The 3 DDoS attack levels
- L3 (Network Layer): network attacks (ICMP flood, IP fragmentation). Massive volume (Tbps possible)
- L4 (Transport Layer): TCP/UDP attacks (SYN flood, UDP flood). Saturate the connection table
- L7 (Application Layer): HTTP/HTTPS attacks (slowloris, HTTP flood). Mimic legitimate traffic, harder to filter