DDoS (distributed denial-of-service) mitigation is the set of defences that keep a site or service available when attackers flood it with traffic from many sources to exhaust its bandwidth, servers or application resources.
Definition
DDoS (distributed denial-of-service) mitigation is the set of defences that keep a site or service available when attackers flood it with traffic from many sources to exhaust its bandwidth, servers or application resources. Mitigation combines a large distributed network that can absorb volumetric floods, filtering that drops attack traffic while passing legitimate requests, rate limiting, challenge mechanisms for suspicious clients, and application-layer protection against low-volume requests crafted to be expensive to process.
For consumer-facing online businesses, DDoS protection is standard infrastructure rather than an optional extra, usually delivered through a CDN or a specialist provider that sits in front of the origin servers. The goal is that an attack is absorbed and filtered upstream so that real users see little or no disruption.
In context
iGaming is a frequent DDoS target. Attacks are timed to high-revenue moments — major sports events, big fixtures, jackpot periods — when downtime is most costly, and they are used for extortion (pay to stop the attack), by competitors, and as cover for other intrusions.
An operator that goes down during a major event loses live betting turnover directly and damages player trust, so DDoS resilience is a core operational requirement, and licensed regimes expect operators to maintain business continuity.
For affiliates, DDoS resilience is a legitimate, if rarely discussed, operator-quality factor: a brand with a poor uptime record during big events is a weaker recommendation for in-play bettors. It is also relevant to the affiliate's own infrastructure — a large content or comparison site is itself a potential target, especially around peak traffic events, so it needs the same CDN-level protection.
Affiliates should never engage with or promote "booter" or "stresser" services, which are illegal DDoS-for-hire tools, and content in this area should stay at the level of explaining that reputable operators run upstream DDoS protection and treating attack techniques as out of scope. Uptime monitoring and a note on an operator's stability during recent major events is the useful, publishable angle.
Worked example
An operator routes all traffic through a CDN with volumetric and application-layer DDoS protection. During a major tournament final an attack targets its in-play betting endpoints; the flood is filtered upstream and players see a brief slowdown rather than an outage.
An affiliate's review notes the operator's strong uptime through recent peak events as a plus for live bettors.
Related terms
Frequently asked questions
Browse the full iGaming & affiliate glossary — hundreds of EN/RU terms with examples.
← Back to glossary