ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › ICMP (ping) flood test

Layer 3 · Network · icmp_flood

ICMP (ping) flood test

The icmp_flood simulation sends a fixed echo request per operation to measure how your infrastructure handles network-layer noise. It is a bounded rehearsal of a classic ping flood against a host you own.

Layer L3 Protocol ICMP Command icmp_flood Access After verification

On this page

  1. What an ICMP flood does
  2. How ddos-simulation.com simulates it safely
  3. What the test exercises
  4. When to run it
  5. How to run the test
  6. Reading the results
  7. Availability & limits
  8. FAQ
  9. Related simulations

What an ICMP flood does

An ICMP (ping) flood sends a high rate of echo-request packets to consume bandwidth and force the target and intervening devices to spend cycles generating replies. On its own it is rarely fatal to a well-provisioned host, but it is a useful probe of how much network-layer noise your edge absorbs before it starts to matter.

How ddos-simulation.com simulates it safely

ddos-simulation.com sends a fixed echo request per operation to a single verified domain pinned to a public address, with the rate held inside the domain's limits. No packets are forged and no other host is touched.

Authorized targets only

Every run is bound to one verified domain you have proven you own. Ownership is checked over HTTPS before anything is scheduled, and running traffic against systems you do not own or are not clearly authorized to test may be unlawful. See the Acceptable Use Policy.

What the test exercises

  • ICMP rate limiting and filtering at the edge
  • Bandwidth headroom to the origin
  • Router and firewall handling of echo traffic
  • Whether ICMP is (correctly) deprioritized or dropped
  • Baseline network-layer noise tolerance

When to run an ICMP flood test

Run an ICMP flood test when you want a baseline for how the network layer and its rate limits react to raw packet noise.

  • You want to confirm ICMP rate limiting or filtering at the edge behaves as configured.
  • You're measuring how much network-layer noise the path absorbs before it affects real traffic.
  • You need a simple, low-risk first probe before scheduling heavier network-layer tests.

How to run a icmp flood test

  1. Verify your domain. Prove ownership over HTTPS — it is self-service and takes minutes.
  2. Add the icmp_flood command to a timeline in the portal and set the target path or port, rate, and duration.
  3. Set health thresholds. Choose the error-rate, latency, or status-code limits at which the test should abort itself.
  4. Run and watch. Bounded workers are provisioned minutes before start and torn down the moment the last task ends, while metrics stream live.
  5. Read the results. Review the recorded latency, status codes, and worker timeline to find where your service starts to bend.

Configure a icmp flood test in the portal →

Reading the results

Resilient: ICMP is rate-limited or dropped at the edge, real-traffic latency is unchanged, and no device spends meaningful CPU on echo handling.

Under strain: Echo traffic reaches and loads the origin, latency for real traffic rises, or a device processes every packet instead of shedding it.

Availability & limits

ICMP floods are available after your domain is verified and are priced per engagement — request a quote.

Frequently asked questions

Is an ICMP flood usually enough to take a site down?

Rarely on its own against well-provisioned infrastructure. It is most useful as a probe of edge filtering and bandwidth headroom, and as a baseline for network-layer noise tolerance.

Which hosts are affected?

Only your single verified, publicly-resolved domain. Private and loopback addresses are blocked and nothing is spoofed.

Related simulations

UDP flood test Simulate a bounded UDP flood against infrastructure you own to probe UDP ingress filtering, bandwidth headroom, and rate limits. SYN flood test Sends bounded, unspoofed TCP SYN packets without completing the handshake, pressuring the SYN backlog and testing SYN cookies, connection tracking, and edge mitigation. TCP flag flood test Flood a target you own with crafted TCP control segments — SYN, ACK, RST, and FIN — to pressure stateful firewalls and connection-tracking tables.

Rehearse the icmp flood against infrastructure you own — bounded, monitored, and stopped the instant you have your answer.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA