What is reflection and amplification?¶
Reflection sends forged requests to third-party services so their replies reach the victim. Amplification occurs when each reply is substantially larger than the initiating request.
Understand the visible sources¶
Identify the abused protocol, reflector responses, packet features, timing and request-to-response ratio. The victim usually sees the unwitting third parties, not the system that sent forged requests.
Provider and specialist routing evidence may help locate the initiating infrastructure. Reflector operators can preserve received forged requests, but thousands of responding systems should not be treated as suspects.
Keep weakness and responsibility separate¶
An exposed or misconfigured service creates amplification opportunity; that does not make its operator responsible for intentional attack. Separate infrastructure weakness, unwitting participation and direction.
Source spoofing also makes the apparent response addresses poor offender identifiers. Focus first on common protocol, timing and packet characteristics, then pursue upstream evidence.
Key takeaway
Treat reflector addresses as unwitting intermediaries and reconstruct the forged-request mechanism through protocol, packet and provider evidence before attribution.