A flood test tells you your infrastructure can absorb N gigabits per second. It tells you nothing about whether your WAF fires correctly, whether your rate limits are scoped to the right paths, or whether an attacker using 10,000 different IPs at 10 requests per second each would ever trigger a single alert. Behavioral testing addresses this gap by running attack patterns that reflect how adversaries actually operate, not just how large their botnets are.
The distinction between volumetric and behavioral testing maps directly to the attacker population. Volumetric attacks (UDP floods, SYN floods, amplification attacks) are commodity: anyone can rent them for $20 per hour. Behavioral L7 attacks require more sophistication but produce greater availability impact per dollar of attack cost. The adversaries worth defending against are predominantly using behavioral techniques.
What Behavioral Tests Measure
Behavioral DDoS testing measures whether your defenses respond correctly to specific attack patterns, not just to raw volume. Test categories include: slow-rate attacks against rate limits calibrated for burst (100 requests per second sustained is more damaging to some origins than 10,000 requests per second for 5 seconds), geographic distribution attacks that stay below per-IP thresholds while exceeding aggregate capacity, header variation attacks that probe WAF matching across different User-Agent and Accept-Encoding combinations, and path rotation attacks that spread load across multiple endpoints to stay below per-endpoint limits.
Slow HTTP Body Tests
The Slowloris and slow-body attack patterns send HTTP requests with correct headers but delay the body transmission, holding open connections indefinitely. Most CDNs handle these at the edge, but origins with direct exposure or misconfigured timeout settings are vulnerable. A behavioral test for this sends 200 simultaneous connections that transmit 1 byte of body every 10 seconds, and measures whether new legitimate connections can be established after 60 seconds. If they cannot, the origin's connection table is exhausted by the slow connections.
"We passed every capacity test the vendor ran. Then we found out that slow HTTP attacks completely ignored our rate limits because they were configured on request count, not connection duration."
Sub-Threshold Distributed Tests
The most common practical gap in rate limiting is threshold calibration for distributed attacks. If your per-IP limit is 100 requests per minute, an attacker with 1,000 IPs sending 99 requests per minute per IP delivers 99,000 requests per minute to your origin with zero rate limit blocks. Behavioral testing simulates this by distributing load across a sufficient number of source IPs to stay under per-IP limits while measuring the aggregate impact on origin latency and error rates. If P99 latency exceeds threshold before any rate limit fires, the defense is ineffective for this attack pattern.
Varying Endpoint Tests
Per-endpoint rate limits fail when the attacker varies the target path to stay under each individual endpoint's limit while the cumulative processing cost exceeds origin capacity. A search endpoint limited to 500 requests per minute and a recommendation endpoint limited to 500 requests per minute can both be at 490 requests per minute while the origin is saturated. Behavioral testing probes this by rotating across all high-cost endpoints simultaneously and measuring aggregate origin impact.
What to Report from Behavioral Tests
Each behavioral test should produce: the test pattern and parameters (rate, IP count, target path), the first defense control that fired (if any), the delay before that control fired, the origin impact during the window before the control fired (latency increase, error rate increase), and a remediation recommendation if no control fired. This output is the input to your hardening sprint: each failed test is a configuration gap with a specific fix.
Run Behavioral Tests Against Your Environment
DDactic's assessment includes calibrated behavioral test sequences against your live endpoints, not just passive configuration review.
Run a Free Scan