Information Technology Act, 2000
DoS vs DDoS Attack: Difference, Mechanics and Legal Provisions
Both attacks do the same thing to the victim, make a service unavailable to the people entitled to use it, and the statute catches both in the same clause, s.43(f)'s denial of access. The difference is architecture: the DoS attack comes from one source, the DDoS attack from thousands of conscripted machines at once, and that single change defeats defences, multiplies volume and layers the attribution problem. Topic 85 placed the attacks in the typology; this note, as asked, is the dedicated comparison.
1. One Source Against a Botnet
Figure 1: The attack and its multiplication
- DoS. A denial of service attack from a single origin: one machine floods the target with traffic or requests, or fires a malformed input that crashes the service. Its limits are the attacker's own bandwidth and visibility, one source can be identified, filtered and blocked, which is why pure single-origin attacks now trouble only small targets.
- DDoS. The distributed form: a botnet, hundreds to millions of malware-conscripted computers, routers and cameras (Topic 104), directed by its herder to strike together. Distribution multiplies volume beyond any single connection and defeats source filtering, because the traffic arrives from everywhere, from ordinary machines whose owners know nothing.
- The methods. Both forms use the same three families: volumetric floods that exhaust bandwidth, protocol attacks that exhaust connection tables and network equipment, and application layer attacks that exhaust the service itself with seemingly legitimate requests, the last the hardest to distinguish from real traffic.
- Attribution. The DoS attacker stands behind one address; the DDoS herder stands behind the bots, whose owners are themselves victims of the s.43 intrusion that conscripted them, so the investigation must climb from visible bots to command infrastructure to herder, usually across borders (Topic 86)
2. The Legal Treatment
Figure 2: Hook, offence, escalation, incident
- The hook and the offence. s.43(f): denying or causing denial of access to any person authorised to access a computer resource, written for exactly this attack, with s.43(e)'s disruption clause alongside; done dishonestly or fraudulently, s.66, three years, cognizable and bailable (Topics 53, 58, 97)
- The escalations. A DDoS on a notified protected system engages s.70; struck with intent to threaten the nation or terrorise, and disrupting supplies or services essential to life or harming critical information infrastructure, it is s.66F cyber terrorism, to life, the paradigm being attacks on power, banking, transport and government service infrastructure (Topics 60, 63)
- The botnet's own liability. Building the weapon was itself a crime many times over: every conscripted machine was accessed and contaminated without permission, s.43(a) and (c) with s.66 per machine, and the herder's renting of the botnet to others adds abetment and conspiracy, so a DDoS prosecution has two layers, the strike and the swarm.
- Extortion and the incident side. Ransom DDoS, pay or the flood continues, adds BNS extortion exactly as in ransomware (Topic 106); and the attack is a CERT-In reportable incident on the six-hour clock, with mitigation through providers, scrubbing and sectoral defences running parallel to investigation (Topic 64)
⚠ Exam trap Fix the shared core first, both attacks are s.43(f) denial of access with the s.66 offence, then earn the comparison marks on architecture: one source against a botnet, filterable against unfilterable, simple against layered attribution. Remember the botnet's double criminality, every conscripted machine is a separate s.43 and s.66 intrusion before the first flood packet flies, and reserve s.66F for the case that actually pleads its three limbs, terror intent, the listed act, and consequence to life-essential services or critical infrastructure. |
3. Frequently Asked Questions
What is the difference between a DoS and a DDoS attack?
Both make a service unavailable to its authorised users by flooding or crashing it. A DoS attack comes from a single source, limited by one machine's bandwidth and exposed by one traceable origin, so it can often be filtered. A DDoS attack is launched simultaneously from a botnet of malware-conscripted devices, which multiplies the volume, defeats source filtering because traffic arrives from thousands of ordinary machines, and layers attribution: the visible attackers are victims, and the bot-herder stands behind them, usually abroad.
Under which provisions are DoS and DDoS attacks punished in India?
The core is Section 43(f) of the IT Act, denial of access to authorised users, with the disruption clauses of Section 43(e), becoming the Section 66 offence when done dishonestly or fraudulently. Attacks on notified protected systems engage Section 70, and where the intent and consequences of Section 66F are proved, disruption of essential supplies or services or harm to critical information infrastructure with terror intent, punishment extends to life imprisonment. Building the botnet is separately punishable, each conscripted machine being its own Section 43 and Section 66 intrusion, and the incident is reportable to CERT-In within six hours.
4. Related Topics
- Topic 60: Sections 66B to 66F. The offence family including cyber terrorism.
- Topic 63: Protected systems and NCIIPC. The infrastructure these attacks target.