πŸ”„ Topic

Studying denial-of-service attacks and how different flooding, reflection, and amplification patterns appear in traffic.


🎯 Goal

Understand how attackers disrupt availability and how defenders distinguish direct floods from reflection/amplification attacks.


πŸ›  What I Did

Today I continued the network intrusion section of Course 3 and focused on DoS and DDoS attacks.

The attacks included:

  • ICMP flood
  • UDP flood
  • TCP SYN flood
  • DNS amplification
  • NTP amplification
  • Smurf attack

The shared goal is availability damage: make a service, network, or system unable to respond normally.


πŸ”— Key Cybersecurity Connections

Not all denial-of-service attacks work the same way.

A direct flood sends lots of traffic at the victim.

A SYN flood abuses the TCP handshake by sending many SYN packets and not completing the connection.

A reflection/amplification attack abuses third-party servers. The attacker spoofs the victim’s IP address so replies are sent to the victim.

A Smurf attack abuses ICMP broadcast behavior: the attacker sends ICMP Echo Requests to a broadcast address while spoofing the victim IP, causing many hosts to reply to the victim.


πŸ” Investigation Questions

  • Is the service slow or unavailable?
  • When did the traffic spike begin?
  • Which protocol is involved?
  • Is the traffic ICMP, UDP, TCP, DNS, or NTP?
  • Is the source one host, many hosts, or many reflectors?
  • Are source IPs believable?
  • Are there many SYN packets without completed handshakes?
  • Is the victim receiving responses it never requested?
  • Is upstream mitigation needed?

🚨 Detection Opportunities

Detection patterns:

  • spike in packets per second to one destination
  • many SYN packets with low completed handshakes
  • many DNS or NTP responses with few matching outbound requests
  • ICMP Echo Replies from many hosts to one victim
  • firewall or load balancer resource exhaustion

Example:

dst_ip=192.0.2.50
syn_packets=90000
completed_handshakes=120
window=60s
detection=possible_syn_flood

Another example:

inbound_dns_responses=60000
outbound_dns_queries=5
detection=possible_dns_reflection_amplification

🧭 MITRE ATT&CK Techniques

Possible mappings:

  • T1498 β€” Network Denial of Service
  • T1498.001 β€” Direct Network Flood
  • T1498.002 β€” Reflection Amplification
  • T1499 β€” Endpoint Denial of Service

πŸ—Ί Visual Investigation Diagram

Attacker
    ↓
Flood / spoofed request
    ↓
Victim or reflector
    ↓
Resource exhaustion
    ↓
Service unavailable
    ↓
Defender mitigation

⚠ Challenges

The challenge is classification. ICMP flood, SYN flood, Smurf, and DNS amplification are all availability attacks, but the evidence differs.

A good analyst must describe the pattern, not only the attack name.


πŸ“š What I Learned

I learned that DoS analysis is about resource pressure and traffic symmetry. Are requests and responses balanced? Are handshakes completed? Is traffic coming directly or through reflectors?


➑ Next Steps

  • Build a table of DoS/DDoS types and evidence patterns
  • Create fake firewall logs for SYN flood and DNS amplification
  • Practice explaining reflection and amplification in plain language
  • Review anti-spoofing and upstream mitigation controls

🧠 Reflection

This topic is important because availability is security. A system that cannot respond is not secure, even if no data was stolen.


🧩 Lessons Learned

What worked

Separating direct floods from reflection/amplification.

What broke

Grouping all DDoS patterns together hides important evidence differences.

Why it broke

Different attack types produce different traffic shapes.

Fix / takeaway

Describe protocol, source pattern, handshake behavior, and response symmetry.


πŸ“ˆ Skill Progression Context

This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.

Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.


πŸ˜„ TL;DR

DoS is not one attack. It is a family of ways to break availability.