An SSDP DDoS attack exploits vulnerabilities in Universal Plug and Play.
After reading this article you will be able to:
Related Content
How to DDoS | DoS and DDoS attack tools
DDoS mitigation
What is a denial-of-service (DoS) attack?
What is a DDoS botnet?
Smurf attack (historic)
Subscribe to theNET, Cloudflare's monthly recap of the Internet's most popular insights!
Copy article link
A Simple Service Discovery Protocol (SSDP) attack is a reflection-based distributed denial-of-service (DDoS) attack that exploits Universal Plug and Play (UPnP) networking protocols in order to send an amplified amount of traffic to a targeted victim, overwhelming the target’s infrastructure and taking their web resource offline.
Here is a free tool to check to see if your public IP has any exposed SSDP devices: check SSDP DDoS vulnerability.
Under normal circumstances, the SSDP protocol is used to allow UPnP devices to broadcast their existence to other devices on the network. For example, when a UPnP printer is connected to a typical network, after it receives an IP address, the printer is able to advertise its services to computers on the network by sending a message to a special IP address called a multicast address. The multicast address then tells all the computers on the network about the new printer. Once a computer hears the discovery message about the printer, it makes a request to the printer for a complete description of its services. The printer then responds directly to that computer with a complete list of everything it has to offer. An SSDP attack exploits that final request for services by asking the device to respond to the targeted victim.
For network administrators, a key mitigation is to block incoming UDP traffic on port 1900 at the firewall. Provided the volume of traffic isn’t enough to overwhelm the network infrastructure, filtering traffic from this port will likely be able to mitigate such an attack. For a deeper dive on SSDP attacks and more mitigation strategies, explore technical details about an SSDP attack.
Do you want to know if you have a vulnerable SSDP service that can be used in a DDoS attack? As mentioned before, we’ve created a free tool to check to see if your public IP has any exposed SSDP devices. To check for a SSDP DDoS vulnerability, you can use this free tool.
Cloudflare eliminates SSDP attacks by stopping all the attack traffic before it reaches it’s target; UDP packets targeting Port 1900 are not be proxied to the origin server, and the load for receiving the initial traffic falls on Cloudflare’s network. We offer full protection from SSDP and other layer 3 amplification attacks.
Although the attack will target a single IP address, our Anycast network will scatter all attack traffic to the point where it is no longer disruptive. Cloudflare is able to use our advantage of scale to distribute the weight of the attack across many Data Centers, balancing the load so that service is never interrupted and the attack never overwhelms the targeted server’s infrastructure. During a recent six-month window, our DDoS mitigation system "Gatebot" detected 6,329 simple reflection attacks (that's one every 40 minutes), and the network successfully mitigated all of them. Learn more about Cloudflare's DDoS Protection.
血糖低吃什么补的最快 | 因果关系是什么意思 | pubg什么意思 | 人鱼小姐大结局是什么 | 感冒头痛吃什么药 |
避孕套是什么材质 | 总ige高是什么意思 | 空腹喝酒有什么危害 | 1935年属什么 | 匹夫是什么意思 |
什么是血小板 | 青蛙怕什么 | 霉菌性阴炎用什么药止痒效果好 | 么么什么意思 | 肿瘤标志物是什么意思 |
菲薄是什么意思 | 梦到开车是什么意思 | 走路脚后跟疼是什么原因 | 小便痒痒是什么原因女 | 中度贫血吃什么补血最快 |
什么是微单相机hcv7jop9ns9r.cn | 烧高香是什么意思jinxinzhichuang.com | 阴道有腥味是什么原因hcv8jop4ns4r.cn | 1.15是什么星座hcv8jop0ns9r.cn | marisfrolg是什么牌子xinmaowt.com |
脊柱炎吃什么药效果好ff14chat.com | 手麻是什么原因引起的hcv8jop2ns6r.cn | 什么是词性hcv8jop7ns0r.cn | 妈妈的外婆叫什么hcv9jop2ns3r.cn | 什么河水hcv8jop3ns1r.cn |
宝宝吃益生菌有什么好处和坏处hcv9jop4ns9r.cn | 中位生存期什么意思hcv7jop9ns8r.cn | 暮春是什么时候hcv8jop3ns6r.cn | 靠谱什么意思hcv9jop3ns2r.cn | 12月11日什么星座hcv7jop9ns3r.cn |
孤独的最高境界是什么hcv9jop2ns7r.cn | 沙参长什么样子图片hcv7jop6ns7r.cn | 咳嗽适合吃什么水果hcv7jop5ns0r.cn | 鱼龙混杂什么意思yanzhenzixun.com | 木耳与什么食物相克hcv8jop8ns1r.cn |