Amplification attack
A denial-of-service technique that sends small spoofed requests to services whose replies are far larger, so the replies converge on the victim at many times the attacker's own traffic.
An amplification attack abuses services that answer a small request with a much larger response. The attacker forges the victim’s IP address as the source of each request (see spoofing) and sends the requests to many open servers, which send their large replies to the victim. The ratio of response size to request size is the amplification factor, and it lets a modest amount of attacker bandwidth become a flood that fills the victim’s link. The services abused commonly run over UDP, because UDP has no handshake to confirm the source address. Open DNS resolvers, NTP servers and SNMP agents are frequently cited examples.
Amplification is a special case of the reflection attack: an amplification attack of this kind uses reflectors, but a reflection attack need not amplify. The smurf attack is an older form that multiplied ICMP traffic through a broadcast address. Attackers commonly launch amplification from a botnet as a distributed denial of service.
Exam relevance: a scenario is likely to describe a victim flooded with large responses to requests it never sent. The points to keep straight are that the source address is forged, that UDP makes the forgery easy, and that networks applying ingress filtering to spoofed sources at their edge deny attackers inside them the forged source address the attack depends on.