June 7, 2016 By Larry Loeb 2 min read

Akamai’s Security Intelligence Response Team (SIRT) recently issued an advisory warning for a new spate of distributed denial-of-service (DDoS) attacks leveraging the Trivial File Transfer Protocol (TFTP).

As of April 20, 2016, Akamai had mitigated 10 attacks that were using this method. It reported most of the campaigns consisted of multivector attacks that included TFTP reflection. The security firm also found indications that this method may have been integrated into at least one site offering DDoS-as-a-service.

Why the Trivial File Transfer Protocol?

According to Akamai, TFTP has been around for a long time. It was intended to be used for file transfers of firmware and configuration files, typically for networked devices. However, the simple design of the protocol omits features such as authentication and directory listing capabilities.

The attack engages TFTP servers connected to the internet. It makes a default request for a file, and the victim TFTP server returns data to the requesting target host as a result of this request regardless of a file name mismatch. It spends time performing a wasted effort, which is just what the attackers want to happen.

TFTP only sends out data in specific block sizes and requires acknowledgment of each block being received. Akamai explained that because the target of the DDoS attack will never acknowledge the data being exfiltrated, only the first block is sent. This mitigates the potential of higher amplification based on single requests.

Some observed attacks had several data blocks attached to them, which could have greatly increased how much wasted effort the TFTP server expended.

SecurityWeek noted that Akamai’s Jose Arteaga said a weaponized version of the TFTP attack script started circulating in March, around the same time the media began highlighting research into this attack.

A Simple Mitigation Technique

In its advisory, Akamai recommended a few mitigation techniques. “For those hosting TFTP servers, assess the need to have UDP port 69 exposed to the internet. This should be firewalled and only allowed to trusted sources,” it said.

Intrusion detection systems can also help flag suspicious activities on the network.

More from

Change Healthcare discloses $22M ransomware payment

3 min read - UnitedHealth Group CEO Andrew Witty found himself answering questions in front of Congress on May 1 regarding the Change Healthcare ransomware attack that occurred in February. During the hearing, he admitted that his organization paid the attacker's ransomware request. It has been reported that the hacker organization BlackCat, also known as ALPHV, received a payment of $22 million via Bitcoin.Even though they made the ransomware payment, Witty shared that Change Healthcare did not get its data back. This is a…

Phishing kit trends and the top 10 spoofed brands of 2023

4 min read -  The 2024 IBM X-Force Threat Intelligence Index reported that phishing was one of the top initial access vectors observed last year, accounting for 30% of incidents. To carry out their phishing campaigns, attackers often use phishing kits: a collection of tools, resources and scripts that are designed and assembled to ease deployment. Each phishing kit deployment corresponds to a single phishing attack, and a kit could be redeployed many times during a phishing campaign. IBM X-Force has analyzed thousands of…

How I got started: AI security researcher

4 min read - For the enterprise, there’s no escape from deploying AI in some form. Careers focused on AI are proliferating, but one you may not be familiar with is AI security researcher. These AI specialists are cybersecurity professionals who focus on the unique vulnerabilities and threats that arise from the use of AI and machine learning (ML) systems. Their responsibilities vary, but key roles include identifying and analyzing potential security flaws in AI models and developing and testing methods malicious actors could…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today