Network Denial of Service: Reflection Amplification T1498.002

Tactic: Impact

Adversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a target. This type of Network DoS takes advantage of a third-party server intermediary that hosts and will respond to a given spoofed source IP address. This third-party server is commonly termed a reflector. An adversary accomplishes a reflection attack by sending packets to reflectors with the spoofed address of the victim. Similar to Direct Network Floods, more than one system may be used to conduct the attack, or a botnet may be used. Likewise, one or more reflectors may be used to focus traffic on the target. This Network DoS attack may also reduce the availability and functionality of the targeted system(s) and network.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (4 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
DNS.message_type1eq 1query
count1gt 1200
dns.answers.type1eq 1any
nodename1eq 1dns

Top indicator values (4 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
DNS.message_typeeq
query
12
countgt
200
1
dns.answers.typeeq
any
1
nodenameeq
dns
12

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Network

Domain: Network

Splunk 1 rule