T1498.002 Reflection Amplification Mappings

Adversaries may attempt to cause a denial of service by reflecting a high-volume of network traffic to a target. This type of Network DoS takes advantage of a third-party server intermediary that hosts and will respond to a given spoofed source IP address. This third-party server is commonly termed a reflector. An adversary accomplishes a reflection attack by sending packets to reflectors with the spoofed address of the victim. Similar to Direct Network Floods, more than one system may be used to conduct the attack, or a botnet may be used. Likewise, one or more reflector may be used to focus traffic on the target.(Citation: Cloudflare ReflectionDoS May 2017)

Reflection attacks often take advantage of protocols with larger responses than requests in order to amplify their traffic, commonly known as a Reflection Amplification attack. Adversaries may be able to generate an increase in volume of attack traffic that is several orders of magnitude greater than the requests sent to the amplifiers. The extent of this increase will depending upon many variables, such as the protocol in question, the technique used, and the amplifying servers that actually produce the amplification in attack volume. Two prominent protocols that have enabled Reflection Amplification Floods are DNS(Citation: Cloudflare DNSamplficationDoS) and NTP(Citation: Cloudflare NTPamplifciationDoS), though the use of several others in the wild have been documented.(Citation: Arbor AnnualDoSreport Jan 2018) In particular, the memcache protocol showed itself to be a powerful protocol, with amplification sizes up to 51,200 times the requesting packet.(Citation: Cloudflare Memcrashed Feb 2018)



Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
AC-3 Access Enforcement Protects T1498.002 Reflection Amplification
AC-4 Information Flow Enforcement Protects T1498.002 Reflection Amplification
CA-7 Continuous Monitoring Protects T1498.002 Reflection Amplification
CM-6 Configuration Settings Protects T1498.002 Reflection Amplification
CM-7 Least Functionality Protects T1498.002 Reflection Amplification
SC-7 Boundary Protection Protects T1498.002 Reflection Amplification
SI-10 Information Input Validation Protects T1498.002 Reflection Amplification
SI-15 Information Output Filtering Protects T1498.002 Reflection Amplification
azure_private_link Azure Private Link technique_scores T1498.002 Reflection Amplification
azure_ddos_protection_standard Azure DDOS Protection Standard technique_scores T1498.002 Reflection Amplification