L25
DoS, DDoS, reflection and amplification
Cram this first — memory hook
Reflection = bounce toward the victim; amplification = make it bigger; distributed = many sources.
Exam trap
A local firewall cannot restore already saturated upstream capacity just by dropping packets after they arrive.
The slide facts
Denial-of-service attacks target availability. The reflection/amplification illustration uses a spoofed victim address and larger third-party responses.
If you have time — extra
Denial of Service () prevents legitimate use by exhausting or disrupting a resource. Distributed Denial of Service () involves many sources. A need not always be a huge flood; some attacks exploit a weakness to crash a service. Reflection means an attacker causes another system to send replies to the victim, commonly by spoofing the victim's source Internet Protocol address in requests. Amplification means the resulting response traffic is larger than the triggering request traffic. Reflection is about direction/intermediaries; amplification is about growth in traffic. They can occur together, but neither word is a synonym for the other. Conceptually, if a 100-byte trigger causes a 2,000-byte reply, that is about twenty times the payload size before considering other overhead. Defensive measures can include upstream filtering/scrubbing, anti-spoofing practices and avoiding exposed services that act as amplifiers.
Walkthrough
Identify the victim service, traffic sources and any intermediary responders. Ask separately whether replies are redirected and whether volume is expanded. Match protections to the bottleneck and attack mechanism.