DDoS Protection service monitors the traffic utilization and if it is found that there are multiple request (longer than usual) are happening, DDoS is detected and mitigation for it is initiated.
There are other ways hot these attacks are identified and how actions are taken later. You will have to read through below document and also refer index page on the left side to find more details
https://video2.skills-academy.com/en-us/azure/ddos-protection/ddos-protection-standard-features
----------
Please don't forget to Accept Answer and Up-vote if the response helped -- Vaibhav