DDoS attacks do not operate at a single layer. A comprehensive assessment must evaluate resilience at each layer of the stack, because a gap at any layer is an exploitable attack vector regardless of how well the other layers are protected. A scrubbing center that absorbs 10 Tbps of volumetric traffic provides no protection against a 50-rps L7 attack against an expensive API endpoint. A perfectly configured WAF provides no protection against a connection-exhaustion attack on the TLS layer below it.
DDactic's six-layer assessment framework maps each layer to its characteristic attack vectors and the defenses that belong there. The layers are: network (L3/L4), TLS/connection, HTTP protocol, application API, authentication, and infrastructure. Each layer has distinct controls, distinct failure modes, and a distinct set of measurements that determine whether the defenses are functional.
Layer 1: Network (L3/L4)
The network layer assessment checks whether volumetric defenses are in place and correctly routed. The primary controls at this layer are BGP anycast routing (for scrubbing centers), IP reputation filtering, and ingress traffic shaping. DDactic verifies that the organization's BGP advertisement routes traffic through a scrubbing center for all ASNs, that origin IP addresses are not publicly discoverable (bypassing the scrubbing center), and that UDP/ICMP amplification surfaces are minimized. The key finding at this layer is origin IP exposure: 63% of DDactic assessments find at least one subdomain or historical DNS record that reveals the origin IP behind a CDN.
Layer 2: TLS and Connection
The TLS and connection layer covers server-level controls for connection-rate attacks: TLS handshake rate limits (preventing TLS handshake floods that exhaust CPU), idle connection timeouts (preventing slow-read attacks), maximum connections per IP, and TLS renegotiation disable (renegotiation allows re-keying mid-connection, consuming CPU at the server's expense). Default server configurations leave most of these controls at values designed for compatibility, not resilience. An Nginx server with default connection timeouts and no per-IP connection limit can be saturated by a modest slow-read attack.
Layer 3: HTTP Protocol
The HTTP protocol layer covers header validation, request size limits, and HTTP/2-specific controls. HTTP/2 introduces CONTINUATION frame floods, HEADERS frame floods, and rapid SETTINGS frame sends as attack vectors that do not exist in HTTP/1.1. Most WAFs and web servers have received patches for the most severe HTTP/2 vulnerabilities (CVE-2023-44487, the HTTP/2 Rapid Reset), but DDactic regularly finds unpatched server versions in assessments. HTTP request header size limits (large_client_header_buffers in Nginx) and maximum URI length limits prevent header-amplification attacks.
Layer 4: Application API
The application API layer is where most of DDactic's findings concentrate. Per-endpoint rate limits, query complexity limits for GraphQL, pagination enforcement, and endpoint-specific connection timeouts all belong here. This layer requires the most granular configuration because each endpoint has a distinct cost profile and a distinct legitimate traffic pattern. The measurement methodology at this layer (ramp request rates to find saturation thresholds) produces the data that drives the OPI score.
Layer 5: Authentication
Authentication-layer assessment focuses on login, registration, password reset, and OAuth token endpoints. Beyond the rate limiting covered in the API layer, authentication-specific controls include per-account attempt limits, MFA enforcement (which adds asymmetric cost for the attacker), bot detection challenges on login forms, and CAPTCHA bypass resistance. The financial cost of authentication attacks (SMS verification costs, account lockout support burden) is a unique characteristic of this layer not present in pure API DDoS.
Layer 6: Infrastructure
The infrastructure layer covers database connection pools, cache configuration (preventing cache stampedes), and origin server resource limits. Controls at this layer are the last line of defense: if all outer layers are bypassed or saturated, origin-level controls determine whether the service degrades gracefully or crashes completely. Circuit breakers, request queuing with backpressure, and graceful overload responses (returning 503 with Retry-After rather than hanging) keep the service recoverable under extreme load.
Get a Six-Layer Assessment
DDactic evaluates all six layers and reports findings by layer so remediation can be prioritized across the stack. Start with a free scan.
Run a Free Scan