What is reflection and amplification?¶
The practical answer¶
Reflection and amplification use third-party systems to send larger volumes of traffic towards a target.
The key evidential caution¶
The dangerous assumption is that the systems sending the traffic are necessarily the attacker’s own devices.
They may be legitimate servers responding to forged requests.
In a reflection attack, the offender sends requests that appear to come from the victim’s address.
The third-party systems then send their replies to the victim.
Amplification occurs where the reply is much larger than the original request.
What investigators should establish¶
Investigators should establish:
Key points¶
- which protocol or service was abused
- whether source addresses were spoofed
- which reflectors responded
- the request-to-response size difference
- the traffic timing
- provider or mitigation observations
The victim may receive traffic from many apparently legitimate systems that have no knowledge of the attack.
Evidential limits¶
Do not treat reflector operators as the offender without separate evidence.
Likewise, the true origin may be difficult to identify from the victim’s logs because the forged source information hides the initiating system.
Network-provider records and specialist analysis may be required.
Reflection may involve thousands of unrelated third-party systems. Those systems can provide useful evidence about the forged requests they received, but contacting or treating them all as suspects would be misleading. Focus on the abused protocol, timing, packet characteristics and provider-level route towards the initiating infrastructure.
Where the abused third-party service is misconfigured or unnecessarily exposed, that may explain amplification opportunity but does not make its operator responsible for the attack. Separate infrastructure weakness, unwitting participation and intentional control.
Operational takeaway¶
Treat reflector addresses as intermediaries, preserve protocol and provider evidence and avoid attributing the attack from the visible response sources alone.