πŸ”„ Topic

Understanding denial-of-service attacks, including floods, reflection, amplification, and Smurf attacks.


🎯 Goal

Learn how different DoS and DDoS attacks work and how defenders can recognize them in traffic patterns and logs.


πŸ›  What I Did

Today I studied several denial-of-service attack types:

  • ICMP flood
  • UDP flood
  • DNS amplification
  • NTP amplification
  • TCP SYN flood
  • Smurf attack

The core idea is that the attacker tries to make a system, service, or network unavailable.

They may exhaust:

  • bandwidth
  • CPU
  • memory
  • connection tables
  • firewall capacity
  • application resources
  • DNS infrastructure
  • load balancer capacity

A simple ICMP flood may look like many ping requests hitting the same victim.

Example:

Time        Source IP       Destination IP   Protocol   Info
12:01:01    203.0.113.10    192.0.2.50      ICMP       Echo request
12:01:01    203.0.113.11    192.0.2.50      ICMP       Echo request
12:01:01    203.0.113.12    192.0.2.50      ICMP       Echo request
12:01:01    203.0.113.13    192.0.2.50      ICMP       Echo request

A SYN flood is different.

It abuses the TCP handshake by sending many SYN packets without completing the connection.

Example:

Client sends SYN
Server replies SYN-ACK
Client never completes ACK
Server resources remain half-open

At scale, this can exhaust connection handling resources.


πŸ”— Key Cybersecurity Connections

The important correction today was that not all DoS attacks work the same way.

Some are direct floods.

Some abuse protocol behavior.

Some abuse third-party systems.

Some rely on spoofed source IP addresses.

A Smurf attack is a type of denial-of-service attack that abuses ICMP and broadcast behavior.

The attacker sends ICMP Echo Requests to a broadcast address while spoofing the victim’s IP address.

Many hosts then reply to the victim.

So the attacker does not need every packet to come directly from their own machine.

They abuse other systems to create the flood.

This is why reflection and amplification matter.

Reflection means replies are sent to the victim.

Amplification means the replies are larger or more numerous than the attacker’s original request.


πŸ” Investigation Questions

  • Is the service slow or fully unavailable?
  • When did the traffic spike start?
  • What protocol is involved?
  • Is the attack ICMP, UDP, TCP, DNS, or NTP-based?
  • Is traffic coming from one source or many sources?
  • Are source IPs believable or likely spoofed?
  • Are there many SYN packets without completed handshakes?
  • Is the victim receiving replies from systems it never contacted?
  • Are third-party reflectors involved?
  • Is the firewall, server, or upstream provider dropping packets?
  • Is this volumetric, protocol-based, or application-layer?

🚨 Detection Opportunities

Possible detection ideas:

  • high volume of ICMP Echo Requests
  • high volume of ICMP Echo Replies without matching requests
  • many UDP packets to random ports
  • many DNS responses from external resolvers
  • many NTP responses from external servers
  • high SYN count with low completed connection count
  • sudden traffic spike from many source IPs
  • traffic pattern dominated by one protocol
  • inbound responses from services the victim did not query
  • abnormal bandwidth consumption

Example SYN flood pattern:

destination_ip=192.0.2.50
tcp_flags=SYN
syn_count=50000
completed_handshakes=120
timeframe=60 seconds
suspicion=SYN_flood

Example reflection pattern:

victim receives many DNS responses
victim did not send matching DNS queries
source servers are real DNS resolvers
likely attack type=DNS amplification

🧭 MITRE ATT&CK Techniques

  • T1498 β€” Network Denial of Service
  • T1499 β€” Endpoint Denial of Service

Related behavior:

  • reflection
  • amplification
  • spoofed source IP traffic
  • resource exhaustion

πŸ—Ί Visual Investigation Diagram

Attacker
    ↓
Spoofed request
    ↓
Reflector or broadcast network
    ↓
Many replies generated
    ↓
Victim receives flood
    ↓
Service becomes unavailable
    ↓
SOC checks traffic pattern and escalation path

⚠ Challenges

The main challenge was classification.

β€œDDoS” is often used casually, but a defender needs more precision.

A SYN flood is not the same as DNS amplification.

A Smurf attack is not just generic ping traffic.

A UDP flood is not the same as NTP amplification.

Different mechanisms require different mitigations.

Another challenge was understanding why an attacker would use reflection or amplification.

The reason is leverage.

With spoofing and vulnerable third-party systems, the attacker may generate much more victim-facing traffic than they directly send.


πŸ“š What I Learned

I learned that denial-of-service attacks should be classified by mechanism.

Useful categories:

  • direct flood
  • distributed flood
  • reflection
  • amplification
  • protocol abuse
  • state exhaustion
  • application exhaustion

I also learned that from a SOC perspective, the goal is not only to say:

We are under DDoS.

The goal is to describe the evidence:

High-volume inbound DNS responses from many resolvers with no matching outbound queries suggests DNS amplification.

That is a much stronger incident statement.


➑ Next Steps

  • Create small fake log examples for each DoS type
  • Practice identifying SYN flood evidence
  • Review NetFlow fields used during DDoS triage
  • Learn basic cloud DDoS mitigation concepts
  • Compare direct floods with reflection attacks
  • Build a notebook table: attack type, protocol, evidence, mitigation

🧠 Reflection

Today helped me clean up a messy area.

Before, many DoS and DDoS terms felt similar.

Now I can separate them by how the traffic is generated and what the victim sees.

That is much closer to real analyst thinking.


🧩 Lessons Learned

What worked

Comparing attack types side by side.

What broke

Initially treating Smurf attacks as just another ICMP flood.

Why it broke

I had not separated direct flooding from reflection and amplification.

Fix / takeaway

Always ask:

  • Who sent the original request?
  • Who received the reply?
  • Was the source IP spoofed?
  • Was traffic amplified?
  • What resource was exhausted?

πŸ“ˆ Skill Progression Context

This topic supports SOC readiness because availability incidents are high-pressure.

A SOC analyst needs to quickly identify the traffic pattern, explain the likely attack type, and escalate to the correct team:

  • network team
  • firewall team
  • ISP
  • cloud provider
  • DDoS mitigation provider
  • incident response team

Good classification leads to better response.


πŸ˜„ TL;DR

DDoS is not one attack.

It is a family of ways to make something scream, slow down, or disappear.