---
title: "Layer 3 vs layer 4 vs layer 7 DDoS: what's the difference? | StreetHosting"
description: "Learn the difference between layer 3, 4 and 7 DDoS attacks: what each one exhausts, how to measure in Gbps, pps and rps, and where each is really mitigated."
url: "https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos"
type: "page"
language: "en-US"
---

Infrastructure · 9 min · Intermediate

Published on Sep 28, 2026 · Updated on Sep 28, 2026

# DDoS attacks by layer: network, transport and application

A layer 3 DDoS fills the pipe, a layer 4 DDoS fills up connection tables, and a layer 7 DDoS makes the application work until it falls over. See what each one exhausts and at which point in the infrastructure each defense works.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[DDoS protection](https://streethosting.com.br/en/guides/topics/ddos-protection) [Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flayer-3-vs-layer-4-vs-layer-7-ddos.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flayer-3-vs-layer-4-vs-layer-7-ddos.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flayer-3-vs-layer-4-vs-layer-7-ddos.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flayer-3-vs-layer-4-vs-layer-7-ddos.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flayer-3-vs-layer-4-vs-layer-7-ddos.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=Layer%203%20vs%20layer%204%20vs%20layer%207%20DDoS%3A%20what%27s%20the%20difference%3F&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flayer-3-vs-layer-4-vs-layer-7-ddos "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flayer-3-vs-layer-4-vs-layer-7-ddos "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flayer-3-vs-layer-4-vs-layer-7-ddos "Share on LinkedIn") [](https://wa.me/?text=Layer%203%20vs%20layer%204%20vs%20layer%207%20DDoS%3A%20what%27s%20the%20difference%3F%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Flayer-3-vs-layer-4-vs-layer-7-ddos "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos.md)

In this guide 7 sections

* [Why separate by layer](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#por-que-camadas)
* [Layer 3: the attack on the network](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#camada-3)
* [Layer 4: the attack on transport](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#camada-4)
* [Layer 7: the attack on the application](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#camada-7)
* [Where each layer is mitigated](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#onde-mitigar)
* [Multi-vector attacks and game servers](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#multivetor)
* [Protected infrastructure](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#infraestrutura-protegida)

Quick answer

The difference between **layer 3, 4 and 7 DDoS**is the resource each attack exhausts. Layer 3 fills the link with IP and ICMP packets. Layer 4 abuses TCP and UDP to fill up connection tables or bandwidth. Layer 7 imitates users and requests expensive tasks until the application falls over. The first two are measured in Gbps and packets per second and are mitigated at the provider's edge; the third is measured in requests per second and is handled in the proxy, the WAF and the code itself.

## Why separate by layer[](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#por-que-camadas)

The layers come from the OSI model, which divides network communication into levels. Three of them matter for DDoS. Layer 3 is the network layer, where IP and ICMP live. Layer 4 is the transport layer, with TCP and UDP. Layer 7 is the application layer: HTTP, DNS, your game's protocol, your bot's API.

Classifying an attack by layer is not pedantry. Each layer exhausts a different resource, shows up in a different metric and is defended at a different point in the infrastructure. People who mix the three up end up installing a WAF to contain a UDP flood or waiting for the network's Anti-DDoS to fix a slow search endpoint.

| Layer          | Examples                                                          | Resource exhausted                            | Metric that spikes                         |
| -------------- | ----------------------------------------------------------------- | --------------------------------------------- | ------------------------------------------ |
| 3, network     | ICMP flood, IP fragment flood, unusual IP protocols               | Link bandwidth and packet processing          | Gbps and packets per second                |
| 4, transport   | SYN flood, ACK flood, UDP flood, amplification                    | Connection tables, bandwidth and kernel CPU   | Packets per second and pending connections |
| 7, application | HTTP flood, slowloris, expensive endpoint abuse, game query flood | CPU, memory, database and application workers | Requests per second and response time      |

In practice, the question that settles the classification is simple: for this attack to work, does the application need to understand the packet? If it does not, it is layer 3 or 4. If it does, it is layer 7.

## Layer 3: the attack on the network[](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#camada-3)

A layer 3 attack wants to clog the path. It does not matter which port the packet is headed to or whether a service is listening: the damage happens earlier, on the link and the router that have to carry and process every packet.

* **ICMP flood:** a deluge of ICMP packets, like the ones from ping, that eats bandwidth and forces the system to process and answer each one.
* **Fragment flood:** fragmented IP packets that never complete. The destination holds the pieces waiting for the rest, and reassembly memory fills up. The relationship between fragmentation and packet size is covered in the guide on [what MTU is](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu).
* **Unusual IP protocols:** traffic from protocols such as GRE aimed at a server that does not even use that protocol, just to occupy the link.

Blocking all ICMP in the firewall looks like protection, but it breaks things. Path MTU discovery depends on ICMP messages, and IPv6 does not work without ICMPv6. The right move is to rate-limit ICMP, not to cut off the whole protocol.

Against layer 3, the server can do almost nothing on its own. If a 1 Gbps link receives more than 1 Gbps, the excess is lost before it reaches the operating system, and no local firewall rule comes into play.

## Layer 4: the attack on transport[](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#camada-4)

At layer 4 the attack starts exploiting how TCP and UDP work. Some vectors are still volumetric, others target the state the server and the firewall keep for each connection.

### TCP: SYN, ACK and stuck connections[](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#tcp)

TCP opens connections in three steps: the client sends a SYN, the server replies with SYN/ACK and waits for the final ACK. In a **SYN flood**, the ACK never arrives, and the server piles up half-open connections until the queue is full. In an **ACK flood**, acknowledgment packets arrive for connections that never existed, and every stateful firewall along the path has to look up its table to discard them. There are also floods of complete connections that stay open doing nothing, exhausting the service's connection limit.

On the server side, the first defense is already enabled on Ubuntu: SYN cookies, which allow replying without storing state when the queue fills up. Check it:

`sysctl net.ipv4.tcp_syncookies # 1 = enabled sysctl net.ipv4.tcp_max_syn_backlog # size of the pending connection queue cat /proc/sys/net/netfilter/nf_conntrack_max`

### UDP and amplification[](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#udp)

UDP has no handshake. Any packet to an open port goes straight to the application, which makes a **UDP flood** cheap for the attacker and hard to separate from legitimate traffic, especially on game servers, which live on UDP. With no connection to validate, the filter has to look at packet volume, size and profile, and that is only viable at scale at the network edge.

**Amplification** is the heaviest variant. The attacker sends small queries to misconfigured public servers, such as open DNS resolvers, old NTP servers, exposed memcached, SSDP and CLDAP, with your IP spoofed as the sender. The responses, far larger than the queries, all land on your link. In a traffic sample this shows up as UDP arriving from thousands of servers with the same source port, 53, 123 or 11211.

| Vector           | Protocol | What it exhausts         | Main defense                                              |
| ---------------- | -------- | ------------------------ | --------------------------------------------------------- |
| SYN flood        | TCP      | Pending connection queue | SYN cookies and SYN proxy at the edge                     |
| ACK flood        | TCP      | Firewall state table     | Stateful firewall at the edge                             |
| Connection flood | TCP      | Service connection limit | Per-IP limit and protection that understands the protocol |
| UDP flood        | UDP      | Bandwidth and kernel CPU | Filtering by port and traffic profile at the edge         |
| Amplification    | UDP      | Link bandwidth           | Filtering by source port and volume at the edge           |

## Layer 7: the attack on the application[](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#camada-7)

At layer 7 the attack speaks the application's language. Every request looks like it came from an ordinary user, and the network volume can be small. The goal is to make the server burn CPU, memory and database queries until it cannot serve anyone else.

* **HTTP flood:** thousands of GET or POST requests per second. Variants with random URL parameters are used to bypass the cache and force the origin to answer everything.
* **Slowloris and slow POST:**connections that send headers or body at an extremely slow pace and keep occupying the web server's workers.
* **Expensive endpoint abuse:** search without an index, login with a heavy password hash, report generation, an API without pagination. A few requests per second are enough to take it down.
* **Game protocol:**status query floods, fake login attempts and packets that exploit the server's logic.

The defense starts at the reverse proxy. In Nginx, limit requests and connections per IP on sensitive routes and shorten the timeouts, which neutralizes most of slowloris:

`# /etc/nginx/nginx.conf, inside the http block limit_req_zone $binary_remote_addr zone=porip:10m rate=10r/s; limit_conn_zone $binary_remote_addr zone=conexoes:10m; limit_req_status 429; client_header_timeout 10s; client_body_timeout 10s; keepalive_timeout 15s; # in the site's server block location /login { limit_req zone=porip burst=20 nodelay; limit_conn conexoes 20; proxy_pass http://127.0.0.1:3000; }`

After the proxy come the WAF, which filters malicious request patterns, and the application itself: cache for whatever is expensive, authentication before heavy operations, mandatory pagination and queues for long tasks. A deeper look at this layer is in [layer 7 DDoS](https://streethosting.com.br/en/guides/infrastructure/layer-7-ddos-attack) and the role of the WAF in [what a WAF is and when to use one](https://streethosting.com.br/en/guides/infrastructure/what-is-a-waf).

## Where each layer is mitigated[](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#onde-mitigar)

Think of the infrastructure as a funnel. Each point can only defend what reaches it, and the attack has to be stopped at the first point that has the capacity for it.

| Defense point         | Layers it covers                    | Who controls it        | Limit                               |
| --------------------- | ----------------------------------- | ---------------------- | ----------------------------------- |
| Provider edge         | 3 and 4, volumetric and state-based | Provider               | Cannot see your application's logic |
| Server firewall       | 4 at low volume, surface reduction  | You                    | Useless if the link is already full |
| Reverse proxy and WAF | 7 over HTTP                         | You or a proxy service | Does not protect UDP game ports     |
| Application           | 7, cost of each request             | You                    | Depends on code and architecture    |

The provider's edge absorbs the volume, discards whatever does not have a legitimate profile and hands clean traffic to your machine. As a last resort, some providers null-route the attacked IP to protect the rest of the network, which takes the service offline. That is why it pays to ask before signing up how the mitigation works and whether it covers TCP and UDP on the ports you use.

The server firewall does not hold back volume, but it decides what stays exposed. Every port open without need is one more target. The split of responsibilities between network and application firewalls is in [network vs application firewall](https://streethosting.com.br/en/guides/infrastructure/network-firewall-vs-application-firewall).

To find out which layer is being attacked on your server, the combination of bandwidth, packets per second, pending connections and the access log almost always answers it. The walkthrough with commands is in [how to identify a DDoS attack](https://streethosting.com.br/en/guides/infrastructure/detect-ddos-attack-on-server).

## Multi-vector attacks and game servers[](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#multivetor)

Real attacks rarely stay on a single layer. It is common to see a UDP flood on the game port at the same time as an HTTP flood on the website and a SYN flood on the panel, or a vector switch every few minutes to test which defense gives way first.

Game servers have an aggravating factor: the legitimate traffic is UDP, continuous and latency-sensitive. Web proxies, which work very well for HTTP, do not understand that traffic, so the game port depends on edge protection that knows the protocol's profile. The website, the store and the panel, on the other hand, can sit behind a proxy and a WAF.

* Game port on an IP with edge protection that covers UDP
* Website, store and panel behind a reverse proxy with request limits
* Admin panel off the public internet, over VPN or a tunnel
* Server firewall allowing only the ports in use
* Expensive endpoints with cache, authentication or a queue

## Protected infrastructure[](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#infraestrutura-protegida)

Layers 3 and 4 are only truly mitigated before your server, and that is the responsibility of whoever operates the network. At StreetHosting, Anti-DDoS is included with VPS and dedicated servers, with a data center in São Paulo, and it filters traffic before it reaches your machine. Layer 7 of your website is still yours: a well-configured Nginx, WAF and code complete the defense. Network details are on the [StreetHosting infrastructure page](https://streethosting.com.br/en/infraestructure).

| Option                   | Protection          | Network           | Starting at                                        |
| ------------------------ | ------------------- | ----------------- | -------------------------------------------------- |
| Xeon VPS                 | AntiDDoS Enterprise | 1 Gbps uplink     | R$ 26.00 per month (2 vCPU, 2 GB)                  |
| Ryzen 9 9950X VPS        | Anti-DDoS included  | 1 Gbps uplink     | R$ 40.00 per month (1 vCPU, 2 GB DDR5)             |
| AMD Budget SM dedicated  | AntiDDoS Gamer      | Dedicated 10 Gbps | R$ 1,499.00 per month (Ryzen 9 5900XT, 64 GB)      |
| AMD Extreme SM dedicated | AntiDDoS Gamer      | Dedicated 10 Gbps | R$ 2,229.00 per month (Ryzen 9 9950X, 128 GB DDR5) |

For communities and projects that already face frequent attacks, the [dedicated servers](https://streethosting.com.br/en/dedicated) combine the edge protection with a 10 Gbps port of their own, which leaves link headroom for legitimate traffic. To start smaller, the [VPS plans with Anti-DDoS included](https://streethosting.com.br/en/vps) activate within 60 seconds and give you root access to configure the firewall, proxy and application your way.

In this guide

* [Why separate by layer](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#por-que-camadas)
* [Layer 3: the attack on the network](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#camada-3)
* [Layer 4: the attack on transport](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#camada-4)
* [Layer 7: the attack on the application](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#camada-7)
* [Where each layer is mitigated](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#onde-mitigar)
* [Multi-vector attacks and game servers](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#multivetor)
* [Protected infrastructure](https://streethosting.com.br/en/guides/infrastructure/layer-3-vs-layer-4-vs-layer-7-ddos#infraestrutura-protegida)

## Frequently asked questions

What is the difference between layer 3, 4 and 7 DDoS attacks?

A layer 3 attack hits the network with a volume of IP and ICMP packets until the link is full. A layer 4 attack abuses TCP and UDP to exhaust connection tables or bandwidth. A layer 7 attack imitates users and asks the application for expensive tasks, taking the service down with very little traffic.

Which type of DDoS is the most dangerous?

It depends on the defense you have. Without protection at the provider's edge, a volumetric layer 3 or 4 attack takes everything down, because nothing running on your machine can hold back a saturated link. With the edge protected, layer 7 usually causes more trouble, because it looks like legitimate traffic and requires tuning in the application.

Does the VPS firewall stop a layer 4 attack?

Only small ones. SYN cookies, rate-limit rules and a properly sized connection table handle modest floods. Once the volume exceeds the link's capacity, packets are lost before they reach the local firewall, and mitigation has to happen on the provider's network.

Do game servers suffer layer 7 attacks?

They do. For a game, layer 7 is the game protocol itself, so status query floods, fake login attempts and packets that exploit the server's logic count as layer 7. The community's website, store and web panel are common targets too.

Is DNS amplification a layer 3, 4 or 7 attack?

It abuses an application protocol, but the effect on the target is volumetric: large UDP responses arrive and fill the link. That is why most classifications place amplification among layer 3 and 4 attacks, mitigated at the edge.

Next step

Explore the infrastructure

Datacenter in São Paulo, gamer network and options for high-demand projects.

[Explore the infrastructure](https://streethosting.com.br/en/infraestructure)

[See dedicated servers Exclusive hardware in São Paulo with NVMe and Anti-DDoS.](https://streethosting.com.br/en/dedicated) [See VPS plans Root VPS in Brazil with NVMe and Anti-DDoS.](https://streethosting.com.br/en/vps)

## Related guides

[Infrastructure Intermediate How to detect a DDoS attack on your server: Linux diagnosis General lag, players dropping and a sluggish SSH session can be a DDoS or just an overloaded server. Here are the symptoms, the commands that confirm the attack and what to send to support without wasting time. 9 min Read guide](https://streethosting.com.br/en/guides/infrastructure/detect-ddos-attack-on-server) [Infrastructure Advanced Layer 7 DDoS: what an application layer attack is and how to mitigate it A volumetric DDoS clogs your bandwidth. A layer 7 attack is subtler: it mimics real users to exhaust the server's CPU and queue with little traffic. Here is why it fools filters and how to mitigate it. 3 min Read guide](https://streethosting.com.br/en/guides/infrastructure/layer-7-ddos-attack) [Infrastructure Beginner What is a DDoS attack on a game server? Explained DDoS is not ordinary lag, and it is not a crash caused by a badly written plugin. It is a coordinated campaign to flood the network or the CPU until nobody can connect. This guide explains the attack in plain language and what your community should expect from real mitigation. 6 min Read guide](https://streethosting.com.br/en/guides/infrastructure/what-is-a-ddos-attack-game-server)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
