# Obsidio > Swiss DDoS resilience platform. Controlled, realistic DDoS simulations against your own infrastructure with 100,000+ distributed devices and audit-ready reports for FINMA, DORA, and NIS2. ## Pages - [Home](https://obsidio.com/): Obsidio is a Swiss DDoS resilience platform. Run controlled, real-world DDoS simulations against your own infrastructure with 100,000+ distributed devices and audit-ready reports aligned to FINMA, DORA, and NIS2. - [About](https://obsidio.com/about/): Obsidio is built and operated in Switzerland by Papers AG. Independent, neutral, FINMA-aligned. Our mission: turn resilience testing into measurable, verifiable assurance. - [Accessibility Statement](https://obsidio.com/accessibility/): Obsidio accessibility statement. WCAG 2.2 AA conformance status, ongoing measures, known issues, and how to report accessibility barriers. - [Benefits](https://obsidio.com/benefits/): Compliance-ready reporting, unmatched realism via 100,000+ real devices, Swiss independence, and self-service testing — why leading institutions choose Obsidio. - [Blog](https://obsidio.com/blog/): Practical guidance on DDoS resilience testing, FINMA, DORA and NIS2 compliance, and what realistic attack simulation reveals about your defenses. - [Brand Assets](https://obsidio.com/brand-assets/): Official Obsidio brand assets for partners, press, and integrations: logo variants, brand colors, and wallpapers. - [Contact](https://obsidio.com/contact/): Talk to the Obsidio team. Demos, technical support, and guidance on audit-ready resilience reporting for FINMA, DORA, and NIS2. - [Cookie Policy](https://obsidio.com/cookie-policy/) - [FAQ](https://obsidio.com/faq/): Answers to the most common questions about Obsidio: what it is, who needs DDoS simulations, how authorization works, what evidence you receive, and how it supports compliance. - [Imprint](https://obsidio.com/imprint/): Imprint and regulatory information for Obsidio, operated by Papers AG, Zug, Switzerland. - [Industries](https://obsidio.com/industries/): Obsidio supports banks, insurers, financial market infrastructures, energy, telecom, healthcare, and public services with realistic, repeatable DDoS simulations. - [Privacy Policy](https://obsidio.com/privacy-policy/): How Papers AG processes personal data when you use the Obsidio website and platform. FADP and GDPR compliant. - [Product](https://obsidio.com/product/): Obsidio simulates real-world DDoS pressure in a controlled, ethical, verifiable way. Dashboards, simulation types, and audit-ready reports for CISOs and compliance teams. - [Terms & Conditions](https://obsidio.com/terms-conditions/): Terms and conditions governing access to and use of the Obsidio website and platform operated by Papers AG. ## Blog - [Arten von DDoS-Angriffen: Die vollständige Taxonomie](https://obsidio.com/de/arten-von-ddos-angriffen/): Was DDoS-Angriffe sind und welche Arten es gibt: volumetrisch, Protokoll, Anwendungsebene und Slow – und welche Typen sich wirklich testen lassen. - [SYN Flood Attack: How It Works, and What It Cannot Test](https://obsidio.com/syn-flood-attack/): A SYN flood attack fills the TCP backlog with half-open connections. How SYN cookies, backlog tuning and edge SYN proxying stop it, and what they miss. - [DORA Compliance: What the Testing Pillar Actually Requires](https://obsidio.com/dora-compliance/): DORA compliance explained: who is in scope, the five pillars, yearly resilience testing under Article 24, TLPT every three years, and audit-ready evidence. - [Types of DDoS Attacks: The Complete Taxonomy](https://obsidio.com/types-of-ddos-attacks/): Volumetric, protocol, application-layer, slow: the four classes of DDoS attacks, and which types of DDoS attacks you can actually test. - [DDoS Stress Test: What It Is, When It’s Legal, and How a Real One Runs](https://obsidio.com/ddos-stress-test/): What a DDoS stress test is, why authorized testing of your own systems is legal, how it differs from a load test, and how a proper run works. - [What Is a Botnet? How Hijacked Devices Power DDoS Attacks](https://obsidio.com/what-is-a-botnet/): What is a botnet? How malware turns routers, cameras and TVs into DDoS weapons, from Mirai's 600,000 devices to the 31.4 Tbps AISURU record. - [Puppeteer Script Testing: How It Works and What It Measures](https://obsidio.com/puppeteer-script-testing/): Puppeteer Script runs your own browser journey on every worker at once. Synthetic user testing that reaches the app tier, session store and database. - [TCP Connection Flood: How It Works and How to Test Your Defenses](https://obsidio.com/tcp-connection-flood/): A TCP connection flood holds idle sockets to exhaust your connection table, file descriptors and accept queue. What to check, and how to test it properly. - [TLS Flood: How It Works and How to Test Your Defenses](https://obsidio.com/tls-flood-attack/): A TLS flood completes the full handshake, then abandons the connection. Your WAF sees nothing. What breaks, how to defend it, and how to test it safely. - [RUDY Attack: How It Works and How to Test Your Defenses](https://obsidio.com/rudy-attack/): A RUDY attack sends a valid POST with an honest Content-Length, then trickles the body one byte at a time. Why your WAF sees nothing, and how to test it. - [Apache Killer (CVE-2011-3192): How It Works and How to Test](https://obsidio.com/apache-killer-attack/): Apache Killer (CVE-2011-3192) drains a vulnerable Apache server's memory with one crafted Range header. How it works, how to defend, how to test. - [Browser Flood: How It Works and How to Test Your Defenses](https://obsidio.com/browser-flood-attack/): Browser Flood drives real Chromium tabs at your site, so bot detection and JavaScript challenges cannot tell it from genuine users. How to test it safely. - [GoldenEye Attack: How It Works and How to Test Your Defenses](https://obsidio.com/goldeneye-attack/): A GoldenEye DDoS attack randomises query strings so every request misses your cache and reaches origin. What your CDN config decides, and how to test it. - [HTTP Flood Attack: How It Works and How to Test Your Defenses](https://obsidio.com/http-flood-attack/): An HTTP flood attack sends valid requests at volume. Which controls stop it, the nginx and Apache limits that decide it, and how to test for real. - [Slowloris Attack: How It Works and How to Test Your Defenses](https://obsidio.com/slowloris-attack/): How a Slowloris attack exhausts a server's connection pool at almost no bandwidth, the four slow vectors, and how to test your own timeouts. - [How to Test Your DDoS Protection](https://obsidio.com/how-to-test-ddos-protection/): How to test your DDoS protection safely: the attack types to cover, an authorization-first method, and audit-ready FINMA, DORA and NIS2 evidence. ## See also - [Full content as markdown](https://obsidio.com/llms-full.txt)