The idea behind security tests is easy. You want to know what a hacker can do - you hire a security expert who acts like a hacker to see how far he can get. You want to know what an evil admin can do - your security experts gets admin privileges and does his job that way.
I am aware that there are other and maybe better ways to perform an audit, but these are common approaches that work. Unfortunately it gets difficult when the threat is not a single person or a team of hackers, but a distributed bot-network that spams you with more or less intelligent requests. How can you test such a scenario? Lets say I have my infrastructure ready and I am confident that my systems can withstand a certain amount of pressure from a DDoS attack. Now I want to verify my expectations and perform a DDoS test from the Internet.
Where can I legally get a DDoS simulator? I do not want to buy resources from an illegal bot-net and I only want to work with experts in this field. Are there companies who perform such tests for you or can you at least rent systems that are powerful enough to simulate a DDoS attack? I am aware of the legal issues like informing all involved parties like providers and the like - this question is focused on how such a test can be performed. I am also not looking for a list of companies that can do that, I am interested what is state of the art in this field and which services are available on the market.