The attack in question was neither new nor particularly sophisticated. Yet, in less than 60 seconds, an attack with a bandwidth of 370 gigabits per second was underway. Without DDoS protection, anyone would simply go offline in such a situation. This case is instructive because of the textbook method used to carry out the attack–a tool as old as the internet itself that still works.
The Mechanism Behind the Attack
This attack is as simple as it is effective. The User Datagram Protocol (UDP) sends data packets without waiting for confirmation. In contrast, TCP expects an acknowledgment for every packet sent (“Did you get that? Good, here’s the next one.”). UDP, on the other hand, just fires away. It doesn’t matter whether the packet arrives. On to the next one!
This characteristic makes UDP resource-efficient. Attackers don’t have to maintain a connection, manage responses, or keep packets in a queue. They can give every device in their botnet a single instruction: Send packets in this direction. Each device does exactly that –without synchronization, coordination, or orchestration. One command for all.
Fragmentation as a Weapon
Unlike a typical UDP flood, this attack involved incomplete packets. Nearly all of the recorded packets were fragments. Not a single packet was complete.
Network packets have a maximum size, known as the MTU (maximum transmission unit). If a packet exceeds this limit, it is split into fragments, which must be transmitted individually and reassembled by the recipient. A server that receives a fragment stores it in a buffer and waits for the rest of the packet. The server can only process the complete packet once all parts have arrived.
In this case, it is more likely that the attacker sent only the first fragment and did not follow up with the rest. The target system places the fragment in the buffer and waits. Then, more incomplete packets arrive. With 8,500 different source IP addresses and a total volume of 370 gigabits per second, the available buffer resources are exhausted within seconds. This means that the available resources were tied up waiting for packets that never arrived. Consequently, there were no longer any resources available, not even for legitimate requests.
Learn how the new Network DDoS Protection protects you even more effectively
Faster mitigation, IPv6 parity, greater transparency, and significantly less manual effort.
Resource-efficient for the attacker, harmful to the target
This is one of the most significant asymmetries of this attack. A UDP fragment attack is cost-effective for the attacker. The attacker does not have to assemble complete packets, maintain connections, or process responses. There is no coordination effort or overhead from protocol handshakes.
A rough calculation shows that 370 gigabits distributed across nearly 8,500 source IP addresses averages to about 43 megabits per second per device. That’s not a significant burden for a server. However, for a compromised IoT device, such as a camera or home router, this could amount to half of its available upload bandwidth. Someone working from home with a fiber-optic connection who isn’t on a video call wouldn’t notice a 30-megabit upload running in the background. This makes botnets composed of such devices difficult to detect and easy to operate.
For the attacked system, however, the situation is quite different. Without specialized DDoS protection infrastructure, an attack of this magnitude could be catastrophic for many companies, regardless of how many firewalls or endpoints are on the network. At this volume, conventional defense measures are often overwhelmed before a person can react.
Geographically Unusual
This attack stood out because of where it originated. The top source regions – Brazil, India, Venezuela, and Azerbaijan – do not fit the typical profile for an attack on the customer’s infrastructure.
This suggests a geographically widespread botnet powered not by centralized cloud resources but by a broad mix of compromised devices worldwide. This breadth makes it more difficult to stop the attack through simple geo-blocking or IP blocklists. With over 8,500 source IP addresses, no single address appears frequently enough to be flagged by traditional rate limits.
An Old Method, a Current Threat
“UDP fragment attacks” are nothing new. For decades, they have been a standard tool in the arsenal of DDoS attackers. The technology itself has not changed, but its availability has. Botnets made up of IoT devices and cheaply hijacked server capacity, as well as the lack of need for orchestration, make such attacks easier to carry out than ever before. Attackers don’t need to set up complex infrastructures, coordinate protocol changes, or sort resources by capacity. They simply issue a command and wait for the target to go down.
Those who wait for attackers to switch to new, more spectacular methods before investing in protective measures underestimate just how much damage old, simple tools can still cause to modern infrastructure.
What This Case Means for Your Infrastructure
First, volumetric attacks often cannot be repelled by conventional firewalls. A 370-gigabit attack typically exceeds the capacity of any local defense infrastructure and occurs too quickly for a human to react. Therefore, effective protection must take effect before the attack reaches your network.
Second, fragmentation attacks target buffer resources, not just bandwidth. Those who base their protection solely on volume thresholds overlook the fact that a small amount of traffic consisting of incomplete fragments can exhaust these resources.
Third, response speed is critical because humans are not fast enough. An automated countermeasure that takes effect immediately without manual intervention is required for a ramp-up of less than 60 seconds.
What Link11 Observed During the Attack
The security infrastructure was able to manage this attack. Thanks to its globally distributed scrubbing capabilities, volumetric UDP floods could be detected without signature matching because the volume itself served as the signal. The attack was repelled before it could reach the customer’s network to any significant extent. For an unprotected infrastructure, the consequences could have been serious.
Sometimes, the most instructive attacks aren’t the most sophisticated ones. Sometimes, the simplest attack vectors demonstrate that basic protection isn’t just an option–it’s a prerequisite.
Do you know how your infrastructure would respond to a volumetric UDP attack within the first 30 seconds? Link11 analyzes your current protection architecture and shows you exactly where you stand in terms of response speed and capacity. Feel free to contact us to set up a conversation!
Lisa Fröhlich