Skip to content

Dataset

UDP reflection and amplification factors

Bandwidth amplification factors for reflection-capable UDP protocols, transcribed from CISA alert TA14-017A. A factor is a measurement under stated conditions, not a constant — read the methodology note.

Rows
19
Last updated
2026-08-15
Schema version
1.0
Download
JSON·CSV

UDP reflection and amplification factors

ProtocolReported factor (CISA)Vulnerable commandCurrent relevance
DNS28 to 54see TA13-088AStill among the most abused; TCP support (RFC 9210) and response-rate limiting are the standard countermeasures.
NTP556.9see TA14-013AThe monlist command drove a wave of very large attacks; largely mitigated by patching, but the factor is why it mattered.
SNMPv26.3GetBulk requestModest factor; abuse depends on exposed community strings.
NetBIOS3.8Name resolutionLow factor; relevant mainly on exposed legacy Windows services.
SSDP30.8SEARCH requestConsumer UPnP devices make this a persistent source of mid-size reflection.
CharGEN358.8Character generation requestHigh factor from an obsolete service; should not be reachable at all on a modern network.
QOTD140.3Quote requestObsolete diagnostic service; disable it.
BitTorrent3.8File searchLow factor; abuse tied to DHT and peer-exchange behaviour.
Kad16.3Peer list exchangeP2P network reflection; niche.
Quake Network Protocol63.9Server info exchangeGame-server reflection; relevant to gaming-sector operators specifically.
Steam Protocol5.5Server info exchangeLow factor; gaming infrastructure.
Multicast DNS (mDNS)2 to 10Unicast queryLow factor, but widely exposed on misconfigured devices; see CERT/CC VU#550620.
RIPv1131.24Malformed requestHigh factor from a legacy routing protocol; documented in an Akamai PLXsert advisory.
Portmap (RPCbind)7 to 28Malformed requestDocumented by Level 3 Threat Research in 2015; relevant where RPC is internet-exposed.
LDAP46 to 55Malformed requestDirectory-service reflection reported by Corero in 2016.
CLDAP56 to 70not statedReported by Netlab 360 in 2017 as the third most common reflection vector after DNS and NTP.
TFTP60not statedHigh factor; TFTP should never be internet-reachable.
Memcached10,000 to 51,000not statedThe extreme case: an unauthenticated, internet-exposed cache. Drove record-setting attacks in 2018; the fix is not exposing it (UDP/TCP 11211).
WS-Discovery10 to 500not statedWide range; exploited from 2019 against exposed devices on TCP/UDP 3702.

Sources

  1. Alert TA14-017A: UDP-Based Amplification Attacks

    CISA (US Cybersecurity and Infrastructure Security Agency) · 2014-01-17 · accessed 2026-08-15

    Last revised 18 December 2019. Every factor and command in this table is transcribed from the alert; figures are not averaged or altered.

What changed

  • 2026-08-15Initial release: 19 protocols transcribed from TA14-017A.

Reuse: Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.