A DDoS (Distributed Denial of Service) attack disrupts access to a service by generating large volumes of traffic or requests from multiple systems against a specific server or service.
DDoS attacks take various forms, from consuming network bandwidth or server resources to overwhelming web servers and applications with large volumes of HTTP requests. As a result, websites may experience slower response times, become unable to process legitimate user requests, or even suffer service outages.
DDoS attacks continue to grow in scale. According to Cloudflare’s ‘DDoS Threat Report H1 2026’, 935 network-layer DDoS attacks exceeding 1 Tbps were recorded in the first half of 2026. In Q2 alone, the number of such attacks increased by 519% compared with Q1.
As DDoS threats continue to evolve, effective protection requires looking beyond traffic volume to understand where attack traffic is coming from.
Why the Source of Attack Traffic Matters in DDoS Protection
DDoS attacks generate traffic from a wide range of locations and systems to place excessive load on their targets. When analyzing this traffic, the source of requests can provide useful context alongside factors such as request volume and frequency.
At the web application layer, the IP addresses associated with attack requests can help identify where traffic originates. At the network layer, however, source IP spoofing can make it difficult to determine the actual origin of an attack based on IP addresses alone.
IP information should therefore be considered alongside other security signals when analyzing the characteristics and sources of DDoS traffic, rather than used as the sole basis for identifying an attack.
From this perspective, proactively identifying and managing access originating from IP addresses associated with malicious activity or concealed sources can serve as one layer of DDoS protection.
From Malicious IPs to Anonymous and Tor IPs
Different types of traffic may need to be considered when managing IP-based threats.
A Malicious IP is an IP address identified as being associated with malicious activity.
Blocking access from Malicious IPs can help protect services against traffic originating from known malicious sources.
Meanwhile, an Anonymous IP refers to an anonymized IP that makes the actual connection source difficult to identify, while Tor IPs can similarly obscure the original source of traffic through the Tor network.
Attackers may use tools such as proxies to make their observed location appear to be that of a proxy endpoint rather than their actual location. Identifying and blocking traffic with concealed origins can help manage these risks and address related DDoS attacks.
As the actual source of traffic can be obscured in this way, it is important to identify the types and characteristics of the IPs generating traffic and apply security policies appropriate to the service environment.
What Role Does IP-Based Protection Play in DDoS Defense?
DDoS attacks can target different areas, including networks and applications, requiring different approaches depending on the characteristics of the attack traffic.
IP-based protection uses the source of incoming traffic as a security signal to identify and block potentially high-risk access.
By distinguishing and managing various types of IPs, such as Malicious IPs, Anonymous IPs, and Tor IPs, users can establish security measures to address DDoS attacks associated with these sources.
For DDoS protection, it is important to consider the source of incoming traffic alongside traffic volume and apply appropriate IP-based protection.
Cloudbric Managed Rules for IP-Based Threats and Related DDoS Attacks
Cloudbric Managed Rules provides the following three rules to help protect AWS WAF environments against IP-based threats and related DDoS attacks:
- Malicious IP Protection
- Anonymous IP Protection
- Tor IP Protection
The three rules are also available together as a single package through the IP Protection Bundle.
The IP Protection Bundle enables users to configure and manage multiple rules more efficiently, reducing the operational effort of managing individual rules while maintaining the necessary scope of protection.
Learn more about Cloudbric Managed Rules at Link.