• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Thwarting SSDP-based DDoS Attacks

by CXO Staff
November 1, 2021
in Opinions

Organisations need to update defensive strategies by incorporating the Zero Trust model, says Amr Alashaal, Regional Vice President, Middle East at A10 Networks

DDoS security

Lately, DDoS attackers have been increasingly focused on smaller attacks launched persistently over a long period of time. The trend has been prevalent throughout the last couple of years thanks to the COVID-19 pandemic.

That said, the notoriety and capabilities of large-scale DDoS attacks cannot be diminished. In fact, while large-scale attacks might not occur as frequently as their low-volume, high-frequency cousins, they still tend to cause a lot of damage and make headlines at least a couple of times a year.

At the end of the day, while these large-scale attacks might not be as lucrative as continuously attacking an organisation for days or even weeks, these attacks are increasingly used to make a statement. And in a world where state-sponsored cyberattacks and cyber activism have quickly become a norm, these attacks can be quite damaging.

Amplified reflection attacks take the top position when it comes to size of DDoS attacks. This attack strategy exploits the connectionless nature of the UDP protocol and spoofs the victim’s IP address.

How do Amplification Attacks Work?

Amplified reflection attacks can wreak havoc on small, medium or large organizations alike, leveraging the amplification factors of many protocols and services commonly used across the internet. The most common types of these attacks can use millions of exposed DNS, NTP, SSDP, SNMP, and CLDAP UDP-based services.

Attackers send multiple requests to these services, spoofing the victim’s IP address. The servers reply with large amplified responses to the unwitting victim. These particular servers are targeted because they answer to unauthenticated requests and are running applications or protocols with amplification capabilities.

These attacks have resulted in record-breaking volumetric attacks and with each passing year, new records are reached, both in terms of attack traffic and packets per second.

Amplification Weapons In 2021

In the first half of 2021, the A10 Networks research team observed an additional 2.5 million unique systems that can be used in amplified reflection attacks.

SSDP stayed at the top of the list of amplification weapons, with over 3.2 million systems exposed to the internet. This is an increase of over 28 percent compared to the previous reporting period.

It is important to note that when it comes to amplified reflection attacks, the number of weapons, while an important metric, is not the defining factor; it’s the bandwidth amplification factor that makes all the difference.

For example, while SSDP has led our list of top DDoS weapons for a year, its amplification factor sits at a little over 30x, which is almost half of the protocols at the bottom of our top-five list, TFTP and DNS, which have amplification factors of 60 and 54 respectively.

How SSDP is Exploited?

The SSDP is used for the advertisement and discovery of network services and is the basis of the discovery protocol of Universal Plug and Play (UPnP). SSDP-based DDoS attacks exploit the protocol by spoofing the victim’s IP address and sending these target systems a large volume of response traffic reflected off plug-and-play devices that are open to the

internet. The response generated by these devices can be larger than 30 times the request size. This large volume of traffic can be devastating to systems and organizations that fall victim to such attacks, making them unresponsive or bringing them down entirely.

Preventing SSDP-based DDoS Attacks

The most straightforward blanket protection against such attacks is to simply block port 1900 traffic sourced from the internet unless there is a specific use case for SSDP across the internet. Alternatively, blocking SSDP traffic from specific geo-locations, where a large number of botnet activity has been detected, can also be used to provide surgical protection.

Organisations need to update defensive strategies by incorporating the Zero Trust model and invest in modern, artificial intelligence/machine learning-based solutions that will not only defeat attacks in real time, but also protect against the unknown.

Tags: A10Amr AlashaalCybersecurityDDoSfeatured1
ShareTweet

Related Posts

Empowering the UAE’s digital future through data sovereignty
Opinions

Empowering the UAE’s digital future through data sovereignty

As the UAE continues to lead the charge in technological innovation, the importance of data sovereignty has never been more...

May 26, 2025
AI agents are set to become an indispensable part of the GCC security apparatus
Opinions

AI agents are set to become an indispensable part of the GCC security apparatus

Middle Eastern countries continue to bet big on AI—and for good reason. National strategies like the UAE Artificial Intelligence Strategy...

May 23, 2025

Discussion about this post

Latest Issue

CVC Joins CD&R as an Investment Partner in Epicor

VAST Data and Cisco expand partnership

June 4, 2025
JAGGAER appoints first Chief Digital & AI Officer

JAGGAER appoints first Chief Digital & AI Officer

June 4, 2025
training skills ups killing

Huawei partners with Nafis to launch Emirati Talent Development Programme

June 4, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect
    • Channel Awards 2023
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2024 - CXO Insight Middle East. All Rights Reserved.