Reflection attack

A denial-of-service technique that sends requests to third-party servers with the victim's address forged as the source, so the servers' replies converge on the victim.

In a reflection attack the attacker does not send traffic straight at the target. Instead it sends requests to many innocent servers, the reflectors, and forges the target’s IP address as the source of each request. Every reflector answers the address it was given, so the replies arrive at the target from legitimate systems. The attacker’s own address stays hidden, and the flood comes from sources the victim cannot easily block without losing useful services. Connectionless protocols such as UDP and ICMP suit it, because no handshake exposes the forgery.

Reflection and amplification often combine but differ. Reflection redirects traffic; amplification means each reply is larger than the request, multiplying the attacker’s bandwidth. The smurf attack and the fraggle attack are older reflection attacks that used broadcast addresses. The root enabler is spoofing, which is why ingress filtering at network edges (RFC 2827, also known as BCP 38) is the widely recommended preventive measure. The same name is also used, in a different sense, for replaying a challenge back to its sender in a weak challenge-response protocol.

Exam relevance: a scenario in which a victim is flooded by replies from servers it never contacted is likely to describe reflection. Candidates are expected to separate it from amplification, and to know that stopping forged source addresses addresses the cause.