Techniques › T1498 › T1498.002
T1498.002 Reflection Amplification
impact — Windows, IaaS, Linux, macOS · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
0
Sigma rules tagged attack.t1498.002
0
KEV CVEs mapped here
<p>Adversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a target. This type of Network DoS takes advantage of a third-party server intermediary that hosts and will respond to a given spoofed source IP address. This third-party server is commonly termed a reflector. An adversary accomplishes a reflection attack by sending packets to reflectors with the spoofed address of the victim. Similar to Direct Network Floods, more than one system may be used to conduct the attack, or a botnet may be used. Likewise, one or more reflectors may be used to focus traffic on the target. This Network DoS attack may also reduce the availability and functionality of the targeted system(s) and network.</p><p>Reflection attacks often take advantage of protocols with larger responses than requests in order to amplify their traffic, commonly known as a Reflection Amplification attack. Adversaries may be able to generate an increase in volume of attack traffic that is several orders of magnitude greater than the requests sent to the amplifiers. The extent of this increase will depending upon many variables, such as the protocol in question, the technique used, and the amplifying servers that actually produce the amplification in attack volume. Two prominent protocols that have enabled Reflection Amplification Floods are DNS and NTP, though the use of several others in the wild have been documented. In particular, the memcache protocol showed itself to be a powerful protocol, with amplification sizes up to 51,200 times the requesting packet.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0408 Detection Strategy for Reflection Amplification DoS (T1498.002) v1.0
AN1140 WindowsOutbound spoofed traffic to known amplification protocols (e.g., DNS, NTP, Memcached) combined with abnormal network traffic volume targeting remote reflectors, resulting in disproportionate traffic returned to a victimWindows:perfmon
Sudden spike in outbound throughput without corresponding inbound traffic→ DC0018 Host StatusTunable:TimeWindowAmplificationProtocolPortsPacketToByteRatioAN1141 LinuxSpoofed outbound packets sent to amplification services from command-line tools or scripts, combined with abnormal outbound packet volume on known reflector portsauditd:SYSCALLExecution of spoofing tools (e.g., hping3, nping, scapy) sending UDP packets to known amplifier ports→ DC0064 Command ExecutionNSM:FlowOutbound UDP floods targeting common reflection services with spoofed IP headers→ DC0078 Network Traffic FlowTunable:TimeWindowAmplificationProtocolListExecutionToolListAN1142 macOSCommand-line initiated UDP traffic bursts to external reflection amplification ports using built-in scripting or binaries with network anomaliesmacos:unifiedlogExecution of ping, nping, or crafted network packets via bash or python to reflection services→ DC0032 Process CreationTunable:ReflectionPortsTrafficSpikeThresholdAN1143 IaaSCloud-hosted VM or container generates spoofed UDP requests to third-party services on known amplifier ports, with high outbound-to-inbound traffic ratios in VPC Flow LogsAWS:CloudTrailCreate egress rule allowing UDP to port 53, 123, 11211→ DC0051 Firewall Rule ModificationAWS:VPCFlowLogsLarge outbound UDP traffic to multiple public reflector IPs→ DC0078 Network Traffic FlowAWS:CloudWatchSudden spike in network output without a corresponding inbound request ratio→ DC0018 Host StatusTunable:EgressRulePortsOutboundToInboundRatioVMInstanceTagContext
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1498.002
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.
Rules tagged at the parent level (attack.t1498) 3
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Leo Tsaousis (@laripping)
· 2024-03-26 · logsource: product=kubernetes category=application service=audit · 40967487-139b-4811-81d9-c9767a92aa5a
Detects the removal of a deployment from a Kubernetes cluster.
This could indicate disruptive activity aiming to impact business operations.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 7cded4b3-f09e-405a-b96f-24248433ba44
Detects instances where an NTP service on an OpenCanary node has had a NTP monlist request.
Author: Florian Roth (Nextron Systems)
· 2022-02-25 (modified 2023-02-08) · logsource: product=windows category=process_creation · 999e8307-a775-4d5f-addc-4855632335be
Detects command line patterns used by BlackByte ransomware in different operations