DDoS Threat Intelligence

Amplification Attacks Explained

Under Amplification Attacks Explained
No items found.
Share to:

Amplification attacks are a type of volumetric attack that exploit publicly accessible servers to multiply attack traffic.

How Amplification Works

The Basic Concept:

  • Attacker sends small request with spoofed source IP (victim's IP)
  • Server responds with much larger reply to the victim
  • Amplification factor: Response is 10x-1,000x+ larger than request
  • Result: Small botnet generates massive attack traffic

Why It's Effective:

  • Attacker uses minimal bandwidth
  • Victim receives overwhelming traffic
  • Responses come from legitimate servers (harder to block)

Common Amplification Attack Types

DNS Amplification

  • Amplification Factor: 28x - 54x
  • How: Query for large DNS records (ANY query)
  • Response: Large DNS response to victim
  • Mitigation: Rate limiting, response size limiting, blocking ANY queries

NTP Amplification

  • Amplification Factor: 556x
  • How: MON_GETLIST command to NTP servers
  • Response: List of last 600 hosts that connected
  • Mitigation: Disable MON_GETLIST, update NTP software

SNMP Amplification

  • Amplification Factor: 650x - 1,000x+
  • How: GetBulk request to network devices
  • Response: Large configuration data dumps
  • Mitigation: Disable public SNMP, use SNMPv3, access control

SSDP Amplification

  • Amplification Factor: 30x - 50x
  • How: Discovery requests to UPnP devices
  • Response: Device information
  • Mitigation: Disable UPnP on Internet-facing devices

CLDAP Amplification

  • Amplification Factor: 56x - 70x
  • How: Queries to Connectionless LDAP servers
  • Response: Directory information
  • Mitigation: Restrict CLDAP access, disable if not needed

Why Amplification Attacks Are Dangerous

  • Easy to execute: Don't need large botnets
  • Hard to trace: Traffic comes from legitimate servers
  • Massive scale: Can generate Tbps-level attacks
  • Widely available: Many vulnerable servers exist on the Internet

Defense Strategy

  • Upstream filtering: Block amplified traffic before it reaches you
  • Cloud scrubbing: Absorb and filter amplified traffic at scale
  • Source validation: Implement BCP 38 (prevent IP spoofing)
  • Server hardening: Secure your own servers so they're not used as amplifiers

Ready to Safeguard Your Web Assets?

Protect your critical infrastructure effortlessly with Nexusguard’s reliable and easy-to-manage DDoS protection. Speak with one of our network security experts to learn how we can simplify your security operations and give you peace of mind.
Talk to Our Network Security Expert