Dataset
UDP reflection and amplification factors
Bandwidth amplification factors for reflection-capable UDP protocols, transcribed from CISA alert TA14-017A. A factor is a measurement under stated conditions, not a constant — read the methodology note.
- Rows
- 19
- Last updated
- 2026-08-15
- Schema version
- 1.0
UDP reflection and amplification factors
| Protocol | Reported factor (CISA) | Vulnerable command | Current relevance |
|---|---|---|---|
| DNS | 28 to 54 | see TA13-088A | Still among the most abused; TCP support (RFC 9210) and response-rate limiting are the standard countermeasures. |
| NTP | 556.9 | see TA14-013A | The monlist command drove a wave of very large attacks; largely mitigated by patching, but the factor is why it mattered. |
| SNMPv2 | 6.3 | GetBulk request | Modest factor; abuse depends on exposed community strings. |
| NetBIOS | 3.8 | Name resolution | Low factor; relevant mainly on exposed legacy Windows services. |
| SSDP | 30.8 | SEARCH request | Consumer UPnP devices make this a persistent source of mid-size reflection. |
| CharGEN | 358.8 | Character generation request | High factor from an obsolete service; should not be reachable at all on a modern network. |
| QOTD | 140.3 | Quote request | Obsolete diagnostic service; disable it. |
| BitTorrent | 3.8 | File search | Low factor; abuse tied to DHT and peer-exchange behaviour. |
| Kad | 16.3 | Peer list exchange | P2P network reflection; niche. |
| Quake Network Protocol | 63.9 | Server info exchange | Game-server reflection; relevant to gaming-sector operators specifically. |
| Steam Protocol | 5.5 | Server info exchange | Low factor; gaming infrastructure. |
| Multicast DNS (mDNS) | 2 to 10 | Unicast query | Low factor, but widely exposed on misconfigured devices; see CERT/CC VU#550620. |
| RIPv1 | 131.24 | Malformed request | High factor from a legacy routing protocol; documented in an Akamai PLXsert advisory. |
| Portmap (RPCbind) | 7 to 28 | Malformed request | Documented by Level 3 Threat Research in 2015; relevant where RPC is internet-exposed. |
| LDAP | 46 to 55 | Malformed request | Directory-service reflection reported by Corero in 2016. |
| CLDAP | 56 to 70 | not stated | Reported by Netlab 360 in 2017 as the third most common reflection vector after DNS and NTP. |
| TFTP | 60 | not stated | High factor; TFTP should never be internet-reachable. |
| Memcached | 10,000 to 51,000 | not stated | The extreme case: an unauthenticated, internet-exposed cache. Drove record-setting attacks in 2018; the fix is not exposing it (UDP/TCP 11211). |
| WS-Discovery | 10 to 500 | not stated | Wide range; exploited from 2019 against exposed devices on TCP/UDP 3702. |
Sources
- Alert TA14-017A: UDP-Based Amplification Attacks
CISA (US Cybersecurity and Infrastructure Security Agency) · 2014-01-17 · accessed 2026-08-15
Last revised 18 December 2019. Every factor and command in this table is transcribed from the alert; figures are not averaged or altered.
What changed
- 2026-08-15Initial release: 19 protocols transcribed from TA14-017A.
Reuse: Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.