Figure 311 Smurf Attack

Network Smurf Tool 1990 Full

At the bottom of Figure 3-11 you can see the attacker sending an ICMP echo request packet to the broadcast address of the bounce network. The bounce network is not the actual attack target, though it often experiences an indirect denial of service effect as a result. The ICMP packet has a spoofed source address from a device on the victim network (typically a router interface). The smurf attack is a type of amplification attack because when the single spoofed broadcast ping arrives at the bounce network, each host on that network responds with a unique ping packet to the victim of the attack. Consider an attacker that is able to generate a 768 kilobits per second (kbps) stream of broadcast ping packets to a bounce network with 100 hosts. This will turn into a 76.8 megabits per second (Mbps) stream when the return traffic is sent to the victim network. The larger the bounce network, the larger the amplification.

It is important to note that the router configuration command no ip directed-broadcast prevents your network from being the source of a smurf attack, not the victim of one. If you are the victim, you see large quantities of unicast ICMP echo reply messages, which must be filtered with a technology such as Committed Access Rate (CAR). More details about stopping smurf attacks and other attacks with a denial of service result can be found in the "DoS Design Considerations" section of Chapter 6.

Continue reading here: DoS

Was this article helpful?

0 0

Readers' Questions

  • ANTHONY
    What is a smurf attack?
    1 year ago
  • A Smurf attack is a type of attack that uses ICMP (Internet Control Message Protocol) broadcast messages to flood a target with ping requests, overwhelming the target and potentially causing a denial of service. The attacker sends ICMP echo-request packets to a network broadcast address, which causes all the computers on the network to respond to the request. The responses overload the target system, preventing it from providing services to legitimate users.