DDoS Threat Intelligence
Amplification Attacks Explained
Amplification attacks are a type of volumetric attack that exploit publicly accessible servers to multiply attack traffic.
How Amplification Works
The Basic Concept:
- Attacker sends small request with spoofed source IP (victim's IP)
- Server responds with much larger reply to the victim
- Amplification factor: Response is 10x-1,000x+ larger than request
- Result: Small botnet generates massive attack traffic
Why It's Effective:
- Attacker uses minimal bandwidth
- Victim receives overwhelming traffic
- Responses come from legitimate servers (harder to block)
Common Amplification Attack Types
DNS Amplification
- Amplification Factor: 28x - 54x
- How: Query for large DNS records (ANY query)
- Response: Large DNS response to victim
- Mitigation: Rate limiting, response size limiting, blocking ANY queries
NTP Amplification
- Amplification Factor: 556x
- How: MON_GETLIST command to NTP servers
- Response: List of last 600 hosts that connected
- Mitigation: Disable MON_GETLIST, update NTP software
SNMP Amplification
- Amplification Factor: 650x - 1,000x+
- How: GetBulk request to network devices
- Response: Large configuration data dumps
- Mitigation: Disable public SNMP, use SNMPv3, access control
SSDP Amplification
- Amplification Factor: 30x - 50x
- How: Discovery requests to UPnP devices
- Response: Device information
- Mitigation: Disable UPnP on Internet-facing devices
CLDAP Amplification
- Amplification Factor: 56x - 70x
- How: Queries to Connectionless LDAP servers
- Response: Directory information
- Mitigation: Restrict CLDAP access, disable if not needed
Why Amplification Attacks Are Dangerous
- Easy to execute: Don't need large botnets
- Hard to trace: Traffic comes from legitimate servers
- Massive scale: Can generate Tbps-level attacks
- Widely available: Many vulnerable servers exist on the Internet
Defense Strategy
- Upstream filtering: Block amplified traffic before it reaches you
- Cloud scrubbing: Absorb and filter amplified traffic at scale
- Source validation: Implement BCP 38 (prevent IP spoofing)
- Server hardening: Secure your own servers so they're not used as amplifiers
Ready to Safeguard Your Web Assets?
Protect your critical infrastructure effortlessly with Nexusguard’s reliable and easy-to-manage DDoS protection. Speak with one of our network security experts to learn how we can simplify your security operations and give you peace of mind.
Talk to Our Network Security Expert

Topic You May Interest In
Cost of DDoS Attack
No items found.
