that the person who ordered an attack may have compromised nothing at all. Name the three roles: the fleet owner, the reseller, the buyer.

for a middle

Explain how the supply chain separates capability from action. The fleet is acquired over months by one party and sold in slices to anyone, so the traffic describes the fleet rather than the customer who pointed it.

for a senior

Reason from attack shape back to the purchase. Fixed windows, a short menu of traffic types and clean stops suggest a bought product, while sustained pressure that changes in response to what you do suggests an operator running their own capacity.

for a principal

Own the organisational consequence. A rented burst is cheap to repeat and implies almost nothing about adversary resources, so it should not on its own justify treating the event as a targeted campaign or funding a response sized for one.

## The question behind the question A volumetric flood needs far more bandwidth than any single participant owns, so the interesting question is never "how did they generate it" but "where did they get it, and from whom". Flood capacity has a supply chain, and the person who launches an attack is usually standing at the retail end of it. Interviewers ask this to see whether you confuse *using* capacity with *acquiring* it. ## Three roles, three different people **The herder** builds and holds the fleet. This is slow, patient work: scanning for reachable devices with default or reused credentials, exploiting an old firmware flaw, absorbing other people's abandoned fleets, and then keeping the collection alive as devices reboot, get replaced, or fall off the internet. The herder's asset is a population, and its value decays continuously, so the work never stops. What the herder has to lose is the fleet itself and the anonymity of whatever they use to reach it. **The reseller** turns that population into a product. The fleet is sliced by time, sometimes by geography or traffic type, and sold to strangers, frequently with a self-service front end, tiered plans, and support. The reseller may be the herder, or may be renting wholesale from one. Their asset is the storefront and the customer base; what they have to lose is payment processing and reachability. **The buyer** supplies three things: an address or hostname, a duration, and money. They receive traffic. They do not receive hosts, credentials, an implant, or any way to reach the fleet. In many cases they could not describe what the fleet is made of. ## Why this matters for what you can conclude The most common wrong answer is that a big flood implies a capable attacker. It does not. It implies a capable *seller*. The buyer's technical ceiling can be a form and a payment; the well-documented pattern of school and gaming-service floods exists precisely because the barrier is a purchase, not a skill. It also means the fleet's victims and the flood's target are disjoint sets. Every host in the fleet is a separate compromise of a separate party, usually months earlier, and almost never anyone with a relationship to the target. Reasoning "they must have gotten in somewhere near us first" is a category error here. ## What the purchase shape tells you Because the product is sold in units, bought capacity tends to look like units: - **Round durations.** Traffic that runs and then stops cleanly, rather than fading, is consistent with a window expiring. - **A small menu.** Sellers offer a handful of preset traffic types; a bought attack rarely improvises. - **Identical repeats.** A second, third and fourth burst that look the same are the same preset re-run, not an operator learning. - **No adaptation.** Nobody is watching the effect and adjusting, because nobody at the retail end has that access. Contrast an operator running their own capacity: no meter is running, so they can hold pressure indefinitely, pause, change traffic type in response to what happens, and resume. That difference in tempo is more informative than the peak number. ## Where the money actually goes The economics are worth internalising even without quoting prices. The herder's cost is amortised across every hour sold, and a compromised consumer device costs close to nothing to acquire, so retail prices for short bursts sit low enough to be bought casually. Price scales mainly with **duration and sustained rate**, not with peak, because peak is just how much of the existing fleet is pointed at you for a moment. That is the single most useful economic fact in this area: the meter runs on time, not on the headline number. ## The boundary This is the supply side only. Which of the target's resources the volume exhausts, how far a single request multiplies on its way, and what happens to the traffic when it arrives are all separate subjects. Here the question is narrower and cleaner: who owns the capacity, who sells it, who buys it, and what each of them had to do to get there. ## How to answer in an interview Say plainly that the buyer compromises nothing, name the three roles, and then draw the inference the interviewer is fishing for: the traffic characterises the fleet and its owner, while the *pattern of purchase* is the only thing that characterises the buyer.

  • If the buyer compromised nothing, who did, and against whom?
    The herder, months earlier, against parties unrelated to the target: home routers, cameras, set-top boxes, unpatched servers, sometimes hosting accounts. Every host in the fleet is its own separate victim of its own separate compromise, and the flood's target is not among them.
  • What does buying rather than building predict about the attack's shape?
    Product-shaped behaviour. Bursts match sold durations, traffic types come from a short preset menu, the stop is abrupt rather than gradual, and repeats look identical because the same preset is re-run. An operator running their own fleet has no meter running, so they can sustain, pause and change approach as they watch the effect.
  • Does a buyer ever get more than traffic?
    At the retail end, no. They get an effect for a period. Access to the fleet itself, the ability to choose which hosts participate, or anything reusable belongs to the wholesale relationship between herder and reseller, which is a different transaction with a different price and different exposure.

saying these in an interview costs you the question

  • Assumes whoever flooded you also broke into something themselves
  • Reads peak bandwidth as proof of a skilled adversary
  • Thinks the fleet is built by the person launching the attack
  • Believes the buyer needs custom malware or an exploit

context