New round of DDoS attacks powered by WSD protocol

(Image credit: Shutterstock)

By abusing an improperly implemented tool present in almost 1m network-connected cameras, DVRs and other IoT devices, hackers have discovered a new technique to amplify the effects of denial-of-service attacks.

The new technique abuses the WS-Discovery (WSD) protocol which is used by a wide array of network devices to automatically connect to one another. The WSD protocol allows devices to send user datagram protocol (UDP) packets over port 3702 to describe the capabilities and requirements of a device.

However, devices that receive these probes can respond with replies that can be tens to even hundreds of times bigger and this allows hackers to amplify the power of their DDoS attacks.

Depending on the device, these responses can be anywhere from seven to 153 times bigger and this amplification makes WSD one of the most powerful techniques in a hacker's arsenal for amplifying DDoS attacks which can be crippling to businesses and consumers.

Amplified DDoS attacks

Researchers at Akamai were recently in the process of investigating WSD-based attacks when one of their customers in gaming industry fell victim to such an attack. At its peak, the DDoS attack using WSD amplification generated 35GB per second of junk traffic.

This attack was nowhere close to the 990Gbps DDoS attack caused by security cameras back in 2016 but the new technique being employed by hackers is still cause for concern due to the pool of available devices which Akamai estimates is over 802k.

In a blog post detailing Akamai's findings, Jonathan Respeto explained why WSD poses a major risk and how businesses should prepare for a new wave of DDoS attacks soon, saying:

“WSD is a major risk on the Internet that can push some serious bandwidth using CCTV and DVRs. Once more, we see security take a back seat for the sake of convenience. Manufacturers can just limit the scope of the UDP protocol on port 3702 to the multicast IP space. The only thing we can do now is wait for devices that are meant to have a 10/15 year life to die out, and hope that they are replaced with more secured version. Everyone is a potential target for WSD attacks, so organizations should be ready to route traffic to their DDoS mitigation provider if they're hit with this large attack. Due to its large amplification factors, we expect that attackers will waste little time in leveraging WSD for use as a reflection vector.”

Via Ars Technica

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Latest in News
A phone showing a ChatGPT app error message
ChatGPT is down for many – here's what's going on
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
US flags
US government IT contracts set to be centralized in new Trump order
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping