Self-Inflicted Denial of Service (Self-DDoS) in Distributed Systems, Mechanisms and Mitigating Architectural Strategies: When a System "Attacks" Itself, An Analysis of Retry Storms, Thundering Herds, and Cascading Failure

Authors

  • Tengo Gelishvili Master of Information Systems Management (DevOps), Business and Technology University, Tbilisi, Georgia Author
  • Giorgi Kuchava PhD (Engineering of Informatics), Associate professor, Georgian Technical University, Tbilisi, Georgia Author
  • Teimuraz Sturua Candidate of Technical Sciences, Associate professor, Georgian Technical University, Tbilisi, Georgia Author

Keywords:

self-DDoS, Classic DDoS, Botnet, chaos engineering, Chaos Monkey, Chaos Mesh, Web Application Firewall, Thundering Herds, LitmusChaos

Abstract

"Self-DDoS" (self-inflicted denial of service) describes the phenomenon in which a distributed system, absent any external attacker, achieves the same outcome as a targeted DDoS attack, full or partial unavailability of service purely as a consequence of its own architectural flaws. This paper examines five core mechanisms: the retry storm, the thundering herd, cascading failure, the autoscaling feedback loop, and the cache stampede. For each mechanism a schematic diagram is provided, together with the corresponding mitigation pattern  exponential backoff with jitter, the circuit breaker, bulkhead isolation, rate limiting, and load shedding. The mechanisms are further illustrated through a controlled fault-injection experiment on a Kubernetes test cluster, comparing fixed-interval and jittered-backoff retry policies under simulated downstream latency.

Downloads

Download data is not yet available.

References

თ. გელიშვილი, "ქაოსის ინჟინერიის გამოყენება კიბერუსაფრთხოების სისუსტეების გამოვლენაში," ბაკალავრიატის/მაგისტრატურის ნაშრომი, ბიზნესისა და ტექნოლოგიების უნივერსიტეტი, თბილისი, საქართველო, 2026, 57 გვ.

M. T. Nygard, Release It!: Design and Deploy Production-Ready Software. Raleigh, NC: The Pragmatic Bookshelf, 2007, 350 pp.

M. Fowler, "CircuitBreaker," martinfowler.com, 2014. Available: https://martinfowler.com/bliki/CircuitBreaker.html

Netflix Technology Blog, "Introducing Hystrix for resilience engineering," Netflix Tech Blog, 2012.

A. Basiri, N. Behnam, R. de Rooij, L. Hochstein, L. Kosewski, J. Reynolds, and C. Rosenthal, "Chaos engineering," IEEE Software, vol. 33, no. 3, pp. 35–41, 2016.

B. Beyer, C. Jones, J. Petoff, and N. R. Murphy, Site Reliability Engineering: How Google Runs Production Systems. Sebastopol, CA: O'Reilly Media, 2016, 550 pp.

LitmusChaos Documentation, CNCF LitmusChaos Project. Available: https://litmuschaos.io

Downloads

Published

02-08-2026

How to Cite

Self-Inflicted Denial of Service (Self-DDoS) in Distributed Systems, Mechanisms and Mitigating Architectural Strategies: When a System "Attacks" Itself, An Analysis of Retry Storms, Thundering Herds, and Cascading Failure. (2026). Computational and Applied Science, 1(2), 141-148. https://casjournal.ge/index.php/cas/article/view/18