ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing

The simulation library

DDoS simulation testing

DDoS simulation testing rehearses a real attack against infrastructure you own so you can measure how it holds up — safely, within bounds, and stopped the instant you have your answer. ddos-simulation.com offers 130 techniques across Layers 3–7, HTTP/2/3 control frames, API gateways, and recent 2024–2026 CVE resilience checks, each implemented to exercise a genuine failure mode through the OS network stack.

On this page

  1. What is DDoS simulation testing?
  2. What does it test?
  3. Is it the right test?
  4. How we run simulations safely
  5. What happens during an engagement?
  6. How provider approvals work
  7. What should you prepare?
  8. Example test scenario
  9. The 130 simulations & checks
  10. Pricing and quotes
  11. FAQ

What is DDoS simulation testing?

A distributed-denial-of-service (DDoS) attack tries to overwhelm a service with traffic until legitimate users can no longer reach it. DDoS simulation testing reproduces that pressure on purpose, against systems you control, so you can find the breaking point on your own schedule instead of discovering it during a real incident.

Good simulation testing is bounded and observable: you know exactly what traffic is generated, you watch service health in real time, and you can stop the moment you have your answer. That is the model ddos-simulation.com is built around.

What does a DDoS simulation test?

A useful test does more than ask whether a website stays online. It applies a known traffic pattern while you observe the full delivery path, helping you identify which control or component reaches its limit first.

Edge protection

Validate whether CDN, WAF, bot-management, and rate-limiting rules recognize the planned traffic and protect the origin before users are affected.

Network and connection state

Exercise ingress capacity, firewalls, load balancers, TCP backlogs, and connection-tracking tables with bounded Layer 3 and Layer 4 techniques.

Application capacity

Measure how TLS termination, HTTP servers, application workers, and downstream dependencies behave when request or connection pressure increases.

Operational readiness

Confirm that monitoring, alerts, stop conditions, escalation contacts, and incident procedures work while the event is happening—not only on paper.

Define success before choosing techniques. For example: keep checkout errors below an agreed threshold during a controlled request ramp, confirm edge controls activate before origin latency rises, or verify that a connection limit fails closed without affecting unrelated services.

When is DDoS simulation testing the right choice?

It is a good fit when

  • you own the target or hold explicit authority to test it;
  • you want to validate DDoS controls with real, bounded traffic;
  • you have a measurable availability or incident-response objective; and
  • operations, security, and relevant providers can support an agreed test window.

Choose a different test when

  • you only need normal-user capacity numbers—a load test is usually enough;
  • you are looking for exploitable security flaws—a penetration test has a different purpose;
  • ownership or provider permission is unclear; or
  • the objective requires unbounded or destructive traffic.

DDoS simulation vs. load testing vs. penetration testing

AssessmentTraffic or activityPrimary questionTypical outcome
DDoS simulationControlled adversarial traffic patterns across Layers 3–7Do availability controls and response procedures hold up?A measured threshold, observed failure mode, and remediation target
Load testExpected user journeys and application requestsDoes the application meet capacity and performance goals?Throughput, latency, resource use, and scaling behavior
Penetration testExploit-oriented security testingCan a tester find and demonstrate security weaknesses?Validated vulnerabilities and remediation advice

The categories can overlap. An HTTP simulation may resemble a high-load test, but its scope, authorization, traffic pattern, safety controls, and availability objective make the difference.

How we run simulations safely

Every technique below is scoped at each layer, by design:

  • Verified domains only. Ownership is proven over HTTPS before anything runs, and each worker refuses any target other than its one assigned domain.
  • Our own machines, never a botnet. Simulations run from ddos-simulation.com's dedicated load-generation machines — never compromised hosts — sending only bounded traffic with no arbitrary payloads to a pinned public address, with private and loopback destinations blocked.
  • Per-domain limits. Rate, concurrency, and worker counts are capped per domain and scaled to its validation level.
  • Automatic abort. Set error-rate, latency, or status-code thresholds and the test stops itself the instant your service crosses them.

The result is a stress test, never a weapon. See the Acceptable Use Policy for the full rules.

What happens during a DDoS testing engagement?

  1. Define the outcome and draft the plan. Build a command timeline yourself, or describe the target and objective so we can design one with you. A browser-only draft does not require an account.
  2. Request a review and quote. We review the target, techniques, rates, duration, worker count, safety controls, infrastructure, preferred window, and provider requirements, then price that specific engagement.
  3. Authorize the agreed scope. After accepting the quote, an authorized representative signs the Rules of Engagement, payment is completed, and domain ownership is verified. A plan change requires a new review and approval.
  4. Prepare monitoring and a baseline. Choose the service paths to watch, the health-check interval, and error-rate, latency, or status-code thresholds. Monitoring starts before the traffic timeline so you can compare the test with normal behavior.
  5. Run, observe, and stop safely. Dedicated workers execute only the approved timeline. Watch worker progress, aggregate traffic, and service health live; stop manually at any time or let a configured threshold abort the test automatically.
  6. Review the evidence. The approved plan, command timing and rates, health results, and audit history remain in the workspace. Compare them with your CDN, network, host, and application telemetry to locate the first constrained layer and plan a retest.

How do infrastructure-provider approvals work?

Most production targets depend on several providers: a cloud or hosting platform, network carrier, CDN, DNS service, load balancer, or DDoS-mitigation service. During engagement review, we map that delivery path with you and determine which provider requirements apply to the proposed DDoS simulation.

We work with your team and, where the provider's process requires it, with providers such as Cloudflare, Amazon Web Services (AWS), Microsoft Azure, Google Cloud, DigitalOcean, and others to confirm the permitted target, techniques, traffic levels, test window, monitoring, and emergency contacts.

  • Check the current policy. Provider rules differ and can change. A provider may require advance notice, a separate approval, an approved testing provider, or tighter traffic limits.
  • Document the permitted test. Required notices, approvals, provider limits, and contacts become part of the engagement review and Rules of Engagement.
  • Adjust the plan when necessary. We can reduce rates, change techniques or timing, or exclude infrastructure that a provider has not authorized.
  • Do not run without authorization. If a required provider authorization cannot be confirmed, we rescope the engagement or do not run the test.

No blanket approval is implied. Provider names identify infrastructure our customers may use; they do not imply endorsement, certification, or a commercial partnership. The customer remains responsible for permissions required under its provider accounts and contracts.

What should you prepare before requesting a quote?

You do not need a finished test plan, but these inputs make scoping and review faster:

  • A concrete objective: the control, limit, service-level objective, or response procedure you want to validate.
  • The exact target: domain, public service paths, ports, and environments that are in scope—and the systems that are not.
  • The delivery chain: hosting, network, CDN, DNS, mitigation, and other upstream providers that could receive or observe the traffic.
  • A candidate profile: relevant techniques, a starting level, maximum rate or concurrency, duration, and whether stages should overlap.
  • Health and stop conditions: paths to check, acceptable latency and error rate, expected status codes, and conditions that must end the test.
  • People and timing: preferred window, time zone, operational contacts, an emergency contact with authority to stop, and any change or incident records your team requires.

Domain verification is not the same as permission. We help coordinate the provider review, but the customer must obtain every approval required from the system owner and affected hosting, network, CDN, mitigation, or upstream providers. Review our provider-coordination and authorization guide and the Terms of Service before scheduling.

What might a first DDoS simulation look like?

Example objective: determine whether a checkout API remains within its agreed latency and error-rate limits while controlled HTTPS request pressure increases.

Observation: monitor a lightweight health path and the checkout path before, during, and after the traffic timeline. Set automatic abort thresholds for latency, non-success responses, and error rate.

Traffic plan: start below the expected limit, ramp through separately measurable stages, and add another technique only when it answers a specific question and has been approved.

Decision: compare the portal's traffic and health record with CDN, load-balancer, application, and database telemetry. The first threshold crossed tells you where to investigate before repeating the test.

This is an illustration, not a default prescription. Every engagement is bounded to the target's architecture, ownership, provider rules, risk tolerance, and approved objective.

The 130 simulations & checks

Each technique reproduces a real failure mode through the OS network stack. Grouped below across Layers 3–7, HTTP/2 & HTTP/3 protocol mechanics, API gateways, and 2024–2026 CVE resilience checks.

L3–L4 Network Layer Floods

L4 SYN flood test Sends bounded, unspoofed TCP SYN packets to test SYN cookies, backlogs, and edge filtering. L4 TCP connection flood test Completes full TCP handshakes and drops them immediately, flooding the OS accept queue. L4 TCP flag flood test Floods crafted TCP control segments (SYN, ACK, RST, FIN) to pressure stateful firewalls and conntrack tables. L4 Established connection flood Holds full, unspoofed TCP connections open and idle to exhaust connection-tracking state tables. L4 UDP flood test Probes UDP ingress filtering, packet processing headroom, and border rate limiters. L3 ICMP (ping) flood test Measures resilience to network-layer noise, ICMP rate limiting, and interface bandwidth headroom. L3 QUIC / HTTP3 Initial flood test Emits valid QUIC Initial UDP packets to test cryptographic handshake setup capacity. L4 DNS query flood test Floods DNS with random subdomains to bypass caching and hit authoritative nameservers (water-torture).

L6–L7 Application Layer Floods & Resource Exhaustion

L7 HTTPS flood test Runs an authorized HTTPS request flood to measure web server and reverse proxy throughput. L7 HTTP flood test Simulates high-rate HTTP/1.1 request volume against designated origin endpoints. L7 Slowloris test Holds connections open with a slow trickle of keep-alive headers to exhaust worker threads. L7 Slow POST (RUDY) test Drips large request bodies one byte at a time to tie up application request readers. L7 Slow read test Drains responses under a tiny TCP window to force servers to hold send buffers open. L7 TCP Zero-Window starvation Clamps socket receive window to zero to evaluate origin socket buffer management and connection timeouts. L6 SSL/TLS exhaustion test Simulates full TLS handshake floods to expose the CPU cost of cryptographic negotiation. L6 TLS session resumption stress Floods TLS ClientHello messages with invalid or expired session tickets to force full asymmetric handshakes. L7 WebSocket exhaustion test Completes real WebSocket handshakes and holds them open to consume state memory. L7 GraphQL complexity check Posts deeply nested and cyclic GraphQL queries to evaluate parser AST depth and execution limits.

HTTP/2 & 3 Protocol Mechanics & Control Frames

L7 HTTP/2 Rapid Reset (CVE-2023-44487) Opens and immediately resets HTTP/2 streams to test cancellation budget handling. L7 HTTP/2 CONTINUATION flood (CVE-2024-27316) Streams endless CONTINUATION frames to evaluate header buffer bounding and leak protection. L7 HTTP/2 MadeYouReset (CVE-2025-8671) Provokes server-sent stream resets to bypass concurrency limits mitigating rapid reset. L7 HTTP/2 PING & SETTINGS flood Streams continuous PING and empty SETTINGS control frames to test frame rate limiters. L7 HTTP/2 WINDOW_UPDATE stream churn Sends 1-byte incremental flow-control WINDOW_UPDATE frames to stress stream state tracking.

CVE 2024–2026 Web Server & Reverse Proxy Resilience Probes

CVE Apache mod_rewrite Crash (CVE-2024-38477) Tests Apache HTTP Server mod_rewrite substitution handling under encoded characters. CVE Apache HTTP/2 Conn Crash (CVE-2024-38476) Probes Apache HTTP/2 connection error handling under crafted frame sequences. CVE Apache mod_proxy Overflow (CVE-2024-38475) Evaluates backend response header chunk parsing resilience in Apache mod_proxy. CVE Apache H2 Memory Starvation (CVE-2024-38474) Tests Apache HTTP/2 stream memory pool deallocation when streams are canceled early. CVE Apache mod_proxy Backend DoS (CVE-2024-38473) Probes Apache reverse proxy encoding handling on backend forward requests. CVE Apache mod_authnz_ldap Hang (CVE-2024-39884) Tests Apache LDAP authentication handler resilience to backend directory timeouts. CVE Apache HTTP/2 Bomb Memory Exhaustion (CVE-2026-49975) Chains HPACK dynamic compression inflation with flow-control holds to test Apache mod_http2 memory limits. CVE Apache HttpCore HPACK Decoder Overflow (CVE-2026-54428) Streams crafted HPACK dynamic table state modifications to test Apache HttpComponents decoder buffer bounds. CVE Nginx MP4 Range Crash (CVE-2024-7347) Evaluates Nginx mp4 streaming module range header parsing against worker crash loops. CVE Nginx HTTP/3 Stream Corruption (CVE-2024-34757) Probes Nginx QUIC/HTTP3 stream state machine handling under pipelined resets. CVE NGINX Regex Map Buffer Overflow (CVE-2026-42533) Sends request headers targeting complex regex map directives to test NGINX worker buffer safety. CVE NGINX HTTP/3 Frame Mismatch Crash (CVE-2026-42530) Sends out-of-sequence QUIC frame packets to evaluate NGINX HTTP/3 state machine crash protection. CVE NGINX SSL OCSP Stapling Worker Crash (CVE-2026-40701) Initiates rapid TLS handshakes with client certificate requests to test NGINX OCSP verification safety. CVE NGINX QUIC ACK Range CPU Burn (CVE-2024-24989) Floods ACK frames with fragmented packet ranges to evaluate NGINX ngx_http_v3_module ACK range table processing CPU complexity. CVE NGINX QUIC MTU Probe Crash (CVE-2024-24990) Sends malformed MTU discovery probe frames to test NGINX QUIC packet sizing calculations against integer underflow. CVE NGINX Resolver Buffer Overwrite (CVE-2025-23014) Sends HTTP requests with host headers triggering complex upstream DNS resolution chains to evaluate ngx_resolver buffer bounds. CVE NGINX SSI Subrequest Loop (CVE-2025-24513) Injects cyclical Server Side Include (SSI) directives and subrequest headers to test NGINX subrequest depth limits. L7 NGINX Shared SSL Cache Contention Initiates rapid concurrent TLS handshakes targeting shared SSL session caches to evaluate worker spinlock contention under load. L7 NGINX Large Header Buffer Exhaustion Floods headers alternating across client_header_buffer_size thresholds to evaluate NGINX memory pool recycling and fragmentation. L7 NGINX Subrequest Depth Starvation Sends requests triggering nested auth_request and internal redirect chains to test NGINX NGX_HTTP_MAX_SUBREQUESTS bounds. L7 NGINX Gunzip Buffer Starvation Sends compressed HTTP request bodies and gzip transfer streams to evaluate ngx_http_gunzip_filter_module decompressor memory safety. CVE Tomcat HTTP/2 Stream DoS (CVE-2024-34750) Tests Apache Tomcat HTTP/2 connection manager limits without client window updates. CVE Tomcat TLS Connection Starvation (CVE-2024-38286) Evaluates Tomcat TLS handshake thread accumulation during incomplete handshakes. CVE Tomcat HTTP/2 Stream Thread DoS (CVE-2025-53506) Tests Tomcat HTTP/2 stream multiplexer thread limits under rapid unacknowledged stream bursts. CVE Tomcat HTTP/2 Priority Memory Leak (CVE-2025-31650) Evaluates Tomcat HTTP/2 PRIORITY frame handling and priority tree memory reclamation. CVE Tomcat WebSocket Slow Message Buffer DoS (CVE-2026-66299) Drips partial WebSocket frames across concurrent connections to evaluate Tomcat buffer reclamation. CVE Envoy HTTP/2 Reset Flood (CVE-2024-36137) Validates Envoy Proxy downstream reset flood protection against memory exhaustion. CVE Envoy HTTP/1 Codec Crash (CVE-2024-36138) Tests Envoy HTTP/1 codec parsing under malformed chunked transfer encodings. CVE Envoy H2 Metadata Buffer DoS (CVE-2024-27919) Evaluates Envoy HTTP/2 metadata frame buffering limits under flood conditions. CVE Envoy Request Crash (CVE-2024-45337) Probes Envoy header mutation filters against malformed URI path sequences. CVE Envoy TCP Connection Pool Crash (CVE-2025-62409) Evaluates Envoy TCP connection pool state transitions against null pointer dereferences. CVE Envoy CONNECT Tunnel Desync (CVE-2025-64763) Tests Envoy TCP proxy mode CONNECT early-data stream synchronization limits. CVE Envoy ext_proc Local Reply Crash (CVE-2025-30157) Probes Envoy ext_proc filter crash safety on local replies during aborted handshakes. CVE Envoy Deep JSON Object Stack Overflow (CVE-2026-48042) Sends HTTP payloads with deeply nested JSON arrays/objects to evaluate Envoy JSON destructor stack bounds. CVE Envoy Router 303 Redirect NULL Crash (CVE-2026-47221) Sends bodyless requests provoking HTTP 303 redirects to verify Envoy router filter null pointer handling. CVE Envoy OAuth2 Async In-Flight Exchange Crash (CVE-2026-48090) Triggers in-flight async OAuth2 token exchange cancellation to test Envoy worker thread safety. CVE HAProxy HTTP/2 Memory Leak (CVE-2024-45506) Tests HAProxy HTTP/2 connection multiplexer buffer reclamation. CVE HAProxy Buffer Crash (CVE-2024-45507) Evaluates HAProxy ring buffer management under fragmented HTTP payload streaming. CVE HAProxy Header Parsing DoS (CVE-2024-45508) Probes HAProxy HPACK header decompressed size validation limits. CVE HAProxy mjson Query Complexity DoS (CVE-2025-11230) Sends deeply nested or oversized numeric JSON query payloads to test HAProxy mjson parser resilience. CVE HAProxy QUIC Packet Underflow Loop (CVE-2026-26080) Sends truncated QUIC packet headers to test HAProxy QUIC packet parsing loop bounds and underflow defense. CVE Traefik ForwardAuth Unbounded Response OOM (CVE-2026-26998) Tests Traefik ForwardAuth middleware memory buffering limits against oversized authentication responses. CVE NGINX Unit Java Module Loop (CVE-2025-1695) Evaluates NGINX Unit request dispatcher resilience against cyclical language module routing loops. CVE Varnish HTTP/1 Linger Pipelining Workspace Overflow (CVE-2026-40396) Sends pipelined HTTP/1 requests interleaved with linger delays to test Varnish workspace boundary and assertion safety. CVE Varnish HTTP/2 Upgrade Speculative Workspace Exhaustion (CVE-2026-40394) Sends HTTP/1.1 Upgrade: h2c with trailing pipelined HTTP/2 preface payload to test Varnish transport upgrade buffer splitting safety. CVE Varnish Enterprise HeaderPlus Workspace Overflow (CVE-2026-40395) Sends requests with high-cardinality header arrays to test Varnish vmod_headerplus / req0 workspace bounds. CVE Varnish HTTP/2 Broke Window Flow-Control Starvation (CVE-2024-30156) Opens concurrent HTTP/2 streams with minimal flow-control window increments to evaluate Varnish worker thread release under credit exhaustion.

CVE 2024–2026 Runtime & Core Infrastructure Resilience Probes

CVE Go net/http Chunked DoS (CVE-2024-24790) Tests Go standard library net/http parser against chunked header loop amplification. CVE Go net/http Mux DoS (CVE-2024-24791) Evaluates Go HTTP/2 server stream handler thread pool bounding. CVE Go net/http Cookie Fragment Amplification (CVE-2025-58186) Sends requests with hundreds of tiny Cookie header fragments to test Go net/http memory bounds. CVE Go TLS Hostname Verification CPU (CVE-2025-61729) Probes Go crypto/tls certificate error formatting CPU consumption under malformed handshakes. CVE Node.js HTTP/2 Leak (CVE-2024-22019) Tests Node.js http2 module session cleanup when client frames stall. CVE Node.js Smuggling & Stall (CVE-2024-22020) Probes Node.js llhttp parser under pipelined chunk boundary mismatches. CVE Node.js undici Buffer Exhaustion (CVE-2024-30260) Evaluates undici HTTP client stream buffer bounding against unconsumed responses. CVE Node.js undici HTTP/2 Crash (CVE-2024-30261) Tests undici HTTP/2 client connection recovery when servers send unexpected GOAWAY frames. CVE Node.js HTTP/2 Malformed HEADERS Crash (CVE-2025-59465) Streams malformed HTTP/2 HEADERS frames with invalid HPACK data to verify Node.js error boundary handling. CVE Node.js Async Hooks Stack Exhaustion (CVE-2025-59466) Sends nested asynchronous callback request bursts to verify Node.js async_hooks call-stack limits. CVE Node.js H2 Header Memory Limit Bypass (CVE-2026-56846) Streams fragmented HTTP/2 header blocks designed to test Node.js maxSessionMemory enforcement. CVE Python urllib Parse Loop (CVE-2024-4032) Tests Python urllib URL parsing CPU cost under crafted query parameters. CVE Python asyncio Buffer Exhaustion (CVE-2024-6221) Evaluates Python asyncio socket buffer flow control when backpressure is applied. CVE Python aiohttp Multipart POST Stall (CVE-2025-69228) Streams chunked multipart POST request bodies with micro-delays to test Python aiohttp event loop bounds. CVE Python aiohttp Cookie Storm Logging DoS (CVE-2025-69230) Sends high-frequency streams of malformed cookies to test Python aiohttp logging I/O backpressure. CVE Python aiohttp Auto Decompress Bomb (CVE-2025-69223) Sends compressed request payloads to evaluate Python aiohttp auto_decompress memory expansion limits. CVE Python aiohttp Parser Error Formatting Stall (CVE-2026-69244) Sends malformed HTTP response-like payloads to test Python aiohttp C parser error formatting bounds. CVE Python EngineIO WebSocket Buffer Growth (CVE-2026-48809) Sends continuous oversized EngineIO/Socket.io WebSocket message frames to test incoming buffer ceilings. CVE Caddy / quic-go HTTP/3 QPACK Expansion (GO-2025-4233) Emits HTTP/3 QPACK instruction frames to test quic-go dynamic table memory bounding. CVE BIND 9 Query Crash (CVE-2024-1737) Tests ISC BIND 9 DNS query lookup table limits under high-cardinality record floods. CVE BIND 9 Cache Exhaustion (CVE-2024-1975) Evaluates BIND 9 recursive resolver SIG(0) and TSIG verification CPU consumption. CVE BIND 9 DNSKEY Verification CPU Load (CVE-2025-8677) Sends DNS queries targeting crafted zones with malformed DNSKEY records to test DNSSEC verification CPU bounds. CVE BIND 9 BRID/HHIT Record Crash (CVE-2025-13878) Sends DNS queries for malformed BRID/HHIT resource records to test BIND 9 parser resilience. CVE BIND 9 Invalid TSIG Assertion Crash (CVE-2025-40775) Sends DNS control packets with invalid TSIG signatures to verify BIND 9 assertion failure protection.

API Gateway API Gateway & Ingress Resilience Probes

API Gateway Kong Data Plane Token Parsing Panic (CVE-2026-18675) Sends requests with malformed JWT kid header types to test Kong token verification error boundaries against runtime panics. API Gateway Kong LuaJIT Request Context Memory Starvation Floods requests with high-cardinality headers and cookies to test Kong OpenResty / LuaJIT context table memory bounds. API Gateway Apache APISIX ForwardAuth Header Overflow (CVE-2026-31908) Sends requests with header injection sequences to test APISIX forward-auth plugin buffer reclamation and recursion limits. API Gateway Apache APISIX Regex Route Match CPU Burn Generates path permutations targeting complex route regex rules to evaluate APISIX routing evaluation CPU bounds. API Gateway Spring Cloud Gateway SpEL Algorithmic DoS (CVE-2026-41850) Sends requests with crafted query and header tokens to test Spring Cloud Gateway SpEL predicate evaluation CPU limits. API Gateway Spring Cloud Gateway Netty Buffer Starvation Drips slow HTTP body streams across concurrent connections to evaluate Reactor Netty byte buffer pool reclamation. API Gateway Tyk JSON Schema Validation Complexity DoS Sends deeply nested JSON payloads to test Tyk JSON schema validation middleware CPU bounds and memory limits. API Gateway Tyk Auth Session Cache Churn Floods API endpoints with randomized bearer tokens and keys to evaluate Tyk auth cache-miss handling and worker throughput. API Gateway KrakenD JOSE Header Memory Exhaustion (CVE-2025-30204) Sends requests with oversized, fragmented JOSE header blocks to test KrakenD stateless JWT unmarshaling memory bounds. API Gateway KrakenD CircuitBreaker State Resource Leak (CVE-2026-13649) Probes endpoints under high-frequency error state transitions to evaluate KrakenD CircuitBreaker state table resource reclamation.

Create your own custom test

Combine any of the 130 attack techniques, adjust request rates, concurrency, duration, and automatic health-check abort thresholds using our public configure endpoint — no account or sign-up required to build and preview your timeline.

Configure custom test

How are DDoS simulations priced?

Every test is priced per engagement. Build a plan—or ask us to design one—then request a quote. There is no subscription and no upfront price to pay before you see the accepted scope and one-off engagement price.

The quote reflects the techniques, command duration and overlap, required rate and concurrency, worker capacity, target infrastructure, scheduling, safety controls, and the work needed to review provider approval. The most aggressive network-layer methods—UDP, SYN, established-connection, QUIC, and DNS floods—receive the closest scrutiny.

You can draft a timeline in the browser without an account. Create a workspace when you are ready to save it and request a quote; domain ownership must be verified before the accepted test runs.

See the quote and approval path →

Frequently asked questions

What is DDoS simulation testing?

DDoS simulation testing rehearses a real distributed-denial-of-service attack against infrastructure you own, under controlled conditions, so you can measure how it holds up and fix weaknesses before a real attacker finds them. On ddos-simulation.com every run is bounded, targets a verified domain, and can abort itself the moment your service degrades.

Is DDoS simulation testing legal?

It is legal when you test systems you own or are clearly authorized in writing to test. ddos-simulation.com enforces this with domain-ownership verification and per-domain limits, and never runs traffic against arbitrary targets. Testing systems you do not own or control may be a criminal offence.

How many attack techniques can I simulate?

130 techniques spanning Layers 3 to 7, HTTP/2 & HTTP/3 protocol mechanics, API gateway resilience suites, and recent 2024–2026 CVE resilience checks: HTTP/HTTPS floods, SYN/UDP/TCP connection floods, Slowloris, Slow POST, Slow Read, TCP Zero-Window starvation, SSL/TLS exhaustion, HTTP/2 Rapid Reset, CONTINUATION floods, HTTP/2 PING & WINDOW_UPDATE floods, QUIC Initial floods, DNS floods, WebSocket exhaustion, GraphQL complexity checks, API gateway probes (Kong, APISIX, Spring Cloud Gateway, Tyk, KrakenD), and 2024–2026 CVE simulations for Apache, Nginx, Tomcat, Envoy, HAProxy, Varnish, Traefik, Go, Node.js, Python, and BIND.

How is DDoS simulation testing different from load testing?

Load testing usually models expected application traffic to measure capacity and performance. DDoS simulation testing deliberately reproduces adversarial traffic patterns to validate availability controls, rate limits, connection handling, monitoring, and incident response. A test plan can use both approaches when the objectives overlap.

Do you coordinate with my cloud or CDN provider?

Yes. During scoping we map the hosting, cloud, CDN, DNS, network, and mitigation providers in the delivery chain and work with your team and, where required, the provider to confirm that the test fits its current policy. This can include Cloudflare, Amazon Web Services (AWS), Microsoft Azure, Google Cloud, DigitalOcean, and others. Depending on the provider, that may mean notice, a separate approval process, an approved testing provider, or tighter limits. If a required authorization cannot be confirmed, we rescope the plan or do not run it.

What do I need before requesting a quote?

Prepare the target, the outcome you want to measure, candidate techniques and scale, a preferred test window, health-check paths and stop thresholds, operational contacts, and any required hosting, network, CDN, or upstream-provider permissions. You can draft a plan and request a quote before domain verification, but ownership verification and all required written authorization must be complete before the test runs.

What can I monitor during a DDoS simulation?

The portal shows the command timeline, worker progress, aggregate traffic, and live service-health checks. Health monitoring tracks latency, HTTP status, and error rate on the paths you choose. Configured thresholds can abort the test automatically, and you can stop it manually at any time.

What information is available after the test?

The approved plan, command timing and rates, health results, and audit history remain visible in the customer workspace. Compare that record with telemetry from your CDN, hosting provider, network, and application to identify the first constrained layer and decide what to change before a retest.

How are DDoS simulations priced?

Each engagement is priced individually. You build a plan (or ask us to design one) and request a quote; we price the specific test and confirm timing. Domain ownership must be verified before it runs, and the most aggressive network-layer methods — UDP, SYN, established-connection, QUIC, and DNS floods — get the closest scrutiny in the manual review every engagement goes through.

Draft a timeline in the browser now — no account needed — then verify a domain when you are ready to run it.

Build a test plan
← Back to ddos-simulation.com
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA