Skip to main content
Get a Free Trial
Glossary of Terms

What is a Protocol DDoS Attack?

Unlike application-layer distributed denial of service (DDoS) attacks and volumetric DDoS attacks, protocol DDoS attacks rely on weakness in internet communications protocols. Because many of these protocols are in global use, changing how they work is complicated and very slow to roll out. Moreover, for many protocols, their inherent complexity means that even when they are reengineered to fix existing flaws, new weaknesses are often introduced allowing for new types of protocol attacks and network attacks.

Key Takeaways

  • Protocol DDoS attacks exploit weaknesses in internet communications protocols, unlike volumetric attacks that flood with traffic or application-layer attacks that target apps.
  • Because these protocols are used globally, fixing their vulnerabilities is slow, complex, and expensive. And even when they are updated, new weaknesses often appear.
  • BGP hijacking is a key example, where a bad actor sends a fake routing update to redirect traffic to a different network, causing resource depletion and congestion.
  • Protocol attacks are measured by frequency and persistence rather than size, which is why they rarely make headlines but are still highly damaging.
  • A real-world example occurred in 2018 when hackers used BGP hijacking to redirect MyEtherWallet users to a fake Russian server, stealing over $13,000 in Ethereum in just two hours.
  • Detecting protocol DDoS attacks requires deep monitoring of communication streams and analysis of deviations from expected protocol behavior.

Detecting Protocol DDoS Attacks

Detecting protocol DDoS attacks requires in-depth monitoring of streams of communications and analysis of deviations from expected standards.

Examples of Protocol DDoS Attacks

Border Gateway Protocol (BGP) hijacking is a great example of a protocol that can become the basis of a DDoS attack. BGP is used by network operators to announce to other networks how their address space in configured. If a bad actor manages to send a BGP update that’s presumed to be authentic then traffic intended for one network can be routed to a different network and the spurious traffic can cause resource depletion and congestion. Because BGP is used by tens of thousands of network operators around the world, an upgrade to a more secure version of the protocol would be both complicated and very expensive to deploy. Other protocol attack examples include SYN flood and Ping of Death.

Real-World Protocol DDoS Attacks

Unfortunately, protocol attacks aren’t large enough to make the news so finding good examples is hard. In addition, protocol DDoS attacks aren’t deemed successful based on their size but rather the frequency and persistence of the attack. One of the rare examples of a protocol DDoS attack occurred in 2018 when hackers used BGP hijacking to redirect traffic intended for the MyEtherWallet, a service that managed Ethereum cryptocurrency accounts, to Russian servers that presented a fake version of the site. The attack lasted for roughly two hours and acted as a cover for stealing the contents of cryptocurrency wallets. The Verge reported:

Connecting to the service, users were faced with an unsigned SSL certificate, a broken link in the site’s verification. It was unusual, but it’s the kind of thing web users routinely click through without thinking. But anyone who clicked through this certificate warning was redirected to a server in Russia, which proceeded to empty the user’s wallet. Judging by wallet activity, the attackers appear to have taken at least $13,000 in Ethereum during two hours before the attack was shut down. The attackers’ wallet already contains more than $17 million in Ethereum.

How A10 Can Help Protect Against Protocol DDoS Attacks

A10 Defend provides a holistic DDoS protection solution that is scalable, economical, precise, and intelligent to help customers ensure optimal user and subscriber experiences. Designed for deployments at enterprise- and service provider-scale, A10’s DDoS mitigation solutions provide 10 to 100 times lower cost per subscriber compared to traditional network vendors and are available in both hardware and software form factors.


FAQs

Common examples include BGP hijacking, SYN flood, and Ping of Death. In a BGP hijacking attack, a bad actor sends a fake routing update to redirect traffic to a different network, causing congestion and resource depletion.

A volumetric DDoS attack floods a target with massive amounts of traffic to overwhelm bandwidth. A protocol DDoS attack does not rely on traffic volume but instead exploits flaws in how internet protocols work to exhaust server and network resources.

Detection requires deep monitoring of communication streams and identifying deviations from expected protocol behavior. Protection involves using a scalable DDoS mitigation solution that can analyze traffic in real time and block malicious protocol-based requests before they cause damage.

Because the protocols they exploit are used globally by thousands of network operators, updating or patching them is slow, complicated, and costly. Even when protocols are updated to fix known flaws, the complexity of the changes often introduces new vulnerabilities.

BGP hijacking is when a bad actor sends a fake BGP routing update that appears authentic, tricking networks into redirecting traffic to a different destination. This causes resource depletion and congestion on the targeted network and can also be used as cover for other attacks like data theft, as seen in the 2018 MyEtherWallet attack.

< Back to Glossary of Terms