Attack vectors

DNS Amplification DDoS

Small requests can produce much larger replies.

DNS amplification abuses open resolvers and source-address spoofing to direct oversized UDP responses at a victim.

01

The reflection chain

An attacker sends DNS queries to open resolvers with the victim's IP forged as the source. Each resolver sends its response to the victim, often larger than the original query.

TMW Shield detects abnormal reflected DNS patterns and filters attack traffic at the edge while preserving expected service flows.

DNS amplification FAQ

Why use DNS?

Some DNS responses are much larger than their triggering queries, creating amplification.

Can DNSSEC stop amplification?

DNSSEC authenticates records but does not prevent spoofed queries or stop reflection by itself.

Mitigate DNS reflection upstream

TMW Shield applies protocol-aware UDP filtering to protect your services.