Exploring for Insights on Anomalous Network Traffic
Kentik
JANUARY 11, 2016
To see that, we go back to the Metrics menu and choose Destination » Port. So now we can see that the UDP traffic is being sent to multiple ports, and it’s obvious that we’re experiencing a DNS redirection/amplification attack occurring on port 53, with a lot of port 0 UDP packet fragments being generated as collateral traffic.
Let's personalize your content