SlideShare a Scribd company logo
1 of 13
On the topic of Amplification
Alexander Lyamin
<la@qrator.net>
Usual suspects
User Datagram Protocol
• DNS
• NTP
• SSDP
• SNMP
• Chargen
Weighted
• X – absolute number of amplifiers that fall in
• Y - axis amplification multiplier
DNS
0
20000
40000
60000
80000
100000
120000
140000
160000
13 14 15 16 18 19 20 21 23 24 25 26 28 29 30 31 33 34 35 36 38 39 40 41 43 44 45 46 47 49 50 51 52 54 55 56 57 59 60
NTP
0
2000
4000
6000
8000
10000
12000
14000
35 90 145 200 255 310 365 420 475 530 585 640 695 750 805 860 915 970 1025 1080 1135 1190 1245 1300 1355
Chargen
0
50
100
150
200
250
300
350
400
12 23 34 45 56 67 78 89 100 111 122 133 144 155 166 177 188 200 211 222 233 244 255
SNMP
0
50000
100000
150000
200000
250000
300000
30 32 34 37 39 41 43 46 48 50 53 55 57 59 62 64 66 69 71 73 75 78 80
SSDP
0
50000
100000
150000
200000
250000
300000
350000
400000
60
63
66
69
72
75
78
81
84
87
90
93
96
99
102
105
108
111
114
117
120
123
126
128
131
134
137
140
143
146
149
152
155
158
161
164
167
170
173
176
179
and measured
• X integral multiplier in IPv4 on
• Y timeline since 1 June to 5th October 2014
Integral Multiplier
0
200000000
400000000
600000000
800000000
1E+09
1.2E+09
1.4E+09
1.6E+09
1.8E+09
Chargen
NTP
DNS
SNMP
SSDP
Total
Bottom line
Road notes:
1. 1.6B packets per one packet of a 1st stage – WOW!
2. SSDP is the king of a day.
Hypothesis:
We’re all not dead (yet) because SSDP amplifiers situated
at periphery of the network.
Its not about how much packets you can generate with
2nd stage – its about how many will reach the target.
mailto:melanor9@gmail.com
Subject: %ASN amp.report
Questions?

More Related Content

More from Alexander Lyamin

More from Alexander Lyamin (11)

ENOG-1 ddos-classification.lyamin
ENOG-1 ddos-classification.lyaminENOG-1 ddos-classification.lyamin
ENOG-1 ddos-classification.lyamin
 
D do s survival guide
D do s survival guideD do s survival guide
D do s survival guide
 
Trends d do s 2010
Trends d do s 2010Trends d do s 2010
Trends d do s 2010
 
Lyamin Yandex webmaster2013
Lyamin Yandex webmaster2013Lyamin Yandex webmaster2013
Lyamin Yandex webmaster2013
 
Lyamin ya.roundtable2014
Lyamin ya.roundtable2014Lyamin ya.roundtable2014
Lyamin ya.roundtable2014
 
Rigf2012 lyamin ANYONYMOUS uncovered
Rigf2012 lyamin ANYONYMOUS uncoveredRigf2012 lyamin ANYONYMOUS uncovered
Rigf2012 lyamin ANYONYMOUS uncovered
 
Lyamin zn2013
Lyamin zn2013Lyamin zn2013
Lyamin zn2013
 
Hl++2013 lyamin
Hl++2013 lyaminHl++2013 lyamin
Hl++2013 lyamin
 
Yac2013 lyamin-ddos
Yac2013 lyamin-ddosYac2013 lyamin-ddos
Yac2013 lyamin-ddos
 
Ddos 2011 risspa
Ddos 2011 risspaDdos 2011 risspa
Ddos 2011 risspa
 
HLL2011: Traffic Clearance Center
HLL2011: Traffic Clearance CenterHLL2011: Traffic Clearance Center
HLL2011: Traffic Clearance Center
 

Lyamin nanog63 lightning ddos amplifiers

Editor's Notes

  1. My name is Alexander Lyamin, Qrator Labs 2 quick questions Who being hit by amplification attack last year ? Who observed amplifications originating from their own network ? (that’s where the problem comes from – lack of obserations)
  2. poor design (amplifiable) Lack of ability to establish client authenticity inherent by UDP
  3. So we decided to take a closer look whats up with all this trash flying around the network
  4. It used to be much worset a year ago, we’re (as community) doing a good job fixing our DNS servers.
  5. Also much of an improvement, but still thousands of servers which will amplify by 1300 times
  6. It’s a chargen… what would you expect.
  7. I have no slightest idea what this 3 peaks mean.
  8. Third of a million amplifiers with multiplier of 78, but 50 isn’t tpo shaky
  9. Intersting snapshot, but whats the big picture and is there are changes?
  10. 2 road notes 1.6 BILLION packets per one packet of a 1st stage – (even if purely theoretically) just WOW SSDP is a king 1 hyphotesis We’re not dead (yet) because SSDP amplifiers situated at periphery of the network Its not about how much packets you can generate with 2nd stage – its about how many will reach the target.
  11. Catch me up in hallway or email me to find out hows your ASN fares from our viewpoint. Lets stay vigilant and keep our networks clean.