A security operations center (SOC) analyst observes a significant increase in outbound UDP traffic from a specific internal subnet to various external IP addresses on port 123 (NTP). The traffic volume is abnormally high, and the destination IPs are diverse and frequently changing. There are no legitimate internal services that would initiate such a high volume of outbound NTP requests. Which type of attack is most likely underway?
- ANTP Amplification Attack
- BSYN Flood Attack
- CDNS Amplification Attack
- DSSDP Amplification Attack
Show answer & explanationAnswer & explanation
Correct answer: A. NTP Amplification Attack
NTP amplification attacks leverage Network Time Protocol (NTP) servers to overwhelm a target with a flood of UDP traffic. Attackers send small requests to NTP servers with a spoofed source IP address (the target's IP). The NTP servers then respond with much larger packets to the spoofed IP, amplifying the attack. The scenario describes high outbound UDP traffic on port 123 (NTP) to diverse external IPs, originating from an internal subnet, indicating that the internal machines are likely being used as reflectors or participating in an amplification attack against an external target.
Why the other options are wrong
- B. SYN Flood is a TCP-based attack that targets specific ports (often 80/443) by overwhelming with SYN requests, not UDP port 123.
- C. DNS Amplification uses DNS (port 53) resolvers, not NTP (port 123).
- D. SSDP Amplification uses SSDP (port 1900) and UPnP devices, not NTP (port 123).
NTP Amplification Attack
A type of Distributed Denial of Service (DDoS) attack that uses public Network Time Protocol (NTP) servers to overwhelm a target with UDP traffic.
- Leverages the NTP 'monlist' command or similar features that return large responses.
- Attackers spoof the target's IP address in requests to NTP servers.
- Results in a high volume of UDP traffic to the target on port 123.
Memory trick: Amplification: Small Request, Huge Response.