300K Internet Hosts at Risk for 'Devastating' Loop DoS Attack
ID: 0748db9b-7321-5277-bb4a-a8e5f87b2491
STIX ID: report--0748db9b-7321-5277-bb4a-a8e5f87b2491
Feed Name: Dark Reading
Date Published: 2024-03-21
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers at CISPA discovered "loop DoS," a novel application-layer denial-of-service technique that pairs UDP-based services so they repeatedly reply to each other indefinitely, producing large volumes of traffic that can exhaust bandwidth or compute resources. The report details four attack scenarios (targeting single servers, backbone networks, congesting specific links, and self-amplifying loops), identifies affected legacy and common UDP services (DNS, NTP, TFTP, Daytime, Chargen, Echo, QOTD), notes the attack can be initiated by a single spoofing-capable host and may affect hundreds of thousands of hosts, and recommends mitigations including patching vulnerable services, restricting UDP, using TCP with authentication, and limiting host-to-host communication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
