DDoS Threat Intelligence
Amplification Attacks Explained
Amplification attacks are a type of volumetric attack that exploit publicly accessible servers to multiply attack traffic.
How Amplification Works
The Basic Concept:
- Attacker sends small request with spoofed source IP (victim's IP)
- Server responds with much larger reply to the victim
- Amplification factor: Response is 10x-1,000x+ larger than request
- Result: Small botnet generates massive attack traffic
Why It's Effective:
- Attacker uses minimal bandwidth
- Victim receives overwhelming traffic
- Responses come from legitimate servers (harder to block)
Common Amplification Attack Types
DNS Amplification
- Amplification Factor: 28x - 54x
- How: Query for large DNS records (ANY query)
- Response: Large DNS response to victim
- Mitigation: Rate limiting, response size limiting, blocking ANY queries
NTP Amplification
- Amplification Factor: 556x
- How: MON_GETLIST command to NTP servers
- Response: List of last 600 hosts that connected
- Mitigation: Disable MON_GETLIST, update NTP software
SNMP Amplification
- Amplification Factor: 650x - 1,000x+
- How: GetBulk request to network devices
- Response: Large configuration data dumps
- Mitigation: Disable public SNMP, use SNMPv3, access control
SSDP Amplification
- Amplification Factor: 30x - 50x
- How: Discovery requests to UPnP devices
- Response: Device information
- Mitigation: Disable UPnP on Internet-facing devices
CLDAP Amplification
- Amplification Factor: 56x - 70x
- How: Queries to Connectionless LDAP servers
- Response: Directory information
- Mitigation: Restrict CLDAP access, disable if not needed
Why Amplification Attacks Are Dangerous
- Easy to execute: Don't need large botnets
- Hard to trace: Traffic comes from legitimate servers
- Massive scale: Can generate Tbps-level attacks
- Widely available: Many vulnerable servers exist on the Internet
Defense Strategy
- Upstream filtering: Block amplified traffic before it reaches you
- Cloud scrubbing: Absorb and filter amplified traffic at scale
- Source validation: Implement BCP 38 (prevent IP spoofing)
- Server hardening: Secure your own servers so they're not used as amplifiers
Pronto para proteger seus ativos da Web?
Proteja sua infraestrutura crítica sem esforço com a proteção contra DDoS confiável e fácil de gerenciar da Nexusguard. Fale com um de nossos especialistas em segurança de rede para saber como podemos simplificar suas operações de segurança e proporcionar tranquilidade.
Fale com nosso especialista em segurança de rede

