• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 716
  • Last Modified:

Mitigate UDP Broadcast DDoS Attacks


Could somebody please share some methods to Mitigate UDP Broadcast DDoS Attacks ?

  • 3
1 Solution
Here is a good start. This is from Cisco, but the principals can be applied to other platforms.

g0allAuthor Commented:
Thank you, interesting generic document.

I'm still not able to understand if  mitigating DDoS UDP Broadcast  Attacks is possible and if so, how?
There is always new ways of attacks. But, I can think of the following steps that as a general rule should mitigate against "broadcast" attacks:

1. Turn off directed broadcasts: on Cisco routers this is done by "no ip directed-broadcast" interface command.
2. Turn off "chargen" and "ICMP Echo reply"
3. Do not allow forwarding of broadcast traffic on routers. This is off by default. Make sure it stays that way.
4. Use " ip verify unicast reverse-path " command.
5. Use an IDS at the perimeter of the network to detect attacks.
In addition and prior to above configurations you should have a network design that limits and confines broadcast domains by using VLANs.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Increase Security & Decrease Risk with NSPM Tools

Analyst firm, Enterprise Management Associates (EMA) reveals significant benefits to enterprises when using Network Security Policy Management (NSPM) solutions, while organizations without, experienced issues including non standard security policies and failed cloud migrations

  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now