DDoS Reflection (Reflection/Amplification Denial-of-Service Attack)

Also known as: Reflection Attack, Amplification Attack

A reflection DDoS spoofs the victim's IP as the source of requests sent to open UDP-based services (DNS, NTP, memcached, SSDP, chargen), which reply to the victim with larger responses — amplifying the attack by factors up to ~50,000x. Telecom exposure includes exposed Diameter/GTP/SIP endpoints, roaming DNS, and IPX-facing NEF/SEPP interfaces if BCP38 ingress filtering is missing.

Categories: Threats and AttacksInternet and Routing

DDoS Reflection in context

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

Telecom networks depend on Internet-style routing (BGP, DNS, MPLS) for interconnect. Route hijacks and DNS abuse can degrade or intercept signaling, which is why RPKI and DNSSEC are now standard hardening for carrier networks.

To place DDoS Reflection in the wider telecom-security picture, review A5/2, ASN, BGP, BGP Hijacking, CGNAT and CVE — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.