ISO 9001 certifiedPCI DSS compliantServing business since 1997320,000+ hosted domains99.9% guaranteed uptime24/7 supportISO 9001 certifiedPCI DSS compliantServing business since 1997320,000+ hosted domains99.9% guaranteed uptime24/7 support
Security

Protecting Your Website Against DDoS Attacks

DDoS attacks are increasingly common and can take any business offline in minutes. CDN, rate limiting and a web application firewall are the primary defences. Here is how they work and how to implement them.

What a DDoS attack is

A distributed denial-of-service (DDoS) attack attempts to make a website or online service unavailable by overwhelming it with traffic from multiple sources. Unlike a denial-of-service attack, which comes from a single machine, a DDoS attack uses a network of compromised computers, servers and IoT devices — a botnet — to generate massive amounts of traffic.

DDoS attacks have grown in frequency and size every year. Attackers can rent botnet time for as little as BD 40 per day on darknet markets, which means even a small business can be targeted. The motivations range from extortion and competition to hacktivism and simple vandalism.

The impact of a successful DDoS attack goes beyond lost revenue during the downtime. Customer trust erodes, search rankings suffer and recovery can take days if the attack compromises other systems.

Attack types

DDoS attacks fall into three categories, and each requires a different defensive approach. A serious attack often combines multiple types.

Volumetric attacks aim to saturate the bandwidth of the target. The attacker floods the network with a high volume of traffic — typically UDP floods, ICMP floods or DNS amplification. Volumetric attacks are measured in gigabits per second (Gbps) and can exceed 1 Tbps for large-scale attacks. The primary defence is upstream filtering by a CDN or scrubbing centre that absorbs the traffic before it reaches your server.

Protocol attacks exploit weaknesses in network protocols to consume server resources. SYN floods are the most common example, where the attacker sends a flood of TCP connection requests that the server tries to complete but never finishes. These attacks are measured in packets per second (pps) and are best mitigated by a firewall or a specialised DDoS mitigation appliance that detects incomplete handshakes.

Application-layer attacks target the web application itself, typically by flooding it with HTTP requests that look legitimate. These are the hardest to defend against because the traffic appears normal — the volume is just too high. They are measured in requests per second (rps). A web application firewall (WAF) with rate limiting is the primary defence.

Protection options

No single tool stops every DDoS attack. A layered defence is essential.

Content delivery network (CDN). A CDN distributes your site's content across a global network of servers. When a DDoS attack starts, the CDN absorbs the traffic across its infrastructure so only clean traffic reaches your origin server. Cloudflare, Akamai and Fastly all offer DDoS protection as part of their CDN services. For Bahrain-based sites, a CDN with Middle Eastern points of presence also improves performance for local visitors.

Web application firewall (WAF). A WAF filters HTTP traffic to and from your site, blocking requests that match known attack patterns. It can distinguish between a human using a browser and a botnet sending scripted requests, and it blocks the bot traffic while passing the legitimate traffic through.

Rate limiting. Rate limiting restricts the number of requests a single IP address can make within a time window. It stops application-layer attacks by preventing any single source from overwhelming the server. Implement rate limiting at the CDN or WAF level rather than on your server, so attack traffic is filtered before it reaches you.

Scrubbing services. For businesses that need enterprise-grade protection, dedicated DDoS scrubbing services route all traffic through a specialised filtering centre that removes malicious traffic before forwarding the rest. These services are more expensive but handle very large attacks that overwhelm standard CDN protection. Providers include Cloudflare Magic Transit, Akamai Prolexic and AWS Shield Advanced.

Protection layerBest forMonthly cost range
CDN (built-in DDoS)Volumetric attacksBD 8.50–BD 200
WAFApplication-layer attacksBD 50–BD 500
Rate limitingHTTP floodsOften included with CDN/WAF
Dedicated scrubbingLarge-scale or multi-vector attacksBD 1,000–BD 5,000+

Choosing a provider

When evaluating DDoS protection providers, consider network capacity (how much traffic the provider can absorb before you are affected), regional points of presence (providers with nodes in the Middle East offer lower latency and better protection for Bahrain-based sites), mitigation speed (how quickly the provider detects and responds to an attack), integration (how easily the service works with your existing hosting setup and whether you need to change DNS), and support (whether you can reach a human immediately during an attack, or whether you are reliant on ticket-based support).

Cloudflare offers the most accessible entry point with a generous free tier that includes basic DDoS protection. For businesses handling sensitive data or processing payments, a paid plan with WAF and advanced DDoS protection is advisable. Almada hosting plans include CDN-based DDoS protection as standard, with WAF available as an upgrade.

Incident response plan

Even with good protection, you need a plan for when an attack happens. The difference between an hour-long outage and a day-long outage is often the quality of the response plan.

First, know who to call. Your hosting provider, CDN support and, if applicable, your DDoS mitigation provider should all have escalation contacts. Store these numbers somewhere accessible outside your website (a printed card or a team chat channel).

Second, know what to turn on. Your CDN may have an "under attack" mode that presents a challenge page to all visitors. This blocks automated traffic but also inconveniences legitimate users. Activate it when you confirm an attack, then disable it once the attack subsides.

Third, communicate. Tell your team what is happening, what you are doing and when they can expect a resolution. If customers are affected, a brief status page update or social media post reduces the volume of inbound queries.

Finally, debrief after the event. What kind of attack was it? How was it detected? How long did mitigation take? What would have reduced the impact? Each attack teaches you something about your defences.

For most Bahrain businesses, the practical starting point is CDN-based DDoS protection with WAF and rate limiting. This combination stops the vast majority of attacks and costs less than BD 100 per month. Enterprise-grade scrubbing is only necessary if your business is large enough or your threat profile high enough to warrant it.

DDoS attacks are a question of when, not if. Talk to our team about the right protection for your site.
Questions

Frequently asked questions

A distributed denial-of-service (DDoS) attack floods a website or server with more traffic than it can handle, making it unavailable to legitimate users. The traffic comes from many compromised devices, which makes it harder to block than a single-source attack.

A CDN distributes traffic across a global network of servers, absorbing volumetric attacks before they reach your origin server. A WAF filters HTTP requests to block application-layer attacks. They work best together.

Yes. Small businesses are frequent targets, either directly or as collateral damage when an attacker targets a shared hosting provider or a service the business uses.

Basic CDN-based protection starts at BD 8.50 per month with most hosting providers. Dedicated DDoS scrubbing services range from BD 100 to BD 2,000 per month depending on capacity. A WAF is typically included with enterprise hosting plans.

Contact your hosting provider immediately. If you have a CDN, enable under-attack mode in the dashboard. Do not attempt to block individual IP addresses — the attack traffic will come from thousands of different sources. Focus on adding protective layers at the network edge.

Need DDoS protection for your site?

We provide CDN, WAF and rate limiting as part of our hosting plans. Enterprise-grade protection is available for businesses that need it.

WhatsApp us