Network Security

Dissecting a DNS Amplification DDoS attack

Today we had to investigate a sudden spike in outbound internet traffic on a small business' network. The symptoms reported were a sudden slowness browsing the internet from machines connected to the SMB's LAN. A quick peek on a network usage graph revealed a sudden increase in outbound traffic, see the blue line while the inbound traffic volume was relatively low (green area) ...