It’s not used because any serious attack is going to come from multiple unrelated sources, think a botnet full of compromised IoT devices hitting your server with 20TB a second worth of requests. So you might as well plan for that scenario instead.
If however your DOS attack is an attacker making lower-volume CPU-expensive requests on your site, there's plenty of things to help mitigate the assault.
Sadly DDoS has at times been used as a blanket term that also includes DoS.
There is no 100% secure system.
https://www.cloudflare.com/learning/ddos/famous-ddos-attacks...