π Day 112 β DoS, DDoS, SYN Floods, Smurf, and Amplification
π Topic
Studying denial-of-service attacks and how different flooding, reflection, and amplification patterns appear in traffic.
π― Goal
Understand how attackers disrupt availability and how defenders distinguish direct floods from reflection/amplification attacks.
π What I Did
Today I continued the network intrusion section of Course 3 and focused on DoS and DDoS attacks.
The attacks included:
- ICMP flood
- UDP flood
- TCP SYN flood
- DNS amplification
- NTP amplification
- Smurf attack
The shared goal is availability damage: make a service, network, or system unable to respond normally.
π Key Cybersecurity Connections
Not all denial-of-service attacks work the same way.
A direct flood sends lots of traffic at the victim.
A SYN flood abuses the TCP handshake by sending many SYN packets and not completing the connection.
A reflection/amplification attack abuses third-party servers. The attacker spoofs the victimβs IP address so replies are sent to the victim.
A Smurf attack abuses ICMP broadcast behavior: the attacker sends ICMP Echo Requests to a broadcast address while spoofing the victim IP, causing many hosts to reply to the victim.
π Investigation Questions
- Is the service slow or unavailable?
- When did the traffic spike begin?
- Which protocol is involved?
- Is the traffic ICMP, UDP, TCP, DNS, or NTP?
- Is the source one host, many hosts, or many reflectors?
- Are source IPs believable?
- Are there many SYN packets without completed handshakes?
- Is the victim receiving responses it never requested?
- Is upstream mitigation needed?
π¨ Detection Opportunities
Detection patterns:
- spike in packets per second to one destination
- many SYN packets with low completed handshakes
- many DNS or NTP responses with few matching outbound requests
- ICMP Echo Replies from many hosts to one victim
- firewall or load balancer resource exhaustion
Example:
dst_ip=192.0.2.50
syn_packets=90000
completed_handshakes=120
window=60s
detection=possible_syn_flood
Another example:
inbound_dns_responses=60000
outbound_dns_queries=5
detection=possible_dns_reflection_amplification
π§ MITRE ATT&CK Techniques
Possible mappings:
- T1498 β Network Denial of Service
- T1498.001 β Direct Network Flood
- T1498.002 β Reflection Amplification
- T1499 β Endpoint Denial of Service
πΊ Visual Investigation Diagram
Attacker
β
Flood / spoofed request
β
Victim or reflector
β
Resource exhaustion
β
Service unavailable
β
Defender mitigation
β Challenges
The challenge is classification. ICMP flood, SYN flood, Smurf, and DNS amplification are all availability attacks, but the evidence differs.
A good analyst must describe the pattern, not only the attack name.
π What I Learned
I learned that DoS analysis is about resource pressure and traffic symmetry. Are requests and responses balanced? Are handshakes completed? Is traffic coming directly or through reflectors?
β‘ Next Steps
- Build a table of DoS/DDoS types and evidence patterns
- Create fake firewall logs for SYN flood and DNS amplification
- Practice explaining reflection and amplification in plain language
- Review anti-spoofing and upstream mitigation controls
π§ Reflection
This topic is important because availability is security. A system that cannot respond is not secure, even if no data was stolen.
π§© Lessons Learned
What worked
Separating direct floods from reflection/amplification.
What broke
Grouping all DDoS patterns together hides important evidence differences.
Why it broke
Different attack types produce different traffic shapes.
Fix / takeaway
Describe protocol, source pattern, handshake behavior, and response symmetry.
π Skill Progression Context
This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.
Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.
π TL;DR
DoS is not one attack. It is a family of ways to break availability.
