> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What Radio Jamming Taught Me About DDoS
- URL: https://www.cybrsecmedia.com/what-radio-jamming-taught-me-about-ddos/
- Published: 2026-08-31T15:00:11.000Z
- Updated: 2026-08-31T15:01:56.000Z
- Description: From Army signal intelligence and radio jamming to modern DDoS defense, the same lessons in reconnaissance, timing, disruption and adaptation reveal how attackers overwhelm networks — and how defenders can stay ahead.
- Author: Michael Smith
- Tags: Adventures in Threat Hunting, CYBR.SEC.Community, blog

At 17, I joined the US Army as a way out of Idaho. I spent 8 years on active duty working in signal intelligence, specializing in radio intercept, direction-finding, and jamming. It was highly technical, demanding work that required both sharp analytical thinking and a deep understanding of how communication systems operate under pressure. Now decades later, looking back, I'm amazed at how many of the core principles I learned in that field translate directly to network security.

At its core, communication is communication: whether it's a line-of-sight radio signal or a packet traveling across a fiber-optic network, the same fundamental rules apply. Today, I want to focus on some of the key lessons I learned from jamming radios and how they can inform modern DDoS defense strategies.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

## You Block the Receiver, not the Sender

In radio jamming, you target the receiver, not the sender. Your jamming has to be louder than the real sender at the point of reception. Senders will continue transmitting traffic regardless of your RF onslaught.

In a DDoS attack, the attacker's objective is to prevent that traffic from ever reaching its intended destination. Web browsers and email clients keep sending packets to a targeted server, but those packets can't get through because the attacker's traffic exceeds what the server and its infrastructure can handle.

The obvious implication for defenders is that you mitigate DDoS traffic at or near the destination rather than at the source. Cleaning up DDoS sources takes time and a community effort because they're... distributed.

## Effective Disruption Requires Good Reconnaissance

Before you start to disrupt communications, you need a map of targets and capabilities. This means that you have to conduct reconnaissance. In jamming, this is a list of frequencies, physical locations, and callsigns.

When you are a DDoS'er and want to launch and sustain an effective attack campaign over a longer period, you have to know your target's attack surface. This involves identifying:

- Domains, websites, and other services owned by the target
- IP addresses and network blocks on which services reside
- Hosting, cloud, and other providers
- DNS providers
- DDoS mitigation providers
- Dynamic web applications and APIs
- Large website objects such as PDFs and MS Word documents

Once you have a map of the target organization and an idea of what attack payloads they are susceptible to, you can change the attack vector, the target, and the timing to evade mitigation and

## Timing is Everything

Jamming is most effective when used in conjunction with a major operation, such as an attack, when communication is more important. You're blocking calls for artillery fire or the call for reinforcements, and this gives you numerical superiority at the point of attack. If you jam during a quiet time, it's both easier to evade the jamming and to locate and destroy the jammer.

DDoS by itself during a relatively quiet time is not as critical. If you sustain an outage but none of your users are awake to notice, did you really take an outage? It might require escalation to an on-call group and, over time, wear down your operations staff. But generally, you invest your resources in mitigation and survive to fight another day.

However, DDoS attacks are most effective when combined with other factors: the peak holiday shopping season, geopolitical events, other hacktivist attacks, ransomware infections, or data breaches. This forces the security and operations group to make tough decisions. Fight the data breach or restore website availability? How can you mitigate a DDoS attack while avoiding the risk of filtering out real users who are making online purchases?

## Effectiveness Monitoring

Jamming also blocks your own reception of the target signal. You can't jam and listen to the target at the same time. You need another platform to monitor the target and tell whether your jamming is effective. This allows you to adjust the attack by increasing power, altering your technique, changing the antenna's direction, or choosing a different target.

Likewise, in a DDoS world, you can't monitor your target for availability and launch DDoS attacks from the same platform. The DDoS activity drowns out your own Internet traffic. Most intelligent DDoSers use a monitoring system, such as Is It Down, Down Detector, Pingdom, or others, to determine whether their attack is effective or needs adjustment. They then adjust the attack by increasing the number of attacking bots, altering the attack technique, or changing the target.

## Use the Minimum Power to Be Effective

A radio jammer is a huge beacon for direction-finding equipment, which leads to its eventual destruction. As a result, we use the minimum amount of power to achieve our disruption goals. You start small and then increase the intensity until you can tell that you are disrupting communications. In the best jamming attacks, the target doesn't even know that they are being intentionally jammed.

When a node (a bot) in a DDoS platform is used, it sends a strong signal to the network owner that a compromised machine on their network needs to be shut down. And when a DDoS platform grows too large and too powerful, it becomes a priority for law enforcement in a takedown operation.

As a result, you always want to use the minimum resources to disrupt your target. Using stealthier attacks first, such as Slowloris or RUDY, can cause outages without defenders knowing they are under attack. You can increase your effectiveness using your target list from reconnaissance, availability monitoring, application-layer attacks, multi-vector attacks, and carpet-bombing techniques. And finally, you can increase the number of bots and each bot's output to overwhelm the target. 

## Target Reacquisition

When being jammed, good radio operators jump to alternate frequencies to evade the attack. As an attacker, you need to reacquire the frequencies that they are now using and attack those. You might chase the target across up to 15 different frequencies. This also fragments the defenders across multiple frequencies, a secondary goal that can further enhance the impact of jamming.

During a DDoS attack or a longer campaign, defenders on-ramp assets to the mitigation infrastructure and start mitigating the attack. Persistent attackers will then work to identify targets that are not being defended or to find attacks that evade mitigation.

And just like in jamming, if the DDoS'er can keep the targets constantly on-ramping and off-ramping, it adds confusion. This creates opportunities for misconfigurations that magnify the attack's impact.

## Effective Jamming and DDoS Takes Effort

Both radio jamming and DDoS attacks are often seen as simple, low-skill threats. In reality, successful disruption campaigns demand persistence, adaptability, and precision. Attackers must constantly monitor and respond to defensive strategies, whether that means evading changes in frequency or bypassing mitigation measures.

The good news is that all the efforts we have discussed in this blog post leave traces. Threat intelligence teams can use attacker Tactics, Techniques, and Procedures (TTPs) to detect threats early and strengthen defenses before an attack takes hold.

Understanding the parallels between jamming and DDoS is more than an academic exercise. It offers practical insight into how attackers think and operate, helping defenders stay one step ahead.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)