Layer 7 (application layer) DDoS attacks target the highest level of the OSI model, where your web application processes requests. Unlike Layer 3/4 attacks that aim to saturate bandwidth or exhaust network resources, Layer 7 attacks exploit the computational cost of processing legitimate-looking requests. A single HTTP request might consume milliseconds of CPU time and multiple database queries, making it possible to overwhelm a server with relatively few requests per second.
Common Layer 7 attack types include HTTP GET/POST floods that send thousands of valid-looking requests per second, slowloris attacks that hold connections open with partial headers, slow-read attacks that download responses at an extremely slow rate, and targeted attacks against resource-intensive endpoints like search functions, login pages, and API endpoints.
These attacks are particularly dangerous because they often fly under the radar of network-layer DDoS protection. The attack traffic consists of valid HTTP requests from real IP addresses (often compromised machines or residential proxies), making it indistinguishable from legitimate traffic at the packet level. Effective Layer 7 protection requires application-level intelligence.