Site AI Auditby Internet Solutions

DDoS Protection for Small Websites: What You Actually Need

September 30, 20268 min readSecurity & SSL
DDoS Protection for Small Websites: What You Actually Need

Short answer: A distributed denial-of-service (DDoS) attack floods a website or its server with so much traffic that real visitors cannot get through. For most small websites, practical protection comes from a hosting provider with network-level DDoS filtering, a CDN or reverse proxy in front of the site that absorbs and filters attacks, good page caching, rate limits on expensive pages such as login and search, and an origin server whose IP address is not publicly exposed. Add simple monitoring and a short response plan, and you are covered for the attacks small sites typically face.

What a DDoS attack is

A denial-of-service attack tries to make a service unavailable by exhausting its resources: network bandwidth, server connections, processor time or memory. In a distributed attack, the traffic comes from many machines at once, typically compromised computers, servers and internet-connected devices controlled as a botnet. Because the requests come from thousands of addresses, blocking a single IP does not help.

Attacks come in three broad forms:

Why small websites get hit

Small businesses sometimes assume they are too unimportant to attack. In practice, small sites are affected in several ways:

  1. Shared infrastructure. On shared hosting, an attack on another customer on the same server or network can slow down or take down your site too.
  2. Extortion. Criminals sometimes threaten an attack unless a ransom is paid, or launch a short attack as a demonstration.
  3. Competitors and grudges. Attack services are cheap to hire, and online shops, booking sites and gaming communities are occasional targets.
  4. Collateral damage. Attacks on a provider, DNS service or network upstream affect everyone behind it.

Many outages blamed on DDoS are actually caused by aggressive bots, scrapers or crawlers that are not trying to cause harm but send too many requests to an unprepared server. The same defences help against both.

The business impact is what matters. For a brochure site, an hour offline is annoying. For an online shop during a sale, a booking system on a busy weekend or a site that takes leads from paid ads, the same hour means lost revenue and wasted advertising spend. Decide how much downtime you can accept, and let that guide how much protection you pay for.

Layer 1: your hosting provider’s network protection

The first question for any site is what protection the host already provides. Most established hosting and cloud providers filter large volumetric attacks at the network level as part of their service. Ask your provider, or check their documentation:

The answer to the second question matters. Some providers “null-route” an attacked address, which stops the attack by making your site unreachable, effectively completing the attacker’s goal.

It also pays to check DNS. If your DNS provider goes down, nobody can find your site even if the server is fine, so use a DNS service with a large, distributed network.

Layer 2: a CDN or reverse proxy in front of the site

A content delivery network or security proxy places a large, distributed network between visitors and your server. It absorbs volumetric attacks across many data centres, filters protocol attacks and offers tools against application-layer floods, such as rate limiting, bot detection and challenge pages. Many CDN providers include basic DDoS protection even on free or low-cost plans. Our guide on whether you need a CDN covers the wider benefits.

When you set one up, make sure the connection between the CDN and your server stays encrypted and validated, as explained in our article on CDN SSL modes.

Layer 3: hide and protect the origin server

A proxy only helps if attackers cannot bypass it by sending traffic straight to your server’s real IP address. Common ways the origin address leaks:

After placing a proxy in front of the site, configure the server’s firewall to accept web traffic only from the proxy provider’s published IP ranges. If the origin IP was public for years, consider moving to a new address when you add the proxy. Send e-mail through a separate mail service rather than from the web server.

Layer 4: make requests cheap and limit expensive ones

Application-layer attacks succeed when each request makes the server work hard. Reducing that work raises the amount of traffic your site can survive:

  1. Cache pages. Cached pages can be served in milliseconds, and pages cached at the CDN do not reach your server at all. Our guide to page caching explains the options.
  2. Rate-limit expensive endpoints. Login, search, cart, contact forms and API endpoints should accept only a reasonable number of requests per visitor per minute. The same idea protects against brute-force login attacks.
  3. Use a web application firewall. A WAF can block known malicious patterns and bots before they reach the application.
  4. Disable unused features. Old APIs, XML-RPC and unused plugins with public endpoints are extra targets.
  5. Keep the server sized for peaks. A server that is already near its limits on a busy day falls over under the smallest attack.

What to do during an attack

Preparation makes an attack an inconvenience rather than a crisis. Write down in advance:

During an attack, check whether the site is really under attack or just overloaded by a bot or a traffic spike, enable the stronger protection modes, look at the logs to find the targeted URLs and rate-limit or cache them, and keep your provider informed. Do not pay extortion demands: payment does not guarantee the attack stops and marks you as a willing payer.

What protection costs, and what you do not need

For a typical small-business website, the setup above is often available at low or no extra cost: network protection included with reputable hosting, a CDN with basic DDoS mitigation, a caching plugin or server cache and firewall rules. Specialised enterprise DDoS services, dedicated scrubbing contracts and always-on monitoring teams are designed for large online businesses, banks and services that must never go down. Consider them only if downtime would cause serious losses or you are a known target.

Monitoring is worth having at every level. A simple uptime check that alerts you when the site stops responding, combined with speed monitoring, tells you about a problem before customers do.

How Site AI Audit helps

Site AI Audit is not a DDoS protection service and does not load-test your site. It checks the everyday health that makes attacks easier to survive and spot: server response time, compression and page weight, the SSL certificate, the HTTPS redirect, security headers and exposed software versions. Paid plans add re-checks and weekly monitoring with alerts when the SSL certificate is about to expire or a page breaks. See the plans and what each includes.

Related reading

The bottom line

DDoS attacks can reach any website, but small sites rarely need enterprise tools. Choose a host with network-level protection, put a CDN or reverse proxy in front of the site, keep the origin IP hidden, cache pages and rate-limit expensive ones, and write a short plan for what to do when it happens. That combination handles the attacks and bot floods small businesses typically face.

FAQ

What is a DDoS attack?

It is an attempt to make a website unavailable by flooding it with traffic from many compromised machines at once, so the server or its network connection cannot serve real visitors.

Do small websites need DDoS protection?

They need basic protection, which usually comes from the hosting provider and a CDN. Specialised enterprise services are rarely necessary for small sites.

Does a CDN protect against DDoS attacks?

Most CDNs absorb and filter many attacks thanks to their large networks, and offer rate limiting and bot controls. They only help fully if the origin server’s IP address is hidden.

How do I know if my site is under a DDoS attack?

Signs include sudden slowness or outages together with a sharp rise in requests, often to one URL, from many addresses. Server and CDN logs show the pattern; your host can confirm it.

Should I pay a DDoS ransom demand?

No. Paying does not guarantee the attack stops and can make you a repeat target. Contact your host and CDN, enable stronger protection and report the extortion to the police.

#Caching#Web hosting#Website security
Check your own website — free.What to fix on your website — and where to start.
Start free

More from the blog

All articles →
Internet Solutions

More from our team

Built by Internet Solutions. Try the rest of our products — each one saves you time in a different way.

internet-solutions.net ↗
Site AI Audit
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.