On a global scale this would mean that the one big DDoS you'd expect to see effectively gets split into many tiny DDoSes, which Google can handle using methods mentioned in the other responses in this thread.
It would be interesting to see how often people try though.
Google has been buying up 'dark fiber' for years and has thousands of miles of cable connecting their data centers.
They can certainly handle petabit/s levels of traffic inside the datacenter[1], it's not that much of a stretch to think that they can handle double digit terabit/s through their collective external fiber links.
Also, just think about their normal level of operation. Even just all the Android devices feeding data back and forth, let alone analytics, maps, gmail, search etc etc. They've got 36 data centers and co-locate in more than 60 public exchanges (and that was in 2010!), not to mention the Google Global Cache (GGC) servers inside consumer networks across the globe.
Their scale is ridiculously large. I suspect that they actually can't be DDoS'd in the normal 'chuck traffic at them' sense.
[0] http://www.theregister.co.uk/2010/03/17/the_size_of_the_goog...
[1] http://googlecloudplatform.blogspot.co.uk/2015/06/A-Look-Ins...
Of course our growth strategy is quality (people willing to pay for a good service quid-pro-quo) over quantity (free service and monetise later via ads/analytics), so we've had a slow steady growth for the entire 15 years we've been operating rather than the viral growth and sell-out/pivot that unicorns are known for.
People like Ford and Edison used to believe that you could get more quality as volume increased. And in fact, if you wanted to increase quality, then you had to increase volume.
And I do agree to a point. We're very happy to have increasing numbers of users so we can afford to do things like contracting the excellent developer who's working on JMAP support for Calendars in Cyrus IMAP at the moment, as well as hiring people to add new features or improve existing ones.
We do try to stay at a point where we can run comfortably on 50% of our hardware, so we can shut down half our machines at once for maintenance. Redundancy certainly helps - we've blogged a few times about how good it is to be able to shut down any one machine with only a few minutes' warning to move active users off it.
I'm certainly looking forward to spending time again on what I wanted to be doing (Cyrus IMAPd improvements at the moment) rather than battling a DDoS!
- Build defenses against DDoS into its networks
- Have large enough capacity that such attacks are less effective anyway