RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Monday, August 10, 2026
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Add RCR Wireless as a preferred source on Google
  • Qualcomm 6G Insights
  • Huawei Content Hub
  • Qualcomm – 6G Vision
  • OSS/BSS Channel
  • RCRTech Roundtable: AI Infrastructure
RCR Wireless
RCR Wireless
  • Advanced Mimo
  • Mobile mmWave
  • 5G Positioning
  • Green Networks
  • Metaverse
  • Automotive
  • Industrial and Wide-area IoT
Copyright 2021 - All Right Reserved
Home - Application layer DDoS attacks: What is an HTTP(S) flood?
FeaturedFundamentalsSecurity

Application layer DDoS attacks: What is an HTTP(S) flood?

by Catherine Sbeglia Nin February 20, 2023
written by Catherine Sbeglia Nin February 20, 2023 Share
LinkedinEmail
Share 0LinkedinEmail
http application layer ddos
343

HTTP flood is the most common type of application layer DDoS attacks

Distributed denial-of-service (DDoS) attacks refer to a malicious actor or actors temporarily or indefinitely disrupting services of a host connected to a network to render an entire network or website unavailable. There are generally considered three types of DDoS attacks: Volumetric attacks, which involve generating massive volumes of traffic to completely saturate a network’s bandwidth; protocol attacks, which eat up the processing capacity of network infrastructure resources; and lastly, the subject of this article, application or Layer 7 attacks, which exploit weaknesses in the layer of a website that interfaces between human input and the site’s technical backend.

Damian Menscher, one of the lead engineers on Google’s DoS Security SRE team, told RCR Wireless News that a few years ago, application layer attacks — particularly those targeting the protocol Hypertext Transfer Protocol (HTTP) — were not growing as quickly as some other types of DDoS attacks. At the time, he found this surprising, and sure enough that trend began to shift. “In late 2021 or early 2022, there was a new method that attackers started using for those application layer attacks and so that exponential growth has now taken off and caught up with the others,” he said, adding that as a result, application layer attacks are “the current focus on everyone’s mind.”

For Google, though, application layer attacks were always a priority, according to Menscher: “Google approached [DDoS] differently. Most other companies in the world were worried about network level — packet and bandwidth — attacks and they developed a lot of expertise in those and now are starting to worry about [application layer attacks],” he noted.

He explained further that the reason for this is that Google has much more bandwidth than most other companies and so bandwidth flooding-type events weren’t as much of a concern for the tech giant. “Most of our capabilities started on the other end of the spectrum with defending against application layer attacks and then working backwards to develop the other types of defenses everyone else considers standard,” he said.

But what is HTTP, and what happens if it’s a target?

In Layer 7 there are two protocols that are typically the focus of such attacks: HTTP — mentioned earlier — and Domain Name System (DNS). Of the two, HTTP are the most common types of application layer DDoS attacks. HTTP is the primary protocol used to send data between a web browser and a website, and HTTPS or Hypertext transfer protocol secure is a more secure, encrypted version of this protocol. HTTPS is important for certain, sensitive data transactions on the internet, such as banking or accessing your email or health records.

In the case of an HTTP or HTTPS flood, a bad actor will initiate a flood of seemingly legitimate HTTP(S) requests, using up the network’s resources, and eventually causing it to lag or even entirely shut down. Because the requests mimic legitimate traffic so well, this is a particularly challenging DDoS attack to catch.Web browsers, like Google, take HTTPS very seriously, as Menscher already alluded to. Non-HTTPS websites will be flagged by browsers as not secure.

“Google incrementally took steps to nudge websites towards incorporating HTTPS over a number of years,” DDoS mitigation company Cloudflare reports on its website, adding that Google also considers HTTPS when assessing how to return search results. “[T]he more secure the website, the less likely the visitor will be making a mistake by clicking on the link Google provided,” the IT company said.

How to defend against HTTP(S) flood attacks?

When it comes to protecting your network from DDoS attacks, Menscher said it’s not really a one-size-fits-all situation: “Different places may be focused on different threats depending on where they fit in their business or what their business concerns are,” he offered. However, if HTTP(S) attacks are of particular concern, there are some specific actions that can be taken, even if mitigating such attacks is notably complex.

For example, limiting the number of concurrent connections allowed to the service port can help prevent HTTP flood attacks. Even better, utilizing a partner-provided solution that can automatically stop sending new connections to the service port once this maximum is reached, will further ensure protection. Once the number of connections on the port dips back below the threshold, these solutions can resume sending connections through.

While instances of DDoS attacks in general are increasing both in frequency and size, Menscher advises companies not to panic. “Exponential growth is expected in computers — we expect computers to increase in power over time, hard drives get larger, networks get faster — so if attacks get larger, that is totally normal and expected,” he shared. “I don’t tend to panic over these things. I think it’s helpful to know what to plan for but certainly I don’t think the world is coming to an end over any of this.”

You Might Also Like
  • Intelligent RAN Forum 2026
  • NTN Integration Forum 2026
  • Operators are seeking greater control of NTN: GSMA Intelligence
  • Monday (telco diary) | Q-Day is nigh – join the telco wake-up call
  • The new reality of cyber risk in an AI-driven world (Reader Forum)
  • From SD-WAN to 5G core – the network controller is now the target (Reader Forum)

Table of Contents

  • HTTP flood is the most common type of application layer DDoS attacks
    • But what is HTTP, and what happens if it’s a target?
    • How to defend against HTTP(S) flood attacks?
Share 0 LinkedinEmail
Catherine Sbeglia Nin
Catherine Sbeglia Nin

Catherine Sbeglia Nin is the Managing Editor for RCR Wireless News, where she covers topics such as Wi-Fi, network infrastructure, AI and edge computing. She also produced and hosted Arden Media's podcast Well, technically... After studying English and Film & Media Studies at The University of Rochester, she moved to Madison, WI. Having already lived on both coasts, she thought she’d give the middle a try. So far, she likes it very much.

previous post
BICS selects Nokia SDN solution for 5G network slicing
next post
Rogers, Shaw extend deadline to complete proposed merger

White Papers

  • Norton eBook: The 2026 Telco Playbook

  • Enea White Paper: Why Intelligent AAA is the Swiss Army Knife of Telecom

  • CSG White Paper: Telco AI Enabler: Mediation’s Defining Role

  • Enea White Paper: Scalable Database Design for 5G and Beyond

  • Supermicro and NVIDIA Whitepaper: Powering sovereign AI at scale

Editorial Reports

  • Report: NTN in motion — evolving standards, expanding services

  • Market Pulse Report: Telco AI in 2026 – Trends, Challenges and Opportunities

  • Nvidia Report: The State of AI in Telecommunications: 2026 Trends

Webinars

  • Webinar: Building 6G — aligning technology, policy and purpose

  • SIMCom Webinar: Scaling your next deployment – from plastic to provisioning

  • Webinar: Rethinking the RAN as AI, cloud and openness converge

  • Webinar: Scale-Up, Scale-Out, Scale-Across – Building AI-Era Network Fabrics

  • Webinar: NTN in motion – evolving standards, expanding services

Since 1982, RCR Wireless News has been providing wireless and mobile industry news, insights, and analysis to mobile and wireless industry professionals, decision makers, policy makers, analysts and investors.

Facebook Twitter Youtube Linkedin Envelope Rss

Useful Links

  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive
  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive

Edtior's Picks

‘We think of them as hometown ISPs’ – WISPA chief on BEAD, Starlink,...
Friday (telco diary) | Friday night fare – private 5G to go
The Agentic Network — NVIDIA on the full-stack path to telecom autonomy

Latest Articles

‘We think of them as hometown ISPs’ – WISPA chief on BEAD, Starlink, CBRS
Friday (telco diary) | Friday night fare – private 5G to go
The Agentic Network — NVIDIA on the full-stack path to telecom autonomy
Ericsson named sole global tech partner in SK Telecom-led AI-RAN pilot

© 2026 RCR Wireless News All Right Reserved. Developed by Eight Hats.

Cookie Policy | Privacy Policy

RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
@2020 - All Right Reserved. Designed and Developed by PenciDesign